PluginProbe
Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution / 2.5.0
Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution v2.5.0
2.5.0 2.4.0 2.3.0 2.2.5 2.2.0 2.1.2 2.1.1 trunk 1.10.0 1.10.01 1.10.02 1.5.0 1.5.01 1.5.02 1.5.1 1.5.10 1.5.20 1.5.21 1.5.22 1.5.23 1.5.24 1.5.25 1.6.0 1.7.0 1.7.1 All 34 releases
← All changes | app/Http/Policies/CalendarEventPolicy.php +46 -5 1.10.01 → 2.5.0 View file →
@@ -4,9 +4,11 @@
4 4
5 5 use FluentBooking\App\Services\PermissionManager;
6 6 use FluentBooking\Framework\Http\Request\Request;
7 7 use FluentBooking\Framework\Foundation\Policy;
8 +use FluentBooking\App\Models\Booking;
8 9 use FluentBooking\App\Models\CalendarSlot;
10 +use FluentBooking\Framework\Support\Arr;
9 11
10 12 class CalendarEventPolicy extends Policy
11 13 {
12 14 /**
@@ -15,14 +17,20 @@
15 17 * @return Boolean
16 18 */
17 19 public function verifyRequest(Request $request)
18 20 {
19 - if (current_user_can('manage_options') || PermissionManager::userCan('manage_other_calendars')) {
21 + if (PermissionManager::userCan(['manage_all_data', 'manage_other_calendars'])) {
20 22 return true;
21 23 }
22 24
23 - if ($request->event_id) {
24 - $calendarEvent = CalendarSlot::find($request->event_id);
25 + // Resolve event_id from the URL route only — request-body values
26 + // must not be permitted to redirect the authorization target.
27 + // The /bookings/ index route has no placeholder so guard the access.
28 + $urlParams = (array) $request->get_url_params();
29 + $eventId = isset($urlParams['event_id']) ? (int) $urlParams['event_id'] : 0;
30 +
31 + if ($eventId) {
32 + $calendarEvent = CalendarSlot::find($eventId);
25 33 if (!$calendarEvent) {
26 34 return false;
27 35 }
28 36 return in_array(get_current_user_id(), $calendarEvent->getHostIds());
@@ -27,11 +35,44 @@
27 35 }
28 36 return in_array(get_current_user_id(), $calendarEvent->getHostIds());
29 37 }
30 38
31 - if ($request->method() == 'GET') {
32 - return PermissionManager::userCan('read_other_calendars');
39 + if ($request->getMethod() == 'GET') {
40 + return PermissionManager::userCan(['manage_all_data', 'read_other_calendars']);
33 41 }
34 42
35 43 return false;
44 + }
45 +
46 + public function rescheduleBooking(Request $request)
47 + {
48 + return $this->canRescheduleRouteBooking($request);
49 + }
50 +
51 + public function getRescheduleSlots(Request $request)
52 + {
53 + return $this->canRescheduleRouteBooking($request);
54 + }
55 +
56 + /**
57 + * The manage_all_bookings bypass is scoped to the booking in the URL, so it
58 + * never widens access to events that are not being rescheduled.
59 + */
60 + private function canRescheduleRouteBooking(Request $request)
61 + {
62 + $urlParams = (array) $request->get_url_params();
63 + $bookingId = (int) Arr::get($urlParams, 'id');
64 + $eventId = (int) Arr::get($urlParams, 'event_id');
65 +
66 + $booking = $bookingId ? Booking::find($bookingId) : null;
67 +
68 + if (!$booking || (int) $booking->event_id !== $eventId) {
69 + return false;
70 + }
71 +
72 + if (PermissionManager::userCan(['manage_all_data', 'manage_all_bookings'])) {
73 + return true;
74 + }
75 +
76 + return $this->verifyRequest($request);
36 77 }
37 78 }