[FIX] point_of_sale: control if a cashier is in localstorage
Before this commit, we could temporarily change cashier from A to B, and back to A seamlessly just by refreshing the page. This could be a security issue for a cashier is held responsible for its sales. This commit stores the cashier in localstorage, and with the right sets of methods, corrects the issue. OPW 767827 closes #19207
This commit is contained in:
@@ -500,6 +500,13 @@ var PosDB = core.Class.extend({
|
||||
}
|
||||
return orders;
|
||||
},
|
||||
set_cashier: function(cashier) {
|
||||
// Always update if the user is the same as before
|
||||
this.save('cashier', cashier);
|
||||
},
|
||||
get_cashier: function() {
|
||||
return this.load('cashier');
|
||||
}
|
||||
});
|
||||
|
||||
return PosDB;
|
||||
|
||||
@@ -240,6 +240,7 @@ exports.PosModel = Backbone.Model.extend({
|
||||
}
|
||||
|
||||
self.db.set_uuid(self.config.uuid);
|
||||
self.cashier = self.get_cashier();
|
||||
|
||||
var orders = self.db.get_orders();
|
||||
for (var i = 0; i < orders.length; i++) {
|
||||
@@ -579,11 +580,12 @@ exports.PosModel = Backbone.Model.extend({
|
||||
|
||||
// returns the user who is currently the cashier for this point of sale
|
||||
get_cashier: function(){
|
||||
return this.cashier || this.user;
|
||||
return this.db.get_cashier() || this.cashier || this.user;
|
||||
},
|
||||
// changes the current cashier
|
||||
set_cashier: function(user){
|
||||
this.cashier = user;
|
||||
this.db.set_cashier(this.cashier);
|
||||
},
|
||||
//creates a new empty order and sets it as the current order
|
||||
add_new_order: function(){
|
||||
|
||||
Reference in New Issue
Block a user