| @@ -4,9 +4,11 @@ | ||
| 4 | 4 | |
| 5 | 5 | use FluentBooking\App\Services\PermissionManager; |
| 6 | 6 | use FluentBooking\Framework\Http\Request\Request; |
| 7 | 7 | use FluentBooking\Framework\Foundation\Policy; |
| 8 | +use FluentBooking\App\Models\Booking; | |
| 8 | 9 | use FluentBooking\App\Models\CalendarSlot; |
| 10 | +use FluentBooking\Framework\Support\Arr; | |
| 9 | 11 | |
| 10 | 12 | class CalendarEventPolicy extends Policy |
| 11 | 13 | { |
| 12 | 14 | /** |
| @@ -15,14 +17,20 @@ | ||
| 15 | 17 | * @return Boolean |
| 16 | 18 | */ |
| 17 | 19 | public function verifyRequest(Request $request) |
| 18 | 20 | { |
| 19 | - if (current_user_can('manage_options') || PermissionManager::userCan('manage_other_calendars')) { | |
| 21 | + if (PermissionManager::userCan(['manage_all_data', 'manage_other_calendars'])) { | |
| 20 | 22 | return true; |
| 21 | 23 | } |
| 22 | 24 | |
| 23 | - if ($request->event_id) { | |
| 24 | - $calendarEvent = CalendarSlot::find($request->event_id); | |
| 25 | + // Resolve event_id from the URL route only — request-body values | |
| 26 | + // must not be permitted to redirect the authorization target. | |
| 27 | + // The /bookings/ index route has no placeholder so guard the access. | |
| 28 | + $urlParams = (array) $request->get_url_params(); | |
| 29 | + $eventId = isset($urlParams['event_id']) ? (int) $urlParams['event_id'] : 0; | |
| 30 | + | |
| 31 | + if ($eventId) { | |
| 32 | + $calendarEvent = CalendarSlot::find($eventId); | |
| 25 | 33 | if (!$calendarEvent) { |
| 26 | 34 | return false; |
| 27 | 35 | } |
| 28 | 36 | return in_array(get_current_user_id(), $calendarEvent->getHostIds()); |
| @@ -27,11 +35,44 @@ | ||
| 27 | 35 | } |
| 28 | 36 | return in_array(get_current_user_id(), $calendarEvent->getHostIds()); |
| 29 | 37 | } |
| 30 | 38 | |
| 31 | - if ($request->method() == 'GET') { | |
| 32 | - return PermissionManager::userCan('read_other_calendars'); | |
| 39 | + if ($request->getMethod() == 'GET') { | |
| 40 | + return PermissionManager::userCan(['manage_all_data', 'read_other_calendars']); | |
| 33 | 41 | } |
| 34 | 42 | |
| 35 | 43 | return false; |
| 44 | + } | |
| 45 | + | |
| 46 | + public function rescheduleBooking(Request $request) | |
| 47 | + { | |
| 48 | + return $this->canRescheduleRouteBooking($request); | |
| 49 | + } | |
| 50 | + | |
| 51 | + public function getRescheduleSlots(Request $request) | |
| 52 | + { | |
| 53 | + return $this->canRescheduleRouteBooking($request); | |
| 54 | + } | |
| 55 | + | |
| 56 | + /** | |
| 57 | + * The manage_all_bookings bypass is scoped to the booking in the URL, so it | |
| 58 | + * never widens access to events that are not being rescheduled. | |
| 59 | + */ | |
| 60 | + private function canRescheduleRouteBooking(Request $request) | |
| 61 | + { | |
| 62 | + $urlParams = (array) $request->get_url_params(); | |
| 63 | + $bookingId = (int) Arr::get($urlParams, 'id'); | |
| 64 | + $eventId = (int) Arr::get($urlParams, 'event_id'); | |
| 65 | + | |
| 66 | + $booking = $bookingId ? Booking::find($bookingId) : null; | |
| 67 | + | |
| 68 | + if (!$booking || (int) $booking->event_id !== $eventId) { | |
| 69 | + return false; | |
| 70 | + } | |
| 71 | + | |
| 72 | + if (PermissionManager::userCan(['manage_all_data', 'manage_all_bookings'])) { | |
| 73 | + return true; | |
| 74 | + } | |
| 75 | + | |
| 76 | + return $this->verifyRequest($request); | |
| 36 | 77 | } |
| 37 | 78 | } |