Разграничесние доступа к запросам

This commit is contained in:
Anton Kamalov
2024-10-24 21:17:22 +03:00
parent e97300f860
commit ec31c49b0e
3 changed files with 6 additions and 4 deletions

View File

@@ -16,7 +16,7 @@ requests_bp = Blueprint('requests_bp', __name__, template_folder='templates')
@check_auth @check_auth
def requests(): def requests():
if request.method == 'GET': if request.method == 'GET':
return render_template('zapros_menu.html', options=requests_list) return render_template('zapros_menu.html', options=requests_list, current_role=session['role'])
@requests_bp.route('/req1', methods=['GET', 'POST']) @requests_bp.route('/req1', methods=['GET', 'POST'])
@check_auth @check_auth

View File

@@ -12,7 +12,9 @@
<h1>Выберите вариант запроса</h1> <h1>Выберите вариант запроса</h1>
<nav class="menu"> <nav class="menu">
{% for point in options %} {% for point in options %}
<a href="{{ url_for(point['url']) }}"><button>{{ point['name'] }}</button></a> {% if current_role in point['roles'] %}
<a href="{{ url_for(point['url']) }}"><button>{{ point['name'] }}</button></a>
{% endif %}
{% endfor %} {% endfor %}
</nav> </nav>
<div class="return"> <div class="return">

View File

@@ -1,4 +1,4 @@
[ [
{"name": "Материалы заготовок", "url": "requests_bp.sklad_zapros"}, {"name": "Материалы заготовок", "url": "requests_bp.sklad_zapros", "roles" : "admin, user"},
{"name": "Поставки заготовок", "url": "requests_bp.zagotovki_ship"} {"name": "Поставки заготовок", "url": "requests_bp.zagotovki_ship", "roles" : "admin, user"}
] ]