PluginProbe
Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution / 2.3.0
Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution v2.3.0
2.4.0 2.3.0 2.2.5 2.2.0 2.1.2 2.1.1 trunk 1.10.0 1.10.01 1.10.02 1.5.0 1.5.01 1.5.02 1.5.1 1.5.10 1.5.20 1.5.21 1.5.22 1.5.23 1.5.24 1.5.25 1.6.0 1.7.0 1.7.1 1.7.2 All 33 releases
fluent-booking / app / Http / Policies / CalendarEventPolicy.php

CalendarEventPolicy.php in Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution 2.3.0, at app/Http/Policies/CalendarEventPolicy.php

44 lines 1.4 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 namespace FluentBooking\App\Http\Policies;
4
5 use FluentBooking\App\Services\PermissionManager;
6 use FluentBooking\Framework\Http\Request\Request;
7 use FluentBooking\Framework\Foundation\Policy;
8 use FluentBooking\App\Models\CalendarSlot;
9
10 class CalendarEventPolicy extends Policy
11 {
12 /**
13 * Check user permission for any method
14 * @param \FluentBooking\Framework\Http\Request\Request $request
15 * @return Boolean
16 */
17 public function verifyRequest(Request $request)
18 {
19 if (PermissionManager::userCan(['manage_all_data', 'manage_other_calendars'])) {
20 return true;
21 }
22
23 // Resolve event_id from the URL route only — request-body values
24 // must not be permitted to redirect the authorization target.
25 // The /bookings/ index route has no placeholder so guard the access.
26 $urlParams = (array) $request->get_url_params();
27 $eventId = isset($urlParams['event_id']) ? (int) $urlParams['event_id'] : 0;
28
29 if ($eventId) {
30 $calendarEvent = CalendarSlot::find($eventId);
31 if (!$calendarEvent) {
32 return false;
33 }
34 return in_array(get_current_user_id(), $calendarEvent->getHostIds());
35 }
36
37 if ($request->getMethod() == 'GET') {
38 return PermissionManager::userCan(['manage_all_data', 'read_other_calendars']);
39 }
40
41 return false;
42 }
43 }
44