mirror of
https://origin.cursor.com/mrdevmx/panels.git
synced 2026-10-09 14:13:18 +00:00
fix: filtrar asistencia del paquete de nómina por tenant
attendance no tiene RLS propio; el JOIN a projects ahora también restringe por tenant_id para no mezclar marcas de otro cliente. Co-authored-by: alberto.martinez <alberto.martinez@mrdev.mx>
This commit is contained in:
parent
9c8b6ea19c
commit
14985ae829
1 changed files with 10 additions and 3 deletions
|
|
@ -247,6 +247,7 @@ async function attachJornalCells(
|
|||
db: Db,
|
||||
sheets: Array<Record<string, unknown>>,
|
||||
days: string[],
|
||||
tenantId: number,
|
||||
): Promise<Array<Record<string, unknown>>> {
|
||||
const from = days[0];
|
||||
const to = days[days.length - 1];
|
||||
|
|
@ -255,8 +256,9 @@ async function attachJornalCells(
|
|||
`SELECT a.worker_id, a.project_id, a.work_date, a.present, p.name AS project_name
|
||||
FROM attendance a
|
||||
JOIN projects p ON p.id = a.project_id
|
||||
WHERE a.work_date BETWEEN ? AND ?`,
|
||||
).all(from, to) as AttendanceRow[];
|
||||
WHERE a.work_date BETWEEN ? AND ?
|
||||
AND p.tenant_id = ?`,
|
||||
).all(from, to, tenantId) as AttendanceRow[];
|
||||
|
||||
return sheets.map((sheet) => {
|
||||
if (sheet.kind !== "obra") return sheet;
|
||||
|
|
@ -297,7 +299,12 @@ export async function getWeekBundle(db: Db, tenantId: number, weekStart: string)
|
|||
const week = (data.week ?? null) as Record<string, unknown> | null;
|
||||
const start = isoDay(week?.week_start) || weekStart;
|
||||
const days = weekDays(start);
|
||||
const sheets = await attachJornalCells(db, (data.sheets as Array<Record<string, unknown>>) ?? [], days);
|
||||
const sheets = await attachJornalCells(
|
||||
db,
|
||||
(data.sheets as Array<Record<string, unknown>>) ?? [],
|
||||
days,
|
||||
tenantId,
|
||||
);
|
||||
const bounds = destajoPeriodBounds(start);
|
||||
return {
|
||||
...data,
|
||||
|
|
|
|||
Loading…
Reference in a new issue