[FIX] point_of_sale: control if a cashier is in localstorage

Before this commit, we could temporarily change cashier from A to B, and back to A seamlessly just by refreshing the page.
This could be a security issue for a cashier is held responsible for its sales.

This commit stores the cashier in localstorage, and with the right sets of methods, corrects the issue.

OPW 767827

closes #19207
This commit is contained in:
Lucas Perais (lpe)
2017-09-05 08:41:33 +02:00
parent dc88a1ac42
commit e14ab69772
2 changed files with 10 additions and 1 deletions
+7
View File
@@ -500,6 +500,13 @@ var PosDB = core.Class.extend({
}
return orders;
},
set_cashier: function(cashier) {
// Always update if the user is the same as before
this.save('cashier', cashier);
},
get_cashier: function() {
return this.load('cashier');
}
});
return PosDB;
+3 -1
View File
@@ -240,6 +240,7 @@ exports.PosModel = Backbone.Model.extend({
}
self.db.set_uuid(self.config.uuid);
self.cashier = self.get_cashier();
var orders = self.db.get_orders();
for (var i = 0; i < orders.length; i++) {
@@ -579,11 +580,12 @@ exports.PosModel = Backbone.Model.extend({
// returns the user who is currently the cashier for this point of sale
get_cashier: function(){
return this.cashier || this.user;
return this.db.get_cashier() || this.cashier || this.user;
},
// changes the current cashier
set_cashier: function(user){
this.cashier = user;
this.db.set_cashier(this.cashier);
},
//creates a new empty order and sets it as the current order
add_new_order: function(){