| @@ -14,19 +14,24 @@ | ||
| 14 | 14 | * @return Boolean |
| 15 | 15 | */ |
| 16 | 16 | public function verifyRequest(Request $request) |
| 17 | 17 | { |
| 18 | - if (current_user_can('manage_options') || PermissionManager::userCan('manage_other_availabilities')) { | |
| 18 | + if (PermissionManager::userCan(['manage_all_data', 'manage_other_availabilities'])) { | |
| 19 | 19 | return true; |
| 20 | 20 | } |
| 21 | 21 | |
| 22 | - if ($request->method() == 'GET' && PermissionManager::userCan('read_and_use_other_availabilities')) { | |
| 22 | + if ($request->getMethod() == 'GET' && PermissionManager::userCan('read_and_use_other_availabilities')) { | |
| 23 | 23 | return true; |
| 24 | 24 | } |
| 25 | 25 | |
| 26 | - if ($request->schedule_id) { | |
| 27 | - $availability = \FluentBooking\App\Models\Availability::find($request->schedule_id); | |
| 28 | - | |
| 26 | + // Resolve the schedule from the URL route only — request-body values | |
| 27 | + // must not be permitted to redirect the authorization target. | |
| 28 | + $urlParams = (array) $request->get_url_params(); | |
| 29 | + $scheduleId = isset($urlParams['schedule_id']) ? (int) $urlParams['schedule_id'] : 0; | |
| 30 | + | |
| 31 | + if ($scheduleId) { | |
| 32 | + $availability = \FluentBooking\App\Models\Availability::find($scheduleId); | |
| 33 | + | |
| 29 | 34 | if (!$availability) { |
| 30 | 35 | return false; |
| 31 | 36 | } |
| 32 | 37 | |