| @@ -4,9 +4,11 @@ | ||
| 4 | 4 | |
| 5 | 5 | use FluentBooking\App\Services\PermissionManager; |
| 6 | 6 | use FluentBooking\Framework\Http\Request\Request; |
| 7 | 7 | use FluentBooking\Framework\Foundation\Policy; |
| 8 | +use FluentBooking\App\Models\Booking; | |
| 8 | 9 | use FluentBooking\App\Models\CalendarSlot; |
| 10 | +use FluentBooking\Framework\Support\Arr; | |
| 9 | 11 | |
| 10 | 12 | class CalendarEventPolicy extends Policy |
| 11 | 13 | { |
| 12 | 14 | /** |
| @@ -38,6 +40,39 @@ | ||
| 38 | 40 | return PermissionManager::userCan(['manage_all_data', 'read_other_calendars']); |
| 39 | 41 | } |
| 40 | 42 | |
| 41 | 43 | return false; |
| 44 | + } | |
| 45 | + | |
| 46 | + public function rescheduleBooking(Request $request) | |
| 47 | + { | |
| 48 | + return $this->canRescheduleRouteBooking($request); | |
| 49 | + } | |
| 50 | + | |
| 51 | + public function getRescheduleSlots(Request $request) | |
| 52 | + { | |
| 53 | + return $this->canRescheduleRouteBooking($request); | |
| 54 | + } | |
| 55 | + | |
| 56 | + /** | |
| 57 | + * The manage_all_bookings bypass is scoped to the booking in the URL, so it | |
| 58 | + * never widens access to events that are not being rescheduled. | |
| 59 | + */ | |
| 60 | + private function canRescheduleRouteBooking(Request $request) | |
| 61 | + { | |
| 62 | + $urlParams = (array) $request->get_url_params(); | |
| 63 | + $bookingId = (int) Arr::get($urlParams, 'id'); | |
| 64 | + $eventId = (int) Arr::get($urlParams, 'event_id'); | |
| 65 | + | |
| 66 | + $booking = $bookingId ? Booking::find($bookingId) : null; | |
| 67 | + | |
| 68 | + if (!$booking || (int) $booking->event_id !== $eventId) { | |
| 69 | + return false; | |
| 70 | + } | |
| 71 | + | |
| 72 | + if (PermissionManager::userCan(['manage_all_data', 'manage_all_bookings'])) { | |
| 73 | + return true; | |
| 74 | + } | |
| 75 | + | |
| 76 | + return $this->verifyRequest($request); | |
| 42 | 77 | } |
| 43 | 78 | } |