Files
InvoiceShelf/app/Domains/Sales/Policies/CreditNotePolicy.php
T
Darko Gjorgjijoski 5ef7804e60 refactor: adopt modular domain architecture (#747)
* refactor: stabilize model identities for domain migration

* refactor: extract module platform context

* refactor: assign models to domain contexts

* refactor: extract ai platform context

* refactor: extract storage platform context

* refactor: extract mail platform context

* refactor: extract pdf platform context

* refactor: extract operations platform context

* refactor: move installation into operations platform

* refactor: extract money domain context

* refactor: extract taxation domain context

* refactor: extract catalog domain context

* refactor: extract metadata domain context

* refactor: extract reporting domain context

* refactor: extract purchases domain context

* refactor: extract receivables domain context

* refactor: extract accounts domain context

* refactor: complete reporting statement boundary

* refactor: extract contacts domain context

* refactor: extract sales domain context

* refactor: remove legacy application layers

* fix: migrate legacy bouncer role identities
2026-08-05 17:40:03 +02:00

32 lines
1007 B
PHP

<?php
namespace App\Domains\Sales\Policies;
use App\Domains\Accounts\Models\User;
use App\Domains\Sales\Models\Invoice;
use Illuminate\Auth\Access\HandlesAuthorization;
use Silber\Bouncer\BouncerFacade;
/**
* Authorization for credit notes (Stornorechnungen).
*
* A credit note is persisted as an invoice row (type = CREDIT_NOTE), so once it
* exists the ordinary invoice abilities (view, send, delete) govern it through
* InvoicePolicy. What needs its own rule is minting one: the ability maps to
* creating an invoice but is gated on the acting user belonging to the *source*
* invoice's company (tenant isolation, issue #9 from PR #536).
*/
class CreditNotePolicy
{
use HandlesAuthorization;
/**
* Whether the user may create a credit note for the given source invoice.
*/
public function create(User $user, Invoice $invoice): bool
{
return BouncerFacade::can('create-invoice', Invoice::class)
&& $user->hasCompany($invoice->company_id);
}
}