feat(scanner): scope login tickets scanning and history by event
This commit is contained in:
@@ -16,6 +16,9 @@ class ScannerMeResource extends JsonResource
|
||||
return [
|
||||
'user' => UserResource::make($this->resource),
|
||||
'tenant' => TenantResource::make($this->tenant),
|
||||
'event' => $this->whenLoaded('event', fn () => $this->event === null ? null : [
|
||||
'id' => $this->event->id, 'title' => $this->event->title,
|
||||
]),
|
||||
];
|
||||
}
|
||||
}
|
||||
|
||||
@@ -26,7 +26,7 @@ class UserResource extends JsonResource
|
||||
'rol_codigo' => $this->rol_codigo,
|
||||
'tenant_codigo' => $this->tenant_codigo,
|
||||
'admin_scope' => $this->when($this->rol_codigo === RoleCode::AdminApp->value, $this->admin_scope),
|
||||
'event_id' => $this->when($this->rol_codigo === RoleCode::AdminApp->value, $this->event_id),
|
||||
'event_id' => $this->when(in_array($this->rol_codigo, [RoleCode::AdminApp->value, RoleCode::Scanner->value], true), $this->event_id),
|
||||
'categories' => $this->whenLoaded('scanCategories', fn () => $this->scanCategories
|
||||
->map(fn ($category) => [
|
||||
'id' => $category->id,
|
||||
|
||||
@@ -10,6 +10,7 @@ use App\Domains\Core\Authorization\Enums\PermissionCode;
|
||||
use App\Domains\Core\Authorization\Enums\RoleCode;
|
||||
use App\Shared\Notification\Events\PasswordResetRequested;
|
||||
use Carbon\CarbonImmutable;
|
||||
use Illuminate\Auth\Access\AuthorizationException;
|
||||
use Illuminate\Support\Facades\DB;
|
||||
use Illuminate\Support\Facades\Hash;
|
||||
use Illuminate\Support\Facades\Log;
|
||||
@@ -206,6 +207,17 @@ class PasswordLoginService
|
||||
return ['outcome' => LoginAttempt::OUTCOME_INVALID_CREDENTIALS, 'user' => $user, 'locked_until' => null];
|
||||
}
|
||||
|
||||
if ($requiredRole === RoleCode::Scanner) {
|
||||
try {
|
||||
app(EventScopeService::class)->eventId($user);
|
||||
} catch (AuthorizationException) {
|
||||
$this->recordAttempt($user, $normalizedEmail, $attemptTenantCode,
|
||||
LoginAttempt::OUTCOME_INVALID_CREDENTIALS, $ipAddress, $userAgent);
|
||||
|
||||
return ['outcome' => LoginAttempt::OUTCOME_INVALID_CREDENTIALS, 'user' => $user, 'locked_until' => null];
|
||||
}
|
||||
}
|
||||
|
||||
$user->forceFill([
|
||||
'failed_login_attempts' => 0,
|
||||
'last_failed_login_at' => null,
|
||||
|
||||
@@ -18,6 +18,7 @@ class ScannerContextService
|
||||
->firstOrFail();
|
||||
|
||||
$user->setRelation('tenant', $tenant);
|
||||
$user->load('event');
|
||||
|
||||
if ($tenant->requiresScannerCategoryValidation()) {
|
||||
$categories = $user->scanCategories()
|
||||
|
||||
Reference in New Issue
Block a user