Files
InvoiceShelf/app/Http/Controllers/V1/Admin
Darko Gjorgjijoski 3d871604ae Add company ownership check to clone endpoints (#606)
Verify the source record belongs to the current company before cloning.
Previously, users could clone invoices/estimates from other companies,
leaking sensitive data (amounts, customer details, items, taxes, notes).

The view policy already includes hasCompany() check, so authorizing
view on the source record gates both ability and company ownership.

Ref #574
2026-04-03 14:32:12 +02:00
..
2026-03-21 18:59:53 +01:00
2026-03-21 18:59:53 +01:00
2026-03-21 18:59:53 +01:00
2026-03-21 18:59:53 +01:00
2026-03-21 18:59:53 +01:00
2026-03-21 18:59:53 +01:00
2024-06-05 11:33:52 +02:00
2026-03-21 18:59:53 +01:00
2026-03-21 18:59:53 +01:00
2026-03-21 18:59:53 +01:00
2026-03-21 18:59:53 +01:00
2026-03-21 18:59:53 +01:00