PluginProbe
Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution / 2.5.0
Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution v2.5.0
2.5.0 2.4.0 2.3.0 2.2.5 2.2.0 2.1.2 2.1.1 trunk 1.10.0 1.10.01 1.10.02 1.5.0 1.5.01 1.5.02 1.5.1 1.5.10 1.5.20 1.5.21 1.5.22 1.5.23 1.5.24 1.5.25 1.6.0 1.7.0 1.7.1 All 34 releases
fluent-booking / app / Http / Policies / CalendarEventPolicy.php

CalendarEventPolicy.php in Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution 2.5.0, at app/Http/Policies/CalendarEventPolicy.php

79 lines 2.5 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 namespace FluentBooking\App\Http\Policies;
4
5 use FluentBooking\App\Services\PermissionManager;
6 use FluentBooking\Framework\Http\Request\Request;
7 use FluentBooking\Framework\Foundation\Policy;
8 use FluentBooking\App\Models\Booking;
9 use FluentBooking\App\Models\CalendarSlot;
10 use FluentBooking\Framework\Support\Arr;
11
12 class CalendarEventPolicy extends Policy
13 {
14 /**
15 * Check user permission for any method
16 * @param \FluentBooking\Framework\Http\Request\Request $request
17 * @return Boolean
18 */
19 public function verifyRequest(Request $request)
20 {
21 if (PermissionManager::userCan(['manage_all_data', 'manage_other_calendars'])) {
22 return true;
23 }
24
25 // Resolve event_id from the URL route only — request-body values
26 // must not be permitted to redirect the authorization target.
27 // The /bookings/ index route has no placeholder so guard the access.
28 $urlParams = (array) $request->get_url_params();
29 $eventId = isset($urlParams['event_id']) ? (int) $urlParams['event_id'] : 0;
30
31 if ($eventId) {
32 $calendarEvent = CalendarSlot::find($eventId);
33 if (!$calendarEvent) {
34 return false;
35 }
36 return in_array(get_current_user_id(), $calendarEvent->getHostIds());
37 }
38
39 if ($request->getMethod() == 'GET') {
40 return PermissionManager::userCan(['manage_all_data', 'read_other_calendars']);
41 }
42
43 return false;
44 }
45
46 public function rescheduleBooking(Request $request)
47 {
48 return $this->canRescheduleRouteBooking($request);
49 }
50
51 public function getRescheduleSlots(Request $request)
52 {
53 return $this->canRescheduleRouteBooking($request);
54 }
55
56 /**
57 * The manage_all_bookings bypass is scoped to the booking in the URL, so it
58 * never widens access to events that are not being rescheduled.
59 */
60 private function canRescheduleRouteBooking(Request $request)
61 {
62 $urlParams = (array) $request->get_url_params();
63 $bookingId = (int) Arr::get($urlParams, 'id');
64 $eventId = (int) Arr::get($urlParams, 'event_id');
65
66 $booking = $bookingId ? Booking::find($bookingId) : null;
67
68 if (!$booking || (int) $booking->event_id !== $eventId) {
69 return false;
70 }
71
72 if (PermissionManager::userCan(['manage_all_data', 'manage_all_bookings'])) {
73 return true;
74 }
75
76 return $this->verifyRequest($request);
77 }
78 }
79