Introduce a 'secure' filesystem disk to prevent public access to sensitive commitment form uploads. Files are now stored in a non-public directory and served via a protected controller method that validates user ownership. Additionally, implement shipment authorization policies to ensure users can only access PDF documents (AWB, invoice, labels) belonging to their own orders. Other changes: - Add production environment check for Zarinpal gateway configuration to prevent accidental use of sandbox credentials. - Move discount code and commitment form routes under authentication middleware for improved security. - Add `ShipmentPolicy` to handle resource authorization.
23 lines
536 B
PHP
23 lines
536 B
PHP
<?php
|
|
|
|
namespace App\Policies;
|
|
|
|
use App\Models\Shipment;
|
|
use App\Models\User;
|
|
|
|
/**
|
|
* سیاست دسترسی به سفارشها (و اسنادشان: AWB/Invoice/Label/PDF).
|
|
* - super_admin/admin/staff: هر سفارشی.
|
|
* - customer: فقط سفارشهای خودش.
|
|
*/
|
|
class ShipmentPolicy
|
|
{
|
|
public function view(User $user, Shipment $shipment): bool
|
|
{
|
|
if ($user->hasAnyRole(['super_admin', 'admin', 'staff'])) {
|
|
return true;
|
|
}
|
|
|
|
return $shipment->user_id === $user->id;
|
|
}
|
|
} |