Add IsMenuItemAuthorizedForRfidAsync to IEmployeeLookupService / EmployeeLookupService to validate menu access by joining employee_rfid_tag and employee_menu_item_tag. Update RfidService.ProcessScanDetailed to filter HRMS menu items against this authorization, block scans when no authorized item remains, and return a clear "No menu item selected." message while logging failures. This ensures only menu items explicitly tagged for a given RFID can be ordered, and prevents unauthorized or unmapped items from creating transactions.
Add LocationSiteId to HrmsEmployeeInfo populated from employee_rfid_tag.location_site_id.
Update EmployeeLookupService query to select and map the site id.
Change ScannerDashboardViewModel to load lunch_menu_week using the site id from the scanned employee’s RFID tag instead of only config.