mirror of
https://github.com/tiennm99/coolify.git
synced 2026-08-20 06:23:23 +00:00
fix(auth): enforce authorization checks across API and Livewire components
- Add authorization checks to API controller endpoints (view, create, update, delete) - Wrap Livewire component methods with try-catch for consistent error handling - Add AuthorizesRequests trait to components requiring authorization checks - Ensure all sensitive operations verify user permissions before execution - Implement unified error handling with handleError() helper function
This commit is contained in:
@@ -12,13 +12,11 @@ class NotificationPolicy
|
||||
*/
|
||||
public function view(User $user, Model $notificationSettings): bool
|
||||
{
|
||||
// Check if the notification settings belong to the user's current team
|
||||
if (! $notificationSettings->team) {
|
||||
return false;
|
||||
}
|
||||
|
||||
// return $user->teams()->where('teams.id', $notificationSettings->team->id)->exists();
|
||||
return true;
|
||||
return $user->teams->contains('id', $notificationSettings->team->id);
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -26,14 +24,13 @@ class NotificationPolicy
|
||||
*/
|
||||
public function update(User $user, Model $notificationSettings): bool
|
||||
{
|
||||
// Check if the notification settings belong to the user's current team
|
||||
if (! $notificationSettings->team) {
|
||||
return false;
|
||||
}
|
||||
|
||||
// Only owners and admins can update notification settings
|
||||
// return $user->isAdmin() || $user->isOwner();
|
||||
return true;
|
||||
$teamId = $notificationSettings->team->id;
|
||||
|
||||
return $user->isAdminOfTeam($teamId);
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -41,8 +38,7 @@ class NotificationPolicy
|
||||
*/
|
||||
public function manage(User $user, Model $notificationSettings): bool
|
||||
{
|
||||
// return $this->update($user, $notificationSettings);
|
||||
return true;
|
||||
return $this->update($user, $notificationSettings);
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -50,7 +46,6 @@ class NotificationPolicy
|
||||
*/
|
||||
public function sendTest(User $user, Model $notificationSettings): bool
|
||||
{
|
||||
// return $this->update($user, $notificationSettings);
|
||||
return true;
|
||||
return $this->update($user, $notificationSettings);
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user