fix: add authorization checks for environment and project views

This commit is contained in:
Andras Bacsai
2025-11-26 09:55:04 +01:00
parent 5f33ad74b5
commit ce134cb8b1
3 changed files with 15 additions and 19 deletions

View File

@@ -57,6 +57,7 @@ class Show extends Component
public function switch()
{
$this->authorize('view', $this->project);
$this->view = $this->view === 'normal' ? 'dev' : 'normal';
$this->getDevView();
}
@@ -97,25 +98,19 @@ class Show extends Component
{
$variables = parseEnvFormatToArray($this->variables);
DB::transaction(function () use ($variables) {
$changesMade = false;
$changesMade = DB::transaction(function () use ($variables) {
// Delete removed variables
$deletedCount = $this->deleteRemovedVariables($variables);
if ($deletedCount > 0) {
$changesMade = true;
}
// Update or create variables
$updatedCount = $this->updateOrCreateVariables($variables);
if ($updatedCount > 0) {
$changesMade = true;
}
if ($changesMade) {
$this->dispatch('success', 'Environment variables updated.');
}
return $deletedCount > 0 || $updatedCount > 0;
});
if ($changesMade) {
$this->dispatch('success', 'Environment variables updated.');
}
}
private function deleteRemovedVariables($variables)