From 14985ae8297a46d9329796c5697671ea40fffbe8 Mon Sep 17 00:00:00 2001 From: Cursor Agent Date: Tue, 8 Sep 2026 20:59:27 +0000 Subject: [PATCH] =?UTF-8?q?fix:=20filtrar=20asistencia=20del=20paquete=20d?= =?UTF-8?q?e=20n=C3=B3mina=20por=20tenant?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit attendance no tiene RLS propio; el JOIN a projects ahora tambiƩn restringe por tenant_id para no mezclar marcas de otro cliente. Co-authored-by: alberto.martinez --- api/payroll.ts | 13 ++++++++++--- 1 file changed, 10 insertions(+), 3 deletions(-) diff --git a/api/payroll.ts b/api/payroll.ts index b2093a5..615f514 100644 --- a/api/payroll.ts +++ b/api/payroll.ts @@ -247,6 +247,7 @@ async function attachJornalCells( db: Db, sheets: Array>, days: string[], + tenantId: number, ): Promise>> { const from = days[0]; const to = days[days.length - 1]; @@ -255,8 +256,9 @@ async function attachJornalCells( `SELECT a.worker_id, a.project_id, a.work_date, a.present, p.name AS project_name FROM attendance a JOIN projects p ON p.id = a.project_id - WHERE a.work_date BETWEEN ? AND ?`, - ).all(from, to) as AttendanceRow[]; + WHERE a.work_date BETWEEN ? AND ? + AND p.tenant_id = ?`, + ).all(from, to, tenantId) as AttendanceRow[]; return sheets.map((sheet) => { if (sheet.kind !== "obra") return sheet; @@ -297,7 +299,12 @@ export async function getWeekBundle(db: Db, tenantId: number, weekStart: string) const week = (data.week ?? null) as Record | null; const start = isoDay(week?.week_start) || weekStart; const days = weekDays(start); - const sheets = await attachJornalCells(db, (data.sheets as Array>) ?? [], days); + const sheets = await attachJornalCells( + db, + (data.sheets as Array>) ?? [], + days, + tenantId, + ); const bounds = destajoPeriodBounds(start); return { ...data,