PluginProbe
Fluent Support – Helpdesk & Customer Support Ticket System / 2.3.1
Fluent Support – Helpdesk & Customer Support Ticket System v2.3.1
2.4.0 2.3.2 2.3.1 2.3.0 2.2.1 2.2.0 trunk 1.10.0 1.10.1 1.10.2 1.10.3 1.10.4 1.10.5 1.4.0 1.4.1 1.4.2 1.4.5 1.4.6 1.4.7 1.5.0 1.5.1 1.5.2 1.5.3 1.5.4 1.5.5 All 68 releases
fluent-support / app / Http / Policies / AgentPolicy.php

AgentPolicy.php in Fluent Support – Helpdesk & Customer Support Ticket System 2.3.1, at app/Http/Policies/AgentPolicy.php

58 lines 1.6 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 namespace FluentSupport\App\Http\Policies;
4
5 use FluentSupport\App\Modules\PermissionManager;
6 use FluentSupport\Framework\Http\Request\Request;
7 use FluentSupport\Framework\Foundation\Policy;
8
9 class AgentPolicy extends Policy
10 {
11 /**
12 * Check user permission for any method
13 * @param \FluentSupport\Framework\Http\Request\Request $request
14 * @return Boolean
15 */
16 public function verifyRequest(Request $request)
17 {
18 // Read access (index) and avatar routes keep the existing boundary.
19 return PermissionManager::currentUserCan('fst_sensitive_data');
20 }
21
22 public function addAgent(Request $request)
23 {
24 return $this->guardManageOptions();
25 }
26
27 public function updateAgent(Request $request)
28 {
29 return $this->guardManageOptions();
30 }
31
32 public function deleteAgent(Request $request)
33 {
34 return $this->guardManageOptions();
35 }
36
37 /**
38 * Agent records carry the plugin's permission set, so mutating them is a
39 * privilege-granting operation. Gate on a WordPress capability the plugin's
40 * own permission system cannot mint (FS-SEC-003). Throwing (not returning
41 * false) surfaces a specific 403 message instead of WordPress core's
42 * generic "Sorry, you are not allowed to do that."
43 *
44 * @return Boolean
45 * @throws \Exception
46 */
47 protected function guardManageOptions()
48 {
49 if (current_user_can('manage_options')) {
50 return true;
51 }
52
53 throw new \Exception(
54 esc_html__('Only administrators can add, edit, or delete support staff.', 'fluent-support')
55 );
56 }
57 }
58