fix: cloisonnement des canaux de commande et suivi public restreint a la borne #156
No reviewers
Labels
No labels
auto-merge
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
AcadeNice/corentin_wakdo!156
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "fix/rbac-order-channel"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
GET /api/orders/{number} is anonymous, unauthenticated, and order numbers are sequential (channel prefix + auto-increment id). findByNumber() didn't filter by source, so this endpoint would return the status AND total_ttc_cents of any counter/drive order too, not just kiosk ones -- despite those orders being placed by an identified staff member, not an anonymous customer. findByNumber() now also returns source (additive; create()/pay() keep using the existing present(), unaffected). show() treats a non-kiosk order the same as an unknown one (404 ORDER_NOT_FOUND, identical body, anti-enumeration), and drops total_ttc_cents from its response: no kiosk screen (checkout.js, page-confirmation.js, confirm-modal.js) reads that field from this endpoint today.