ifnex/04_Laravel/app/Policies/ShipmentPolicy.php
Kazem Alghasi 8cf407553b feat(security): implement secure file storage and shipment access control
Introduce a 'secure' filesystem disk to prevent public access to sensitive
commitment form uploads. Files are now stored in a non-public directory
and served via a protected controller method that validates user ownership.

Additionally, implement shipment authorization policies to ensure users
can only access PDF documents (AWB, invoice, labels) belonging to their
own orders.

Other changes:
- Add production environment check for Zarinpal gateway configuration
  to prevent accidental use of sandbox credentials.
- Move discount code and commitment form routes under authentication
  middleware for improved security.
- Add `ShipmentPolicy` to handle resource authorization.
2026-10-01 03:34:28 +03:30

23 lines
536 B
PHP

<?php
namespace App\Policies;
use App\Models\Shipment;
use App\Models\User;
/**
* سیاست دسترسی به سفارش‌ها (و اسنادشان: AWB/Invoice/Label/PDF).
* - super_admin/admin/staff: هر سفارشی.
* - customer: فقط سفارش‌های خودش.
*/
class ShipmentPolicy
{
public function view(User $user, Shipment $shipment): bool
{
if ($user->hasAnyRole(['super_admin', 'admin', 'staff'])) {
return true;
}
return $shipment->user_id === $user->id;
}
}