Files
InvoiceShelf/app/Domains/Accounts/Policies/UserPolicy.php
T
Darko Gjorgjijoski 5ef7804e60 refactor: adopt modular domain architecture (#747)
* refactor: stabilize model identities for domain migration

* refactor: extract module platform context

* refactor: assign models to domain contexts

* refactor: extract ai platform context

* refactor: extract storage platform context

* refactor: extract mail platform context

* refactor: extract pdf platform context

* refactor: extract operations platform context

* refactor: move installation into operations platform

* refactor: extract money domain context

* refactor: extract taxation domain context

* refactor: extract catalog domain context

* refactor: extract metadata domain context

* refactor: extract reporting domain context

* refactor: extract purchases domain context

* refactor: extract receivables domain context

* refactor: extract accounts domain context

* refactor: complete reporting statement boundary

* refactor: extract contacts domain context

* refactor: extract sales domain context

* refactor: remove legacy application layers

* fix: migrate legacy bouncer role identities
2026-08-05 17:40:03 +02:00

140 lines
2.9 KiB
PHP

<?php
namespace App\Domains\Accounts\Policies;
use App\Domains\Accounts\Models\User;
use Illuminate\Auth\Access\HandlesAuthorization;
class UserPolicy
{
use HandlesAuthorization;
/**
* Determine whether the user can view any models.
*
* @return mixed
*/
public function viewAny(User $user): bool
{
if ($user->isOwner()) {
return true;
}
return false;
}
/**
* Determine whether the user can view the model.
*
* @return mixed
*/
public function view(User $user, User $model): bool
{
return $user->isOwner() && $this->sharesActiveCompany($model);
}
/**
* Determine whether the user can create models.
*
* @return mixed
*/
public function create(User $user): bool
{
if ($user->isOwner()) {
return true;
}
return false;
}
/**
* Determine whether the user can update the model.
*
* @return mixed
*/
public function update(User $user, User $model): bool
{
return $user->isOwner() && $this->sharesActiveCompany($model);
}
/**
* Determine whether the user can delete the model.
*
* @return mixed
*/
public function delete(User $user, User $model): bool
{
return $user->isOwner() && $this->sharesActiveCompany($model);
}
/**
* Determine whether the user can restore the model.
*
* @return mixed
*/
public function restore(User $user, User $model): bool
{
if ($user->isOwner()) {
return true;
}
return false;
}
/**
* Determine whether the user can permanently delete the model.
*
* @return mixed
*/
public function forceDelete(User $user, User $model): bool
{
if ($user->isOwner()) {
return true;
}
return false;
}
/**
* Determine whether the user can invite the model.
*
* @return mixed
*/
public function invite(User $user, User $model)
{
if ($user->isOwner()) {
return true;
}
return false;
}
/**
* Determine whether the user can delete models.
*
* @return mixed
*/
public function deleteMultiple(User $user)
{
if ($user->isOwner()) {
return true;
}
return false;
}
/**
* A company owner may only act on members of the company set in the
* `company` request header. Without this, view/update/delete resolve the
* target user by global id, which would let an owner of one company read
* or overwrite users belonging to another company (cross-tenant IDOR).
*/
private function sharesActiveCompany(User $model): bool
{
$companyId = request()->header('company');
return $companyId
&& $model->companies()->wherePivot('company_id', $companyId)->exists();
}
}