F-03: bon-download afgeschermd op rol #113

Closed
opened 2026-05-26 18:23:44 +00:00 by jesse-a · 1 comment
Owner

Severity: MEDIUM

De route expenses/[id]/receipt checkte alleen getSession() — een VIEWER kon dus bon-PDFs ophalen die in de UI verborgen waren omdat de inkoop-module MANAGER-only is.

Fix: route eist nu rol MANAGER, gelijk aan de inkoop-module.

**Severity: MEDIUM** De route `expenses/[id]/receipt` checkte alleen `getSession()` — een VIEWER kon dus bon-PDFs ophalen die in de UI verborgen waren omdat de inkoop-module MANAGER-only is. **Fix**: route eist nu rol MANAGER, gelijk aan de inkoop-module.
Author
Owner

Opgelost in commit 4d080f2.

Opgelost in commit 4d080f2.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
jesse-a/OpenCRM#113
No description provided.