Repository navigation
Feature/t227 account profile UI - #66
Conversation
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
📝 WalkthroughWalkthroughPR thêm trang hồ sơ người dùng, API tổng quan dashboard, biểu đồ ApexCharts và kiểm tra quyền trước khi gọi API. PR cũng cập nhật trạng thái dashboard và cách hiển thị loại phiếu trong màn hình phê duyệt. ChangesTính năng ứng dụng
Estimated code review effort: 4 (Complex) | ~45 minutes Possibly related PRs
Suggested reviewers: 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 4
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@src/services/profileService.js`:
- Around line 51-56: Update the outer catch in the profile-loading flow to
rethrow normalized 401 errors before checking hasProfileData(fallbackProfile),
so an expired session cannot return stale localStorage data. Preserve the
existing fallback behavior for non-401 errors and avoid logging tokens or
profile data.
- Line 50: Thay đổi nhánh fallback trong hàm xử lý hồ sơ để trả về null khi
normalizeProfile(getCurrentUser()) và tất cả endpoint đều không có dữ liệu, thay
vì trả fallbackProfile rỗng. Giữ nguyên kết quả object cho hồ sơ hợp lệ và đảm
bảo ProfileView.vue nhận null để kích hoạt empty state, không ảnh hưởng loading
hoặc error state.
- Around line 6-11: Thêm cấu hình timeout cho axios instance trong phần khởi tạo
profileClient, sử dụng hằng số API_TIMEOUT_MS như dashboardClient. Giữ nguyên
baseURL và headers hiện có.
In `@src/views/DashboardView.vue`:
- Around line 85-89: Update pendingApprovalsTotal in DashboardView.vue to
conditionally sum importReceipts only when canSeeImportApprovals.value is true
and exportReceipts only when canSeeExportApprovals.value is true, defaulting
unauthorized or missing values to zero while preserving backend authorization
for /api/dashboard/overview.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 9081f4f1-0519-4196-a969-8b0036bb5f40
📒 Files selected for processing (7)
src/components/AppSidebar.vuesrc/router/index.jssrc/services/dashboardService.jssrc/services/profileService.jssrc/views/ApprovalsView.vuesrc/views/DashboardView.vuesrc/views/ProfileView.vue
…shboard approval totals
There was a problem hiding this comment.
Actionable comments posted: 1
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
src/views/DashboardView.vue (1)
252-257: 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick winHiển thị đúng lỗi khi
dashboardOverviewthất bại.Khi
overviewResultbị reject với lỗi khác 401, đoạn này chỉ đặtdashboardOverviewFailed.errorMessagevẫn rỗng. Nếu các API còn lại trả về 0,hasDashboardDatalàfalse, nên Line 603 không vào nhánh lỗi. Người dùng sẽ thấy “Chưa có dữ liệu tổng quan” thay vì lỗi tải dữ liệu.Gán thông báo lỗi chung sau nhánh 401.
As per path instructions,
src/views/**phải xử lý đúng loading, empty state và error state.Đề xuất sửa
if (overviewResult.reason?.status === 401) { isLoading.value = false; isRetrying.value = false; router.replace("/login"); return; } + errorMessage.value = "Không thể tải dữ liệu tổng quan.";🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@src/views/DashboardView.vue` around lines 252 - 257, Update the rejected branch handling overviewResult in DashboardView so non-401 failures also assign the shared errorMessage after the existing 401 handling. Preserve dashboardOverview being cleared and dashboardOverviewFailed being set, ensuring the error state is displayed even when hasDashboardData is false.Source: Path instructions
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@src/services/profileService.js`:
- Around line 52-56: Cập nhật luồng tải hồ sơ trong hàm bao quanh
fallbackProfile để inner catch lưu lỗi cuối cùng từ các endpoint, bao gồm
timeout, lỗi mạng và HTTP ngoài 401/404, thay vì nuốt lỗi. Khi không có
fallbackProfile, hãy ném lỗi cuối; chỉ trả null khi mọi endpoint hoàn tất thành
công nhưng không có dữ liệu, đồng thời giữ nguyên hành vi trả fallback khi
fallbackProfile hợp lệ.
---
Outside diff comments:
In `@src/views/DashboardView.vue`:
- Around line 252-257: Update the rejected branch handling overviewResult in
DashboardView so non-401 failures also assign the shared errorMessage after the
existing 401 handling. Preserve dashboardOverview being cleared and
dashboardOverviewFailed being set, ensuring the error state is displayed even
when hasDashboardData is false.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: d2d29068-7dd5-450e-a32a-e90f5a4eba57
📒 Files selected for processing (3)
src/services/profileService.jssrc/views/DashboardView.vuesrc/views/ProfileView.vue
There was a problem hiding this comment.
Actionable comments posted: 1
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
src/views/DashboardView.vue (1)
240-245: 🔒 Security & Privacy | 🟡 Minor | ⚡ Quick winKiểm tra quyền trước khi tải và hiển thị KPI sản phẩm/kho.
loadProductCount()vàloadWarehouseCount()luôn chạy, dùEMPLOYEEbị router chặn/productsvà/warehouses. Điều này có thể gây lỗi 403 trên banner chung và hiển thị số lượng tài nguyên ngoài quyền trên dashboard. Đổi lại, chỉ gọi API và hiển thị KPI khicanAccessRoute("/products")hoặccanAccessRoute("/warehouses")cho phép; backend cũng cần kiểm tra quyền khi trả về tổng số.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@src/views/DashboardView.vue` around lines 240 - 245, Update the Promise.allSettled flow in DashboardView so loadProductCount and loadWarehouseCount are invoked only when canAccessRoute("/products") and canAccessRoute("/warehouses") respectively allow access, and hide or omit their KPI values otherwise while preserving the overview request. Also enforce the same route permissions in the backend endpoints that return product and warehouse totals.Source: Path instructions
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@src/services/profileService.js`:
- Around line 46-49: Trong luồng thử các endpoint của hàm profile service, xử lý
trạng thái 404 trước khi gán giá trị cho lastError. Khi error.response?.status
là 404, tiếp tục endpoint kế tiếp mà không lưu lỗi; chỉ cập nhật lastError cho
các lỗi khác để khi mọi endpoint đều không có hồ sơ, hàm trả về null theo luồng
hiện có.
---
Outside diff comments:
In `@src/views/DashboardView.vue`:
- Around line 240-245: Update the Promise.allSettled flow in DashboardView so
loadProductCount and loadWarehouseCount are invoked only when
canAccessRoute("/products") and canAccessRoute("/warehouses") respectively allow
access, and hide or omit their KPI values otherwise while preserving the
overview request. Also enforce the same route permissions in the backend
endpoints that return product and warehouse totals.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 39afd763-f3ed-45dd-b82f-d6b9fba8e49b
📒 Files selected for processing (2)
src/services/profileService.jssrc/views/DashboardView.vue
| lastError = normalizedError | ||
|
|
||
| if (error.response?.status === 404) { | ||
| continue |
There was a problem hiding this comment.
🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win
Không lưu lỗi 404 vào lastError.
Line 46 lưu 404 trước khi Line 48 chuyển sang endpoint tiếp theo. Nếu tất cả endpoint đều trả 404 và không có fallbackProfile, hàm sẽ ném lỗi 404 tại Line 62 thay vì trả null. UI hồ sơ sẽ hiển thị error state thay vì empty state.
Chỉ gán lastError sau nhánh 404.
Đề xuất sửa
- lastError = normalizedError
-
if (error.response?.status === 404) {
continue
}
+ lastError = normalizedError
+
if (error.response?.status && error.response.status < 500) {🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@src/services/profileService.js` around lines 46 - 49, Trong luồng thử các
endpoint của hàm profile service, xử lý trạng thái 404 trước khi gán giá trị cho
lastError. Khi error.response?.status là 404, tiếp tục endpoint kế tiếp mà không
lưu lỗi; chỉ cập nhật lastError cho các lỗi khác để khi mọi endpoint đều không
có hồ sơ, hàm trả về null theo luồng hiện có.
Source: Path instructions
…g by route permissions
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@src/views/DashboardView.vue`:
- Around line 242-243: Thay thế giá trị giả `overviewResult` trong luồng khởi
tạo `requests` bằng lời gọi API thực tế `getDashboardOverview()`, để kết quả
thành công cập nhật `dashboardOverview.value` và lỗi được xử lý theo flow hiện
có. Kiểm tra lại loading, empty state và error state trong luồng dashboard, đồng
thời giữ nguyên cách xử lý các request khác.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: a2efeeb1-496d-4dd1-b897-ad9e267db8ac
📒 Files selected for processing (3)
src/services/productService.jssrc/services/warehouseService.jssrc/views/DashboardView.vue
…g by route permissions
There was a problem hiding this comment.
Actionable comments posted: 1
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
src/views/DashboardView.vue (1)
246-255: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick winẨn KPI khi role không có quyền truy cập.
Khi
canSeeProductshoặccanSeeWarehouseslàfalse, code thay request bằngPromise.resolve(0). Tuy nhiên template vẫn hiển thị KPI “Tổng sản phẩm” và “Tổng kho” với giá trị0. UI đang hiển thị dữ liệu giả cho tài nguyên bị hạn chế.Chỉ render từng card khi quyền tương ứng được cấp. Đồng thời tính
visibleKpiCardCounttừ cả quyền sản phẩm, kho và tồn kho.As per path instructions, UI phải phản ánh đúng quyền ADMIN/MANAGER/EMPLOYEE.
Đề xuất sửa
-const visibleKpiCardCount = computed(() => (canSeeWarnings.value ? 4 : 2)); +const visibleKpiCardCount = computed( + () => + (canSeeProducts.value ? 1 : 0) + + (canSeeWarehouses.value ? 1 : 0) + + (canSeeWarnings.value ? 2 : 0), +); -<article class="kpi-card"> +<article v-if="canSeeProducts" class="kpi-card"> -<article class="kpi-card"> +<article v-if="canSeeWarehouses" class="kpi-card">🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@src/views/DashboardView.vue` around lines 246 - 255, Update DashboardView’s KPI template to conditionally render the product and warehouse cards only when canSeeProducts and canSeeWarehouses are true, instead of displaying their fallback zero values. Adjust visibleKpiCardCount to derive from product, warehouse, and inventory permissions so the layout reflects ADMIN, MANAGER, and EMPLOYEE access correctly.Source: Path instructions
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@src/views/DashboardView.vue`:
- Around line 242-245: Update the request initialization in the dashboard
loading flow to call loadDashboardOverview() only when the current role can
access at least one of inventory, alerts, approvals, or
pending-export-approvals. Keep product-only roles from requesting or storing
dashboardOverview, while preserving the backend’s per-field permission checks
for roles that do request the overview.
---
Outside diff comments:
In `@src/views/DashboardView.vue`:
- Around line 246-255: Update DashboardView’s KPI template to conditionally
render the product and warehouse cards only when canSeeProducts and
canSeeWarehouses are true, instead of displaying their fallback zero values.
Adjust visibleKpiCardCount to derive from product, warehouse, and inventory
permissions so the layout reflects ADMIN, MANAGER, and EMPLOYEE access
correctly.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 4ec3538a-d854-4e7c-ac8d-9ed9d2f84afc
📒 Files selected for processing (1)
src/views/DashboardView.vue
ThienlocTran
left a comment
There was a problem hiding this comment.
Chưa có backend mà làm đc frontend lun :)) . quá ghê gớm
check giúp tui
Summary by CodeRabbit
Tính năng mới
Sửa lỗi