diff --git a/backend/routes/api.py b/backend/routes/api.py index a79ca76..3246280 100644 --- a/backend/routes/api.py +++ b/backend/routes/api.py @@ -30,10 +30,7 @@ def get_active_year(school_id=None): @login_required def doelen_index(): data = load_index() - if not data['vakken']: - return jsonify({ - 'error': 'Geen doelen gevonden. Upload eerst de JSON bestanden via het beheerderspaneel.' - }), 404 + # Altijd een geldig object teruggeven — lege vakkenlijst is geen fout return jsonify(data) @@ -126,6 +123,7 @@ def save_assessment(): detail={'status': status}) return jsonify({'assessment': assessment.to_dict()}) + @api_bp.route('/assessments/bulk-import', methods=['POST']) @login_required @limiter.limit('5 per minute') @@ -151,6 +149,7 @@ def bulk_import_assessments(): fouten = 0 for vak_id, vak_data in vakken.items(): + # Sanitiseer vak_id if not isinstance(vak_id, str) or len(vak_id) > 100: fouten += 1 continue @@ -201,6 +200,7 @@ def bulk_import_assessments(): detail={'totaal': totaal, 'fouten': fouten}) return jsonify({'totaal': totaal, 'fouten': fouten}) + # ── Directeur schooloverzicht ────────────────────────────────────────────────── @api_bp.route('/school/overview') diff --git a/backend/templates/admin.html b/backend/templates/admin.html index 8d63089..4eaf32e 100644 --- a/backend/templates/admin.html +++ b/backend/templates/admin.html @@ -325,15 +325,20 @@
diff --git a/backend/templates/directeur.html b/backend/templates/directeur.html index 9bc292f..cd2ffad 100644 --- a/backend/templates/directeur.html +++ b/backend/templates/directeur.html @@ -349,6 +349,11 @@
diff --git a/backend/templates/doelen_beheer.html b/backend/templates/doelen_beheer.html index 94e32ee..222da4e 100644 --- a/backend/templates/doelen_beheer.html +++ b/backend/templates/doelen_beheer.html @@ -181,18 +181,23 @@
diff --git a/backend/templates/scholengroep_ict.html b/backend/templates/scholengroep_ict.html index 953a01d..7ff32f3 100644 --- a/backend/templates/scholengroep_ict.html +++ b/backend/templates/scholengroep_ict.html @@ -333,6 +333,11 @@ toevoegen
diff --git a/backend/templates/school_ict.html b/backend/templates/school_ict.html index 0f377d5..8e9068e 100644 --- a/backend/templates/school_ict.html +++ b/backend/templates/school_ict.html @@ -319,6 +319,11 @@
diff --git a/backend/templates/superadmin_login.html b/backend/templates/superadmin_login.html index cde44a2..e0d330d 100644 --- a/backend/templates/superadmin_login.html +++ b/backend/templates/superadmin_login.html @@ -244,9 +244,12 @@