feat(auth): enable event-scoped admin access and backfill staff assignments
This commit is contained in:
@@ -25,8 +25,8 @@ class EnsureAdminAppTenant
|
||||
|| $user->rol_codigo !== RoleCode::AdminApp->value
|
||||
|| ! $user->tenant_codigo
|
||||
|| ! $this->accessService->hasValidScope($user)
|
||||
// Tenant operations remain unavailable until they implement event authorization.
|
||||
|| ($access !== 'context' && ! $user->isTenantAdministrator())
|
||||
// Only routes implementing event authorization may accept event administrators.
|
||||
|| (! in_array($access, ['context', 'event'], true) && ! $user->isTenantAdministrator())
|
||||
) {
|
||||
throw new AuthorizationException;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user