PluginProbe
Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution / 2.5.0
Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution v2.5.0
2.5.0 2.4.0 2.3.0 2.2.5 2.2.0 2.1.2 2.1.1 trunk 1.10.0 1.10.01 1.10.02 1.5.0 1.5.01 1.5.02 1.5.1 1.5.10 1.5.20 1.5.21 1.5.22 1.5.23 1.5.24 1.5.25 1.6.0 1.7.0 1.7.1 All 34 releases
← All changes | app/Http/Policies/AvailabilityPolicy.php +10 -5 1.10.0 → 2.5.0 View file →
@@ -14,19 +14,24 @@
14 14 * @return Boolean
15 15 */
16 16 public function verifyRequest(Request $request)
17 17 {
18 - if (current_user_can('manage_options') || PermissionManager::userCan('manage_other_availabilities')) {
18 + if (PermissionManager::userCan(['manage_all_data', 'manage_other_availabilities'])) {
19 19 return true;
20 20 }
21 21
22 - if ($request->method() == 'GET' && PermissionManager::userCan('read_and_use_other_availabilities')) {
22 + if ($request->getMethod() == 'GET' && PermissionManager::userCan('read_and_use_other_availabilities')) {
23 23 return true;
24 24 }
25 25
26 - if ($request->schedule_id) {
27 - $availability = \FluentBooking\App\Models\Availability::find($request->schedule_id);
28 -
26 + // Resolve the schedule from the URL route only — request-body values
27 + // must not be permitted to redirect the authorization target.
28 + $urlParams = (array) $request->get_url_params();
29 + $scheduleId = isset($urlParams['schedule_id']) ? (int) $urlParams['schedule_id'] : 0;
30 +
31 + if ($scheduleId) {
32 + $availability = \FluentBooking\App\Models\Availability::find($scheduleId);
33 +
29 34 if (!$availability) {
30 35 return false;
31 36 }
32 37