Backend already returned 403 for ungranted secretary actions, but the UI still showed the add/edit/delete buttons (e.g. clinic-services showed «بخش جدید» to a secretary without services.create). Sweep every secretary-reachable page so each create/edit/delete/manage control renders only when the matching usePermissions().can(resource, action) is true. Owner/doctor/clinic are unaffected — can() returns true when there is no permission context — so this restricts only secretaries and mirrors the server checks. Pages/components gated (resource): - services: ClinicServicesPage, ServiceDetailPage (+ its tabs) - inventory: InventoryPage, InventoryItemsTable, InventoryActionsMenu, PackagesView - tags: TagsSettingsPage · staff: StaffPage · discounts: DiscountTab - sms: SmsWalletPage · insurances: TenantInsuranceContracts - clinic_doctors: ClinicDoctorsPage + ClinicDoctorsManager (props, default true) - patients: PatientsListPage, MyPatientsPage, PatientDetailPage (records/notes/ sessions/attachments/calls/wallet — create/update/delete split) - appointments: AppointmentsPage (add + empty-slot booking gated by create), TurnsTable (status dropdown → read-only badge without update_status; actions menu hidden without manage/cancel) - appointment_settings: AppointmentSettingsPage + ClinicAppointmentSettingsPage pass readOnly to ScheduleSection + FreeVisitPrice (new readOnly prop) Not gated: view/read, search, filter, tabs, navigation, export, and modal submit buttons reachable only via an already-gated trigger. tsc clean; full frontend suite 501/501 passes. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
102 lines
4.3 KiB
TypeScript
102 lines
4.3 KiB
TypeScript
import React from 'react';
|
|
import { PencilSquareIcon, TrashIcon } from '@heroicons/react/24/outline';
|
|
import { formatRial, formatNumber } from '../../lib/utils';
|
|
import type { InventoryItem } from '../../hooks/useInventory';
|
|
import InventoryStatusBadge from './InventoryStatusBadge';
|
|
import InventoryActionsMenu from './InventoryActionsMenu';
|
|
import { usePermissions } from '../../hooks/usePermissions';
|
|
|
|
interface Props {
|
|
items: InventoryItem[];
|
|
onEdit: (item: InventoryItem) => void;
|
|
onDelete: (item: InventoryItem) => void;
|
|
}
|
|
|
|
const HEAD = ['نام کالا', 'دستهبندی', 'موجودی', 'واحد', 'قیمت', 'وضعیت', 'عملیات'];
|
|
|
|
/** Consumable-items list: desktop table + mobile card grid (tauri InventoryList). */
|
|
export default function InventoryItemsTable({ items, onEdit, onDelete }: Props) {
|
|
const { can } = usePermissions();
|
|
const canUpdate = can('inventory', 'update');
|
|
const canDelete = can('inventory', 'delete');
|
|
return (
|
|
<div style={{ width: '100%' }}>
|
|
{/* Desktop table */}
|
|
<div
|
|
className="inv-desktop"
|
|
style={{ border: '1px solid #E7E7E7', borderRadius: 8, overflow: 'hidden' }}
|
|
>
|
|
<table className="inv-table">
|
|
<thead>
|
|
<tr>{HEAD.map((h) => <th key={h}>{h}</th>)}</tr>
|
|
</thead>
|
|
<tbody>
|
|
{items.map((item) => (
|
|
<tr key={item.uuid}>
|
|
<td style={{ color: 'var(--text-2)' }}>{item.name}</td>
|
|
<td style={{ color: 'var(--text-3)' }}>{item.category ?? '—'}</td>
|
|
<td>{formatNumber(item.stock)}</td>
|
|
<td>{item.unit}</td>
|
|
<td>{formatRial(item.price)}</td>
|
|
<td><InventoryStatusBadge status={item.status} /></td>
|
|
<td><InventoryActionsMenu item={item} onEdit={onEdit} onDelete={onDelete} /></td>
|
|
</tr>
|
|
))}
|
|
</tbody>
|
|
</table>
|
|
</div>
|
|
|
|
{/* Mobile cards */}
|
|
<ul
|
|
className="inv-mobile"
|
|
style={{ gridTemplateColumns: 'repeat(auto-fill, minmax(260px, 1fr))', gap: 16, margin: 0, padding: 0, listStyle: 'none' }}
|
|
>
|
|
{items.map((item) => (
|
|
<li
|
|
key={item.uuid}
|
|
style={{
|
|
padding: 12, background: 'var(--surface)', border: '1px solid var(--border)',
|
|
borderRadius: 8, boxShadow: 'var(--shadow-sm)',
|
|
}}
|
|
>
|
|
<div style={{ display: 'flex', alignItems: 'center', justifyContent: 'space-between', marginBottom: 12 }}>
|
|
<span style={{ color: 'var(--text)', fontSize: 14, fontWeight: 600 }}>{item.name}</span>
|
|
<InventoryStatusBadge status={item.status} />
|
|
</div>
|
|
{[
|
|
['دستهبندی:', item.category ?? '—'],
|
|
['موجودی:', formatNumber(item.stock)],
|
|
['واحد:', item.unit],
|
|
['قیمت:', formatRial(item.price)],
|
|
].map(([label, value], i, arr) => (
|
|
<div key={label}>
|
|
<div style={{ display: 'flex', alignItems: 'center', justifyContent: 'space-between', gap: 12 }}>
|
|
<span style={{ color: 'var(--text-3)', fontSize: 14 }}>{label}</span>
|
|
<span style={{ color: 'var(--text-2)', fontSize: 14, fontWeight: 500 }}>{value}</span>
|
|
</div>
|
|
{i < arr.length - 1 && (
|
|
<div style={{ height: 1, background: 'var(--border)', margin: '8px auto', width: 'calc(100% - 20px)' }} />
|
|
)}
|
|
</div>
|
|
))}
|
|
{(canUpdate || canDelete) && (
|
|
<div style={{ display: 'flex', justifyContent: 'flex-end', gap: 8, marginTop: 12 }}>
|
|
{canUpdate && (
|
|
<button className="btn sm ghost" aria-label="ویرایش" onClick={() => onEdit(item)} style={{ color: 'var(--text-2)' }}>
|
|
<PencilSquareIcon style={{ width: 16 }} />
|
|
</button>
|
|
)}
|
|
{canDelete && (
|
|
<button className="btn sm ghost" aria-label="حذف" onClick={() => onDelete(item)} style={{ color: 'var(--danger)' }}>
|
|
<TrashIcon style={{ width: 16 }} />
|
|
</button>
|
|
)}
|
|
</div>
|
|
)}
|
|
</li>
|
|
))}
|
|
</ul>
|
|
</div>
|
|
);
|
|
}
|