PluginProbe
Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution / 2.3.0
Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution v2.3.0
2.4.0 2.3.0 2.2.5 2.2.0 2.1.2 2.1.1 trunk 1.10.0 1.10.01 1.10.02 1.5.0 1.5.01 1.5.02 1.5.1 1.5.10 1.5.20 1.5.21 1.5.22 1.5.23 1.5.24 1.5.25 1.6.0 1.7.0 1.7.1 1.7.2 All 33 releases
fluent-booking / app / Http / Policies / AvailabilityPolicy.php

AvailabilityPolicy.php in Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution 2.3.0, at app/Http/Policies/AvailabilityPolicy.php

44 lines 1.4 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 namespace FluentBooking\App\Http\Policies;
4
5 use FluentBooking\App\Services\PermissionManager;
6 use FluentBooking\Framework\Http\Request\Request;
7 use FluentBooking\Framework\Foundation\Policy;
8
9 class AvailabilityPolicy extends Policy
10 {
11 /**
12 * Check user permission for any method
13 * @param \FluentBooking\Framework\Http\Request\Request; $request
14 * @return Boolean
15 */
16 public function verifyRequest(Request $request)
17 {
18 if (PermissionManager::userCan(['manage_all_data', 'manage_other_availabilities'])) {
19 return true;
20 }
21
22 if ($request->getMethod() == 'GET' && PermissionManager::userCan('read_and_use_other_availabilities')) {
23 return true;
24 }
25
26 // Resolve the schedule from the URL route only — request-body values
27 // must not be permitted to redirect the authorization target.
28 $urlParams = (array) $request->get_url_params();
29 $scheduleId = isset($urlParams['schedule_id']) ? (int) $urlParams['schedule_id'] : 0;
30
31 if ($scheduleId) {
32 $availability = \FluentBooking\App\Models\Availability::find($scheduleId);
33
34 if (!$availability) {
35 return false;
36 }
37
38 return (int)$availability->object_id === get_current_user_id();
39 }
40
41 return PermissionManager::userCan('manage_own_calendar');
42 }
43 }
44