PluginProbe
Fluent Support – Helpdesk & Customer Support Ticket System / trunk
Fluent Support – Helpdesk & Customer Support Ticket System vtrunk
2.3.2 2.3.1 2.3.0 2.2.1 2.2.0 trunk 1.10.0 1.10.1 1.10.2 1.10.3 1.10.4 1.10.5 1.4.0 1.4.1 1.4.2 1.4.5 1.4.6 1.4.7 1.5.0 1.5.1 1.5.2 1.5.3 1.5.4 1.5.5 1.5.6 All 67 releases
fluent-support / app / Http / Policies / AgentPolicy.php

AgentPolicy.php in Fluent Support – Helpdesk & Customer Support Ticket System trunk, at app/Http/Policies/AgentPolicy.php

68 lines 2.0 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 namespace FluentSupport\App\Http\Policies;
4
5 use FluentSupport\App\Modules\PermissionManager;
6 use FluentSupport\Framework\Http\Request\Request;
7 use FluentSupport\Framework\Foundation\Policy;
8
9 class AgentPolicy extends Policy
10 {
11 /**
12 * Check user permission for any method
13 * @param \FluentSupport\Framework\Http\Request\Request $request
14 * @return Boolean
15 */
16 public function verifyRequest(Request $request)
17 {
18 // Read access (index) and avatar routes keep the existing boundary.
19 return PermissionManager::currentUserCan('fst_sensitive_data');
20 }
21
22 public function addAgent(Request $request)
23 {
24 return $this->guardManageOptions();
25 }
26
27 public function updateAgent(Request $request)
28 {
29 return $this->guardManageOptions();
30 }
31
32 public function deleteAgent(Request $request)
33 {
34 return $this->guardManageOptions();
35 }
36
37 /**
38 * Agent records carry the plugin's permission set, so mutating them is a
39 * privilege-granting operation. Gate on a WordPress capability the plugin's
40 * own permission system cannot mint. Throwing (not returning
41 * false) surfaces a specific message instead of WordPress core's generic
42 * "Sorry, you are not allowed to do that." The exception code is carried
43 * through as the HTTP status by Route::permissionCallback(), so anonymous
44 * callers get the canonical 401 rather than 403.
45 *
46 * @return Boolean
47 * @throws \Exception
48 */
49 protected function guardManageOptions()
50 {
51 if (current_user_can('manage_options')) {
52 return true;
53 }
54
55 if (!is_user_logged_in()) {
56 throw new \Exception(
57 esc_html__('You must be logged in to perform this action.', 'fluent-support'),
58 401
59 );
60 }
61
62 throw new \Exception(
63 esc_html__('Only administrators can add, edit, or delete support staff.', 'fluent-support'),
64 403
65 );
66 }
67 }
68