PluginProbe
Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution / trunk
Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution vtrunk
2.4.0 2.3.0 2.2.5 2.2.0 2.1.2 2.1.1 trunk 1.10.0 1.10.01 1.10.02 1.5.0 1.5.01 1.5.02 1.5.1 1.5.10 1.5.20 1.5.21 1.5.22 1.5.23 1.5.24 1.5.25 1.6.0 1.7.0 1.7.1 1.7.2 All 33 releases
← All changes | app/Http/Policies/AvailabilityPolicy.php +10 -5 1.5.21trunk View file →
@@ -14,19 +14,24 @@
14 14 * @return Boolean
15 15 */
16 16 public function verifyRequest(Request $request)
17 17 {
18 - if (current_user_can('manage_options') || PermissionManager::userCan('manage_other_availabilities')) {
18 + if (PermissionManager::userCan(['manage_all_data', 'manage_other_availabilities'])) {
19 19 return true;
20 20 }
21 21
22 - if ($request->method() == 'GET' && PermissionManager::userCan('read_and_use_other_availabilities')) {
22 + if ($request->getMethod() == 'GET' && PermissionManager::userCan('read_and_use_other_availabilities')) {
23 23 return true;
24 24 }
25 25
26 - if ($request->schedule_id) {
27 - $availability = \FluentBooking\App\Models\Availability::find($request->schedule_id);
28 -
26 + // Resolve the schedule from the URL route only — request-body values
27 + // must not be permitted to redirect the authorization target.
28 + $urlParams = (array) $request->get_url_params();
29 + $scheduleId = isset($urlParams['schedule_id']) ? (int) $urlParams['schedule_id'] : 0;
30 +
31 + if ($scheduleId) {
32 + $availability = \FluentBooking\App\Models\Availability::find($scheduleId);
33 +
29 34 if (!$availability) {
30 35 return false;
31 36 }
32 37