PluginProbe
Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution / 2.5.0
Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution v2.5.0
2.5.0 2.4.0 2.3.0 2.2.5 2.2.0 2.1.2 2.1.1 trunk 1.10.0 1.10.01 1.10.02 1.5.0 1.5.01 1.5.02 1.5.1 1.5.10 1.5.20 1.5.21 1.5.22 1.5.23 1.5.24 1.5.25 1.6.0 1.7.0 1.7.1 All 34 releases
← All changes | app/Http/Policies/CalendarEventPolicy.php +36 -1 2.2.0 → 2.5.0 View file →
@@ -4,9 +4,11 @@
4 4
5 5 use FluentBooking\App\Services\PermissionManager;
6 6 use FluentBooking\Framework\Http\Request\Request;
7 7 use FluentBooking\Framework\Foundation\Policy;
8 +use FluentBooking\App\Models\Booking;
8 9 use FluentBooking\App\Models\CalendarSlot;
10 +use FluentBooking\Framework\Support\Arr;
9 11
10 12 class CalendarEventPolicy extends Policy
11 13 {
12 14 /**
@@ -33,11 +35,44 @@
33 35 }
34 36 return in_array(get_current_user_id(), $calendarEvent->getHostIds());
35 37 }
36 38
37 - if ($request->method() == 'GET') {
39 + if ($request->getMethod() == 'GET') {
38 40 return PermissionManager::userCan(['manage_all_data', 'read_other_calendars']);
39 41 }
40 42
41 43 return false;
44 + }
45 +
46 + public function rescheduleBooking(Request $request)
47 + {
48 + return $this->canRescheduleRouteBooking($request);
49 + }
50 +
51 + public function getRescheduleSlots(Request $request)
52 + {
53 + return $this->canRescheduleRouteBooking($request);
54 + }
55 +
56 + /**
57 + * The manage_all_bookings bypass is scoped to the booking in the URL, so it
58 + * never widens access to events that are not being rescheduled.
59 + */
60 + private function canRescheduleRouteBooking(Request $request)
61 + {
62 + $urlParams = (array) $request->get_url_params();
63 + $bookingId = (int) Arr::get($urlParams, 'id');
64 + $eventId = (int) Arr::get($urlParams, 'event_id');
65 +
66 + $booking = $bookingId ? Booking::find($bookingId) : null;
67 +
68 + if (!$booking || (int) $booking->event_id !== $eventId) {
69 + return false;
70 + }
71 +
72 + if (PermissionManager::userCan(['manage_all_data', 'manage_all_bookings'])) {
73 + return true;
74 + }
75 +
76 + return $this->verifyRequest($request);
42 77 }
43 78 }