- Timestamp:
- 02/22/26 22:32:07 (7 months ago)
- Branches:
- finki-main, main
- Children:
- 6fea37e, 81bc7da
- Parents:
- 4dff800
- File:
-
- 1 edited
Legend:
- Unmodified
- Added
- Removed
-
server.js
r4dff800 r79fff4f 10 10 11 11 const port = process.env.PORT || 3000; 12 12 13 const sessions = new Map(); 13 14 const verificationCodes = new Map(); … … 31 32 } 32 33 }; 34 33 35 emailTransporter = nodemailer.createTransport(emailConfig); 36 34 37 emailTransporter.verify(function(error, success) { 35 38 if (error) { … … 52 55 const codeMatch = mailOptions.html.match(/\b\d{6}\b/); 53 56 const code = codeMatch ? codeMatch[0] : 'unknown'; 57 54 58 console.log(''); 55 59 console.log('🎯 ===== VERIFICATION CODE ====='); … … 60 64 console.log('================================'); 61 65 console.log(''); 66 62 67 resolve({ messageId: 'dev-' + Date.now() }); 63 68 }); … … 932 937 } 933 938 rolesInserted++; 939 934 940 if (rolesInserted === roles.length) { 935 941 console.log('✅ Roles inserted'); 936 937 942 // Create admin user with ID 000000 938 943 createAdminUser(); … … 1151 1156 // Check if store owner or employee 1152 1157 const personalId = userId.replace('personal_', ''); 1158 1153 1159 database.database.get( 1154 1160 'SELECT boss_id FROM boss WHERE boss_id = ?', … … 1201 1207 body += chunk.toString(); 1202 1208 }); 1203 1204 1209 req.on('end', () => { 1205 1210 const { username, email, password, userType, firstName, lastName } = JSON.parse(body); … … 1266 1271 console.log('✅ Verification email sent to:', email); 1267 1272 database.logAudit(null, 'REGISTER_ATTEMPT', 'user', null, `Registration attempt for ${email} as ${userType}`, ipAddress); 1268 1269 1273 res.writeHead(200, { 'Content-Type': 'application/json' }); 1270 1274 res.end(JSON.stringify({ … … 1294 1298 body += chunk.toString(); 1295 1299 }); 1296 1297 1300 req.on('end', () => { 1298 1301 const formData = JSON.parse(body); … … 1325 1328 1326 1329 const emailRegex = /^[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}$/; 1330 1327 1331 if (!emailRegex.test(formData.ownerEmail)) { 1328 1332 res.writeHead(400, { 'Content-Type': 'application/json' }); … … 1406 1410 // Next store number is max + 1, starting from 1 if no stores exist 1407 1411 let nextStoreNumber = 1; 1412 1408 1413 if (result && result.max_store_num) { 1409 1414 // Extract numeric part from store_id (format: XXX) … … 1461 1466 console.log('✅ Store registration email sent to:', formData.ownerEmail); 1462 1467 database.logAudit(null, 'STORE_REGISTER_ATTEMPT', 'store', null, `Store registration attempt: ${formData.storeName}`, ipAddress); 1463 1464 1468 res.writeHead(200, { 'Content-Type': 'application/json' }); 1465 1469 res.end(JSON.stringify({ … … 1494 1498 body += chunk.toString(); 1495 1499 }); 1496 1497 1500 req.on('end', () => { 1498 1501 const { firstName, lastName, email, password, address, city, postcode, country, isDefaultAddress } = JSON.parse(body); … … 1559 1562 console.log('✅ Verification email sent to:', email); 1560 1563 database.logAudit(null, 'CLIENT_REGISTER_ATTEMPT', 'client', null, `Client registration attempt for ${email}`, ipAddress); 1561 1562 1564 res.writeHead(200, { 'Content-Type': 'application/json' }); 1563 1565 res.end(JSON.stringify({ … … 1586 1588 body += chunk.toString(); 1587 1589 }); 1588 1589 1590 req.on('end', () => { 1590 1591 const { email } = JSON.parse(body); … … 1721 1722 body += chunk.toString(); 1722 1723 }); 1723 1724 1724 req.on('end', () => { 1725 1725 const { email, code } = JSON.parse(body); … … 1793 1793 database.database.run('ROLLBACK'); 1794 1794 console.error('Error inserting personal:', err); 1795 1795 1796 if (err.code === '23505') { 1796 1797 res.writeHead(400, { 'Content-Type': 'application/json' }); … … 1841 1842 } 1842 1843 1843 database.database.run('COMMIT', (commitErr) => { 1844 if (commitErr) { 1845 console.error('Error committing transaction:', commitErr); 1846 database.database.run('ROLLBACK'); 1847 res.writeHead(500, { 'Content-Type': 'application/json' }); 1848 res.end(JSON.stringify({ success: false, message: 'Error completing registration' })); 1849 return; 1844 // Also create entry in users table for login with force_password_change = 1 1845 database.database.run( 1846 'INSERT INTO users (id, username, email, password, user_type, force_password_change) VALUES (?, ?, ?, ?, ?, ?)', 1847 [ 1848 tempStoreData.personalId, 1849 `${tempStoreData.ownerFirstName} ${tempStoreData.ownerLastName}`, 1850 tempStoreData.ownerEmail, 1851 bcrypt.hashSync(tempStoreData.password, 10), 1852 'store_owner', 1853 1 1854 ], 1855 (err) => { 1856 if (err) { 1857 console.error('Error creating user entry for store owner:', err); 1858 } 1859 1860 database.database.run('COMMIT', (commitErr) => { 1861 if (commitErr) { 1862 console.error('Error committing transaction:', commitErr); 1863 database.database.run('ROLLBACK'); 1864 res.writeHead(500, { 'Content-Type': 'application/json' }); 1865 res.end(JSON.stringify({ success: false, message: 'Error completing registration' })); 1866 return; 1867 } 1868 1869 tempStoreRegistrations.delete(code); 1870 verificationCodes.delete(email); 1871 1872 console.log(`✅ Store registration completed successfully:`); 1873 console.log(` Store ID: ${tempStoreData.storeId}`); 1874 console.log(` Store Name: ${tempStoreData.storeName}`); 1875 console.log(` Personal ID: ${tempStoreData.personalId}`); 1876 console.log(` Owner: ${tempStoreData.ownerFirstName} ${tempStoreData.ownerLastName}`); 1877 1878 database.logAudit(tempStoreData.personalId, 'STORE_REGISTER_SUCCESS', 'store', tempStoreData.storeId, `Store registered: ${tempStoreData.storeName}`, ipAddress); 1879 1880 res.writeHead(200, { 'Content-Type': 'application/json' }); 1881 res.end(JSON.stringify({ 1882 success: true, 1883 message: 'Store registration successful! You can now login.', 1884 storeId: tempStoreData.storeId, 1885 storeIdPadded: tempStoreData.storeIdPadded, 1886 storeName: tempStoreData.storeName, 1887 personalId: tempStoreData.personalId, 1888 userType: 'store_owner', 1889 redirectTo: 'login.html' 1890 })); 1891 }); 1850 1892 } 1851 1852 tempStoreRegistrations.delete(code); 1853 verificationCodes.delete(email); 1854 1855 console.log(`✅ Store registration completed successfully:`); 1856 console.log(` Store ID: ${tempStoreData.storeId}`); 1857 console.log(` Store Name: ${tempStoreData.storeName}`); 1858 console.log(` Personal ID: ${tempStoreData.personalId}`); 1859 console.log(` Owner: ${tempStoreData.ownerFirstName} ${tempStoreData.ownerLastName}`); 1860 1861 database.logAudit(tempStoreData.personalId, 'STORE_REGISTER_SUCCESS', 'store', tempStoreData.storeId, `Store registered: ${tempStoreData.storeName}`, ipAddress); 1862 1863 res.writeHead(200, { 'Content-Type': 'application/json' }); 1864 res.end(JSON.stringify({ 1865 success: true, 1866 message: 'Store registration successful! You can now login.', 1867 storeId: tempStoreData.storeId, 1868 storeIdPadded: tempStoreData.storeIdPadded, 1869 storeName: tempStoreData.storeName, 1870 personalId: tempStoreData.personalId, 1871 userType: 'store_owner', 1872 redirectTo: 'login.html' 1873 })); 1874 }); 1893 ); 1875 1894 } 1876 1895 ); … … 1952 1971 } else { 1953 1972 const userId = 'user_' + Date.now().toString().slice(-8); 1973 1954 1974 database.createUser(userId, tempUserData.username, tempUserData.email, tempUserData.password, tempUserData.userType, (err, userId) => { 1955 1975 if (err) { … … 1982 2002 body += chunk.toString(); 1983 2003 }); 1984 1985 2004 req.on('end', () => { 1986 2005 const { email, password } = JSON.parse(body); … … 2003 2022 2004 2023 const twoFACode = generateVerificationCode(); 2005 2006 2024 verificationCodes.set(adminUser.email, { 2007 2025 code: twoFACode, … … 2048 2066 } 2049 2067 }); 2068 2050 2069 return; 2051 2070 } … … 2094 2113 'Set-Cookie': `sessionId=${sessionId}; HttpOnly; Path=/; Max-Age=3600; SameSite=Strict` 2095 2114 }); 2115 2096 2116 res.end(JSON.stringify({ 2097 2117 success: true, … … 2155 2175 2156 2176 const twoFACode = generateVerificationCode(); 2157 2158 2177 verificationCodes.set(personal.email, { 2159 2178 code: twoFACode, … … 2216 2235 2217 2236 const twoFACode = generateVerificationCode(); 2218 2219 2237 verificationCodes.set(personal.email, { 2220 2238 code: twoFACode, … … 2278 2296 2279 2297 const twoFACode = generateVerificationCode(); 2280 2281 2298 verificationCodes.set(userByUsername.email, { 2282 2299 code: twoFACode, … … 2329 2346 2330 2347 const twoFACode = generateVerificationCode(); 2331 2332 2348 verificationCodes.set(user.email, { 2333 2349 code: twoFACode, … … 2396 2412 body += chunk.toString(); 2397 2413 }); 2398 2399 2414 req.on('end', () => { 2400 2415 const { email } = JSON.parse(body); … … 2419 2434 2420 2435 const newTwoFACode = generateVerificationCode(); 2421 2422 2436 verificationCodes.set(userByUsername.email, { 2423 2437 code: newTwoFACode, … … 2456 2470 2457 2471 const newTwoFACode = generateVerificationCode(); 2458 2459 2472 verificationCodes.set(user.email, { 2460 2473 code: newTwoFACode, … … 2497 2510 body += chunk.toString(); 2498 2511 }); 2499 2500 2512 req.on('end', () => { 2501 2513 const { email, code } = JSON.parse(body); … … 2532 2544 verificationCodes.delete(email); 2533 2545 2546 // Determine redirect based on user type 2547 let redirectTo = 'change-password.html?forced=true'; 2548 if (verificationData.userType === 'store_owner') { 2549 redirectTo = 'change-password.html?forced=true&redirect=store-owner.html'; 2550 } else if (verificationData.userType === 'store_employee') { 2551 redirectTo = 'change-password.html?forced=true&redirect=store-employee.html'; 2552 } else if (verificationData.userType === 'admin') { 2553 redirectTo = 'change-password.html?forced=true&redirect=admin.html'; 2554 } else if (verificationData.userType === 'client') { 2555 redirectTo = 'change-password.html?forced=true&redirect=client-dashboard.html'; 2556 } 2557 2534 2558 res.writeHead(200, { 2535 2559 'Content-Type': 'application/json', 2536 2560 'Set-Cookie': `sessionId=${tempSessionId}; HttpOnly; Path=/; Max-Age=3600; SameSite=Strict` 2537 2561 }); 2562 2538 2563 res.end(JSON.stringify({ 2539 2564 success: true, … … 2541 2566 requiresPasswordChange: true, 2542 2567 userType: verificationData.userType, 2543 redirectTo: 'change-password.html?forced=true'2568 redirectTo: redirectTo 2544 2569 })); 2545 2570 … … 2590 2615 'Set-Cookie': `sessionId=${sessionId}; HttpOnly; Path=/; Max-Age=3600; SameSite=Strict` 2591 2616 }); 2617 2592 2618 res.end(JSON.stringify({ 2593 2619 success: true, … … 2616 2642 'Set-Cookie': 'sessionId=; HttpOnly; Path=/; Expires=Thu, 01 Jan 1970 00:00:00 GMT; SameSite=Strict' 2617 2643 }); 2644 2618 2645 res.end(JSON.stringify({ success: true, message: 'Successfully logged out' })); 2619 2646 } … … 2736 2763 }); 2737 2764 } 2738 2739 2765 else if (userIdStr.startsWith('personal_')) { 2740 2766 const personalId = userIdStr.replace('personal_', ''); … … 2885 2911 body += chunk.toString(); 2886 2912 }); 2887 2888 2913 req.on('end', () => { 2889 2914 const categoryData = JSON.parse(body); … … 2968 2993 body += chunk.toString(); 2969 2994 }); 2970 2971 2995 req.on('end', () => { 2972 2996 const orderData = JSON.parse(body); … … 3066 3090 body += chunk.toString(); 3067 3091 }); 3068 3069 3092 req.on('end', () => { 3070 3093 const reviewData = JSON.parse(body); … … 3073 3096 if (userIdStr.startsWith('client_')) { 3074 3097 const clientId = parseInt(userIdStr.replace('client_', '')); 3075 3076 3098 reviewData.client_id = clientId; 3077 3099 … … 3100 3122 body += chunk.toString(); 3101 3123 }); 3102 3103 3124 req.on('end', () => { 3104 3125 const requestData = JSON.parse(body); … … 3170 3191 body += chunk.toString(); 3171 3192 }); 3172 3173 3193 req.on('end', () => { 3174 3194 const refundData = JSON.parse(body); … … 3240 3260 body += chunk.toString(); 3241 3261 }); 3242 3243 3262 req.on('end', () => { 3244 3263 const productData = JSON.parse(body); … … 3333 3352 body += chunk.toString(); 3334 3353 }); 3335 3336 3354 req.on('end', () => { 3337 3355 const productData = JSON.parse(body); … … 3427 3445 } 3428 3446 3447 // Updated /api/force-change-password endpoint with redirect handling 3429 3448 else if (pathname === '/api/force-change-password' && req.method === 'POST') { 3430 3449 const cookies = parseCookies(req); … … 3439 3458 3440 3459 let body = ''; 3441 3442 3460 req.on('data', chunk => { 3443 3461 body += chunk.toString(); 3444 3462 }); 3445 3446 3463 req.on('end', () => { 3447 3464 try { 3448 const { newPassword, confirmPassword } = JSON.parse(body);3465 const { newPassword, confirmPassword, redirectTo } = JSON.parse(body); 3449 3466 3450 3467 if (!newPassword || !confirmPassword) { … … 3508 3525 // Create new permanent session 3509 3526 const newSessionId = generateSessionId(); 3510 sessions.set(newSessionId, String(userId)); 3511 3512 // Determine redirect based on user type 3513 let redirectTo = 'dashboard.html'; 3514 3515 if (user.username === 'admin' || user.user_type === 'admin') { 3516 redirectTo = 'admin.html'; 3517 } else if (user.user_type === 'store_owner') { 3518 redirectTo = 'store-owner.html'; 3519 } else if (user.user_type === 'store_employee') { 3520 redirectTo = 'store-employee.html'; 3521 } else if (user.user_type === 'client') { 3522 redirectTo = 'client-dashboard.html'; 3527 3528 // Determine how to store the user ID based on user type 3529 let sessionUserId = String(userId); 3530 3531 if (user.user_type === 'store_owner' || user.user_type === 'store_employee') { 3532 sessionUserId = `personal_${userId}`; 3523 3533 } 3524 3534 3525 console.log(`Password changed successfully for user ${userId}, redirecting to ${redirectTo}`); 3535 sessions.set(newSessionId, sessionUserId); 3536 3537 // Determine redirect based on user type or provided redirectTo 3538 let finalRedirect = redirectTo || 'dashboard.html'; 3539 3540 if (!redirectTo) { 3541 if (user.username === 'admin' || user.user_type === 'admin') { 3542 finalRedirect = 'admin.html'; 3543 } else if (user.user_type === 'store_owner') { 3544 finalRedirect = 'store-owner.html'; 3545 } else if (user.user_type === 'store_employee') { 3546 finalRedirect = 'store-employee.html'; 3547 } else if (user.user_type === 'client') { 3548 finalRedirect = 'client-dashboard.html'; 3549 } 3550 } 3551 3552 console.log(`Password changed successfully for user ${userId}, redirecting to ${finalRedirect}`); 3526 3553 3527 3554 database.logAudit(userId, 'FORCED_PASSWORD_CHANGE', 'auth', userId.toString(), … … 3531 3558 res.writeHead(200, { 3532 3559 'Content-Type': 'application/json', 3533 'Set-Cookie': `sessionId=${newSessionId}; HttpOnly; Path=/; Max-Age= 3600; SameSite=Strict`3560 'Set-Cookie': `sessionId=${newSessionId}; HttpOnly; Path=/; Max-Age=86400; SameSite=Strict` // Extended to 24 hours 3534 3561 }); 3562 3535 3563 res.end(JSON.stringify({ 3536 3564 success: true, 3537 3565 message: 'Password changed successfully.', 3538 redirectTo: redirectTo,3566 redirectTo: finalRedirect, 3539 3567 userType: user.user_type || 'user' 3540 3568 })); … … 3584 3612 (err, boss) => { 3585 3613 let userType = 'store_employee'; 3586 let redirectTo ='store-employee.html';3614 let finalRedirect = redirectTo || 'store-employee.html'; 3587 3615 3588 3616 if (boss) { 3589 3617 userType = 'store_owner'; 3590 redirectTo ='store-owner.html';3618 finalRedirect = redirectTo || 'store-owner.html'; 3591 3619 } 3592 3620 … … 3594 3622 tempAdminSessions.delete(sessionId); 3595 3623 3596 // Create new permanent session 3624 // Create new permanent session with personal_ prefix 3597 3625 const newSessionId = generateSessionId(); 3598 3626 sessions.set(newSessionId, `personal_${userId}`); 3599 3627 3600 console.log(`Password changed successfully for ${userType} ${userId}, redirecting to ${ redirectTo}`);3628 console.log(`Password changed successfully for ${userType} ${userId}, redirecting to ${finalRedirect}`); 3601 3629 3602 3630 database.logAudit(userId, 'FORCED_PASSWORD_CHANGE', 'auth', userId.toString(), 3603 3631 `${userType} forced password change completed`, ipAddress); 3604 3632 3605 // Set the cookie with proper options 3633 // Set the cookie with proper options - extended to 24 hours 3606 3634 res.writeHead(200, { 3607 3635 'Content-Type': 'application/json', 3608 'Set-Cookie': `sessionId=${newSessionId}; HttpOnly; Path=/; Max-Age= 3600; SameSite=Strict`3636 'Set-Cookie': `sessionId=${newSessionId}; HttpOnly; Path=/; Max-Age=86400; SameSite=Strict` 3609 3637 }); 3638 3610 3639 res.end(JSON.stringify({ 3611 3640 success: true, 3612 3641 message: 'Password changed successfully.', 3613 redirectTo: redirectTo,3642 redirectTo: finalRedirect, 3614 3643 userType: userType 3615 3644 })); … … 3668 3697 body += chunk.toString(); 3669 3698 }); 3670 3671 3699 req.on('end', () => { 3672 3700 const { firstName, lastName, ssn, email, password, storeId, dateOfHire } = JSON.parse(body); … … 3775 3803 database.database.run('ROLLBACK'); 3776 3804 console.error('Error inserting personal:', err); 3805 3777 3806 if (err.code === '23505') { 3778 3807 res.writeHead(400, { 'Content-Type': 'application/json' }); 3779 res.end(JSON.stringify({ success: false, message: 'This personal ID is already taken. Please try again.' })); 3808 res.end(JSON.stringify({ 3809 success: false, 3810 message: 'This personal ID is already taken. Please try again.' 3811 })); 3780 3812 } else { 3781 3813 res.writeHead(400, { 'Content-Type': 'application/json' }); … … 3817 3849 } 3818 3850 3819 database.database.run('COMMIT', (err) => { 3820 if (err) { 3821 database.database.run('ROLLBACK'); 3822 console.error('Error committing transaction:', err); 3823 res.writeHead(500, { 'Content-Type': 'application/json' }); 3824 res.end(JSON.stringify({ success: false, message: 'Error completing registration' })); 3825 return; 3851 // Also create entry in users table for login with force_password_change = 1 3852 database.database.run( 3853 'INSERT INTO users (id, username, email, password, user_type, force_password_change) VALUES (?, ?, ?, ?, ?, ?)', 3854 [ 3855 newPersonalId, 3856 `${firstName} ${lastName}`, 3857 email, 3858 bcrypt.hashSync(password, 10), 3859 'store_employee', 3860 1 3861 ], 3862 (err) => { 3863 if (err) { 3864 console.error('Error creating user entry for employee:', err); 3865 } 3866 3867 database.database.run('COMMIT', (err) => { 3868 if (err) { 3869 database.database.run('ROLLBACK'); 3870 console.error('Error committing transaction:', err); 3871 res.writeHead(500, { 'Content-Type': 'application/json' }); 3872 res.end(JSON.stringify({ success: false, message: 'Error completing registration' })); 3873 return; 3874 } 3875 3876 database.logAudit(personalId, 'EMPLOYEE_REGISTERED', 'employee', newPersonalId, `Employee registered: ${firstName} ${lastName}`, ipAddress); 3877 3878 res.writeHead(200, { 'Content-Type': 'application/json' }); 3879 res.end(JSON.stringify({ 3880 success: true, 3881 message: 'Employee registered successfully!', 3882 employeeId: newPersonalId, 3883 name: `${firstName} ${lastName}` 3884 })); 3885 }); 3826 3886 } 3827 3828 database.logAudit(personalId, 'EMPLOYEE_REGISTERED', 'employee', newPersonalId, `Employee registered: ${firstName} ${lastName}`, ipAddress); 3829 3830 res.writeHead(200, { 'Content-Type': 'application/json' }); 3831 res.end(JSON.stringify({ 3832 success: true, 3833 message: 'Employee registered successfully!', 3834 employeeId: newPersonalId, 3835 name: `${firstName} ${lastName}` 3836 })); 3837 }); 3887 ); 3838 3888 } 3839 3889 ); … … 3887 3937 body += chunk.toString(); 3888 3938 }); 3889 3890 3939 req.on('end', () => { 3891 3940 const { employeeId, storeId } = JSON.parse(body); … … 3975 4024 } 3976 4025 3977 database.database.run('COMMIT', (commitErr) => { 3978 if (commitErr) { 3979 database.database.run('ROLLBACK'); 3980 console.error('Error committing transaction:', commitErr); 3981 res.writeHead(500, { 'Content-Type': 'application/json' }); 3982 res.end(JSON.stringify({ success: false, message: 'Error completing deletion' })); 3983 return; 4026 // Also delete from users table 4027 database.database.run( 4028 'DELETE FROM users WHERE id = ?', 4029 [employeeId], 4030 (err) => { 4031 if (err) { 4032 console.error('Error deleting from users:', err); 4033 } 4034 4035 database.database.run('COMMIT', (commitErr) => { 4036 if (commitErr) { 4037 database.database.run('ROLLBACK'); 4038 console.error('Error committing transaction:', commitErr); 4039 res.writeHead(500, { 'Content-Type': 'application/json' }); 4040 res.end(JSON.stringify({ success: false, message: 'Error completing deletion' })); 4041 return; 4042 } 4043 4044 database.logAudit(personalId, 'EMPLOYEE_DELETED', 'employee', employeeId, `Employee deleted from store ${storeId}`, ipAddress); 4045 4046 res.writeHead(200, { 'Content-Type': 'application/json' }); 4047 res.end(JSON.stringify({ 4048 success: true, 4049 message: 'Employee deleted successfully' 4050 })); 4051 }); 3984 4052 } 3985 3986 database.logAudit(personalId, 'EMPLOYEE_DELETED', 'employee', employeeId, `Employee deleted from store ${storeId}`, ipAddress); 3987 3988 res.writeHead(200, { 'Content-Type': 'application/json' }); 3989 res.end(JSON.stringify({ 3990 success: true, 3991 message: 'Employee deleted successfully' 3992 })); 3993 }); 4053 ); 3994 4054 } 3995 4055 ); … … 4046 4106 body += chunk.toString(); 4047 4107 }); 4048 4049 4108 req.on('end', () => { 4050 4109 const { employeeId, storeId, status } = JSON.parse(body); … … 4153 4212 body += chunk.toString(); 4154 4213 }); 4155 4156 4214 req.on('end', () => { 4157 4215 const { employeeId, storeId, firstName, lastName, email } = JSON.parse(body); … … 4223 4281 res.end(JSON.stringify({ success: false, message: 'Error updating employee information' })); 4224 4282 return; 4283 } 4284 4285 // Also update in users table if email was changed 4286 if (email) { 4287 database.database.run( 4288 'UPDATE users SET email = ? WHERE id = ?', 4289 [email, employeeId], 4290 (err) => { 4291 if (err) { 4292 console.error('Error updating user email:', err); 4293 } 4294 } 4295 ); 4296 } 4297 4298 if (firstName || lastName) { 4299 database.database.get( 4300 'SELECT first_name, last_name FROM personal WHERE id = ?', 4301 [employeeId], 4302 (err, personal) => { 4303 if (!err && personal) { 4304 const newUsername = `${personal.first_name} ${personal.last_name}`; 4305 database.database.run( 4306 'UPDATE users SET username = ? WHERE id = ?', 4307 [newUsername, employeeId], 4308 (err) => { 4309 if (err) { 4310 console.error('Error updating user username:', err); 4311 } 4312 } 4313 ); 4314 } 4315 } 4316 ); 4225 4317 } 4226 4318 … … 4582 4674 body += chunk.toString(); 4583 4675 }); 4584 4585 4676 req.on('end', () => { 4586 4677 const { productCode, storeId } = JSON.parse(body); … … 4652 4743 body += chunk.toString(); 4653 4744 }); 4654 4655 4745 req.on('end', () => { 4656 4746 const { storeId, period, startDate, endDate, type } = JSON.parse(body);
Note:
See TracChangeset
for help on using the changeset viewer.
