Files
firefly-iii/app/Rules/IsAllowedGroupAction.php

79 lines
2.5 KiB
PHP
Raw Normal View History

2024-07-28 07:02:04 +02:00
<?php
2024-07-28 07:02:04 +02:00
/*
* IsAllowedGroupAction.php
* Copyright (c) 2024 james@firefly-iii.org.
*
* This file is part of Firefly III (https://github.com/firefly-iii).
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as
* published by the Free Software Foundation, either version 3 of the
* License, or (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU Affero General Public License for more details.
*
* You should have received a copy of the GNU Affero General Public License
* along with this program. If not, see https://www.gnu.org/licenses/.
*/
declare(strict_types=1);
namespace FireflyIII\Rules;
2025-10-05 12:59:43 +02:00
use Closure;
2024-07-28 07:02:04 +02:00
use FireflyIII\Enums\UserRoleEnum;
use FireflyIII\Exceptions\FireflyException;
2024-07-28 07:02:04 +02:00
use FireflyIII\Models\Account;
use Illuminate\Auth\Access\AuthorizationException;
2024-12-22 08:43:12 +01:00
use Illuminate\Contracts\Validation\ValidationRule;
2024-07-28 07:02:04 +02:00
use Illuminate\Support\Facades\Log;
use Override;
2024-07-28 07:02:04 +02:00
class IsAllowedGroupAction implements ValidationRule
{
2025-11-09 09:08:03 +01:00
// you need these roles to do anything with any endpoint.
private array $acceptedRoles = [UserRoleEnum::OWNER, UserRoleEnum::FULL];
2024-07-28 07:02:04 +02:00
public function __construct(private readonly string $className, private readonly string $methodName) {}
2024-07-28 07:02:04 +02:00
/**
* @throws AuthorizationException
*/
#[Override]
public function validate(string $attribute, mixed $value, Closure $fail): void
2024-07-28 07:02:04 +02:00
{
if ('GET' === $this->methodName) {
2024-07-28 07:02:04 +02:00
// need at least "read only rights".
$this->acceptedRoles[] = UserRoleEnum::READ_ONLY;
}
if ('GET' !== $this->methodName) {
2024-07-28 07:02:04 +02:00
// either post, put or delete or something else.. you need more access rights.
switch ($this->className) {
default:
throw new AuthorizationException(sprintf('Cannot handle class "%s"', $this->className));
2024-07-28 07:02:04 +02:00
case Account::class:
$this->acceptedRoles[] = UserRoleEnum::MANAGE_TRANSACTIONS;
2024-07-28 07:02:04 +02:00
break;
}
}
2025-11-09 09:08:03 +01:00
$this->validateUserGroup();
2024-07-28 07:02:04 +02:00
}
2025-11-09 09:08:03 +01:00
private function validateUserGroup(): void
{
try {
throw new FireflyException('Here we are');
} catch (FireflyException $e) {
Log::error($e->getTraceAsString());
}
exit('here we are');
2024-07-28 07:02:04 +02:00
}
}