Add debug logging to trash and restore endpoints
This commit is contained in:
@@ -174,7 +174,11 @@ async function entryAccessible(user, entryId) {
|
|||||||
if (!rows.length) return { found: false };
|
if (!rows.length) return { found: false };
|
||||||
const groupId = rows[0].group_id;
|
const groupId = rows[0].group_id;
|
||||||
if (user.role === 'admin') return { found: true, group_id: groupId };
|
if (user.role === 'admin') return { found: true, group_id: groupId };
|
||||||
return { found: true, group_id: groupId, allowed: groupId && (await groupBelongsToBranches(user, groupId)) };
|
const allowed = groupId && (await groupBelongsToBranches(user, groupId));
|
||||||
|
if (!allowed) {
|
||||||
|
console.warn(`[ACCESS DENIED] entryAccessible: user=${user.id} (${user.username}) branch_ids=${JSON.stringify(user.branch_ids)} entry=${entryId} group_id=${groupId}`);
|
||||||
|
}
|
||||||
|
return { found: true, group_id: groupId, allowed };
|
||||||
}
|
}
|
||||||
|
|
||||||
function fixFilename(str) {
|
function fixFilename(str) {
|
||||||
@@ -2220,7 +2224,11 @@ app.put('/api/entries/:id/restore', requireAuth, async (req, res) => {
|
|||||||
return res.status(403).json({ error: 'Нет доступа к этой записи' });
|
return res.status(403).json({ error: 'Нет доступа к этой записи' });
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
await pool.query('UPDATE entries SET deleted_at = NULL WHERE id = $1', [req.params.id]);
|
const result = await pool.query('UPDATE entries SET deleted_at = NULL WHERE id = $1', [req.params.id]);
|
||||||
|
console.log(`[RESTORE] User ${req.user.id} (${req.user.username}) restored entry ${req.params.id}, rowCount=${result.rowCount}`);
|
||||||
|
if (result.rowCount === 0) {
|
||||||
|
return res.status(404).json({ error: 'Запись не найдена или уже восстановлена' });
|
||||||
|
}
|
||||||
await logAudit(req, 'entry.restore', { id: req.params.id });
|
await logAudit(req, 'entry.restore', { id: req.params.id });
|
||||||
res.json({ ok: true });
|
res.json({ ok: true });
|
||||||
});
|
});
|
||||||
@@ -2253,6 +2261,7 @@ app.get('/api/trash', requireAuth, async (req, res) => {
|
|||||||
where += ' AND 1 = 0';
|
where += ' AND 1 = 0';
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
console.log(`[TRASH] User ${req.user.id} (${req.user.username}) role=${req.user.role} branch_ids=${JSON.stringify(bw.ids)} scoped=${scoped} where=${where} params=${JSON.stringify(params)}`);
|
||||||
const { rows: crows } = await pool.query(
|
const { rows: crows } = await pool.query(
|
||||||
`SELECT count(*)::int AS n FROM entries e JOIN groups g ON g.id = e.group_id WHERE e.deleted_at IS NOT NULL` +
|
`SELECT count(*)::int AS n FROM entries e JOIN groups g ON g.id = e.group_id WHERE e.deleted_at IS NOT NULL` +
|
||||||
(scoped ? (bw.ids.length ? ` AND g.branch_id IN (${bw.ids.map((_, i) => `$${i + 1}`).join(',')})` : ' AND 1 = 0') : ''),
|
(scoped ? (bw.ids.length ? ` AND g.branch_id IN (${bw.ids.map((_, i) => `$${i + 1}`).join(',')})` : ' AND 1 = 0') : ''),
|
||||||
@@ -2268,6 +2277,7 @@ app.get('/api/trash', requireAuth, async (req, res) => {
|
|||||||
const off = parseInt(offset, 10);
|
const off = parseInt(offset, 10);
|
||||||
if (off > 0) { qparams.push(off); q += ` OFFSET $${qparams.length}`; }
|
if (off > 0) { qparams.push(off); q += ` OFFSET $${qparams.length}`; }
|
||||||
const { rows } = await pool.query(q, qparams);
|
const { rows } = await pool.query(q, qparams);
|
||||||
|
console.log(`[TRASH] Found ${rows.length} entries for user ${req.user.id}`);
|
||||||
let files = {};
|
let files = {};
|
||||||
if (rows.length) {
|
if (rows.length) {
|
||||||
const fRes = await pool.query(
|
const fRes = await pool.query(
|
||||||
|
|||||||
Reference in New Issue
Block a user