Security fixes N4/H2/H1 + hide template editor for non-admins

This commit is contained in:
Kühn
2026-08-28 10:15:31 +02:00
parent a35721abec
commit 03d20b0e09
19 changed files with 31 additions and 56 deletions

View File

@@ -1,3 +0,0 @@
# Frontend Environment Variables
# API base URL for backend (default: http://localhost:5000/api)
VITE_API_BASE=http://localhost:5000/api

View File

@@ -50,8 +50,14 @@ function AppContent() {
};
// Punkt 1: Immediate tab switch - no skeleton/transition delay to avoid bounce
// Admin-only tabs: non-admins are redirected to dashboard (defense in depth)
const ADMIN_TABS = ['templates', 'tasks', 'users', 'auditlog'];
const handleTabChange = (newTab) => {
if (newTab === activeTab) return;
if (user?.role !== 'admin' && ADMIN_TABS.includes(newTab)) {
setActiveTab('dashboard');
return;
}
setActiveTab(newTab);
};

View File

@@ -27,7 +27,8 @@ export default function Sidebar({ activeTab, onTabChange }) {
const tabs = [
{ id: 'dashboard', label: 'Vorlagen' },
{ id: 'templates', label: 'Vorlageneditor' },
// Vorlageneditor nur für Admins sichtbar
...(user?.role === 'admin' ? [{ id: 'templates', label: 'Vorlageneditor' }] : []),
...(user?.role === 'admin' ? [{ id: 'tasks', label: 'Aufgaben' }] : []),
...(user?.role === 'admin' ? [{ id: 'users', label: 'Nutzerverwaltung' }] : []),
...(user?.role === 'admin' ? [{ id: 'auditlog', label: 'Audit-Log' }] : []),