firstOrFail(); // These routes carry no company header, so ScopeBouncer is not in their // middleware stack and the ability scope was never set. 'view-financial-reports' // is stored scoped to a company, so the unscoped check always failed and every // report PDF answered 403. Scope to the company named in the URL: the policy // still checks membership, so this grants nothing new. BouncerFacade::scope()->to($company->id); $this->authorize('view report', $company); $locale = CompanySetting::getSetting('language', $company->id); App::setLocale($locale); $items = InvoiceItem::whereCompany($company->id) ->applyInvoiceFilters($request->only(['from_date', 'to_date'])) ->itemAttributes() ->get(); $totalAmount = 0; foreach ($items as $item) { $totalAmount += $item->total_amount; } $dateFormat = CompanySetting::getSetting('carbon_date_format', $company->id); $from_date = Carbon::createFromFormat('Y-m-d', $request->from_date)->translatedFormat($dateFormat); $to_date = Carbon::createFromFormat('Y-m-d', $request->to_date)->translatedFormat($dateFormat); $currency = Currency::findOrFail(CompanySetting::getSetting('currency', $company->id)); view()->share([ 'items' => $items, 'totalAmount' => $totalAmount, 'company' => $company, 'logo' => $company->logo_path, 'from_date' => $from_date, 'to_date' => $to_date, 'currency' => $currency, ]); // Renders a same-named file from storage/app/templates/pdf/reports/ // when one exists, so a report can be overridden without a // template picker it has no concept of. $templatePath = PdfTemplateUtils::resolveView('reports', 'sales-items'); $pdf = Pdf::loadView($templatePath, [], PdfPageSetup::forReports()); if ($request->has('preview')) { return view($templatePath); } if ($request->has('download')) { return $pdf->download(); } return $pdf->stream(); } }