PluginProbe
FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration / trunk
FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration vtrunk
2.1.0 2.0.15 2.0.12 2.0.10 2.0.4 2.0.1 2.0.0 1.95.3 1.95.2 1.95 1.91.6 trunk 1.11 1.12 1.13 1.20 1.21 1.22 1.23 1.30 1.31 1.32 1.35 1.40 1.41 All 42 releases
fluent-boards / app / Services / AttachmentAccessService.php

AttachmentAccessService.php in FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration trunk, at app/Services/AttachmentAccessService.php

76 lines 2.4 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 namespace FluentBoards\App\Services;
4
5 use FluentBoards\App\Models\Attachment;
6 use FluentBoards\App\Models\Board;
7 use FluentBoards\App\Models\Comment;
8 use FluentBoards\App\Models\Task;
9
10 class AttachmentAccessService
11 {
12 /**
13 * Return the attachment's trusted board ID if the current visitor may read it, or zero.
14 * URL hashes and legacy signatures identify images; they never grant access.
15 */
16 public function getAccessibleBoardId(Attachment $attachment)
17 {
18 $boardId = $this->getBoardId($attachment);
19 if (!$boardId) {
20 return 0;
21 }
22
23 $board = Board::find($boardId);
24 if (!$board) {
25 return 0;
26 }
27
28 // Unsaved uploads remain private to their uploader, who must still have board access.
29 if (empty($attachment->object_id)) {
30 $settings = $attachment->settings;
31 if (absint($settings[Constant::ATTACHMENT_UPLOAD_USER_ID] ?? 0) !== get_current_user_id()) {
32 return 0;
33 }
34
35 return PermissionManager::userHasPermission($boardId) ? $boardId : 0;
36 }
37
38 if (PermissionManager::userHasPermission($boardId)) {
39 return $boardId;
40 }
41
42 // PublicBoardController exposes board backgrounds, but hides task descriptions and comments.
43 if ($attachment->object_type === Constant::BOARD_BACKGROUND_IMAGE
44 && !$board->archived_at
45 && $board->getMetaByKey('public_access_enabled')) {
46 return $boardId;
47 }
48
49 return 0;
50 }
51
52 private function getBoardId(Attachment $attachment)
53 {
54 if ($attachment->object_type === Constant::COMMENT_IMAGE) {
55 if (empty($attachment->object_id)) {
56 $settings = $attachment->settings;
57 return absint($settings[Constant::ATTACHMENT_UPLOAD_BOARD_ID] ?? 0);
58 }
59
60 $comment = Comment::withoutGlobalScopes()->find($attachment->object_id);
61 return $comment ? absint($comment->board_id) : 0;
62 }
63
64 if ($attachment->object_type === Constant::TASK_DESCRIPTION) {
65 $task = Task::find($attachment->object_id);
66 return $task ? absint($task->board_id) : 0;
67 }
68
69 if ($attachment->object_type === Constant::BOARD_BACKGROUND_IMAGE) {
70 return absint($attachment->object_id);
71 }
72
73 return 0;
74 }
75 }
76