feat(auth): enable event-scoped admin access and backfill staff assignments
This commit is contained in:
@@ -23,7 +23,9 @@ class AdminAppContextService
|
||||
$user->load('event');
|
||||
|
||||
if (! $user->isTenantAdministrator()) {
|
||||
$tenant->setRelation('menues', $tenant->menues->where('code', 'main.adminapp')->values());
|
||||
$allowed = ['main.adminapp', 'adminapp.inicio', 'adminapp.event',
|
||||
'adminapp.catalog', 'adminapp.ventas', 'adminapp.staff'];
|
||||
$tenant->setRelation('menues', $tenant->menues->whereIn('code', $allowed)->values());
|
||||
}
|
||||
|
||||
return $user;
|
||||
|
||||
24
app/Domains/Core/Auth/Services/EventScopeService.php
Normal file
24
app/Domains/Core/Auth/Services/EventScopeService.php
Normal file
@@ -0,0 +1,24 @@
|
||||
<?php
|
||||
|
||||
namespace App\Domains\Core\Auth\Services;
|
||||
|
||||
use App\Domains\Core\Auth\Enums\AdminScope;
|
||||
use App\Domains\Core\Auth\Models\User;
|
||||
use Illuminate\Auth\Access\AuthorizationException;
|
||||
|
||||
class EventScopeService
|
||||
{
|
||||
public function eventId(User $user): ?int
|
||||
{
|
||||
if ($user->admin_scope === AdminScope::Event->value || $user->event_id !== null) {
|
||||
if ($user->event_id === null
|
||||
|| ! $user->event()->where('tenant_code', $user->tenant_codigo)->exists()) {
|
||||
throw new AuthorizationException;
|
||||
}
|
||||
|
||||
return $user->event_id;
|
||||
}
|
||||
|
||||
return null;
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user