| 
									
										
										
										
											2024-05-10 06:43:18 +02:00
										 |  |  | <?php | 
					
						
							| 
									
										
										
										
											2024-11-25 04:18:55 +01:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2024-05-10 06:43:18 +02:00
										 |  |  | /* | 
					
						
							|  |  |  |  * AccountPolicy.php | 
					
						
							|  |  |  |  * Copyright (c) 2024 james@firefly-iii.org. | 
					
						
							|  |  |  |  * | 
					
						
							|  |  |  |  * This file is part of Firefly III (https://github.com/firefly-iii). | 
					
						
							|  |  |  |  * | 
					
						
							|  |  |  |  * This program is free software: you can redistribute it and/or modify | 
					
						
							|  |  |  |  * it under the terms of the GNU Affero General Public License as | 
					
						
							|  |  |  |  * published by the Free Software Foundation, either version 3 of the | 
					
						
							|  |  |  |  * License, or (at your option) any later version. | 
					
						
							|  |  |  |  * | 
					
						
							|  |  |  |  * This program is distributed in the hope that it will be useful, | 
					
						
							|  |  |  |  * but WITHOUT ANY WARRANTY; without even the implied warranty of | 
					
						
							|  |  |  |  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the | 
					
						
							|  |  |  |  * GNU Affero General Public License for more details. | 
					
						
							|  |  |  |  * | 
					
						
							|  |  |  |  * You should have received a copy of the GNU Affero General Public License | 
					
						
							|  |  |  |  * along with this program.  If not, see https://www.gnu.org/licenses/. | 
					
						
							|  |  |  |  */ | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | declare(strict_types=1); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | namespace FireflyIII\Policies; | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | use FireflyIII\Models\Account; | 
					
						
							|  |  |  | use FireflyIII\User; | 
					
						
							| 
									
										
										
										
											2024-08-03 06:00:22 +02:00
										 |  |  | use Illuminate\Support\Facades\Log; | 
					
						
							| 
									
										
										
										
											2024-05-10 06:43:18 +02:00
										 |  |  | 
 | 
					
						
							|  |  |  | class AccountPolicy | 
					
						
							|  |  |  | { | 
					
						
							| 
									
										
										
										
											2024-12-22 08:43:12 +01:00
										 |  |  |     public function create(): bool | 
					
						
							| 
									
										
										
										
											2024-05-10 06:43:18 +02:00
										 |  |  |     { | 
					
						
							| 
									
										
										
										
											2024-12-22 08:43:12 +01:00
										 |  |  |         return auth()->check(); | 
					
						
							| 
									
										
										
										
											2024-05-10 06:43:18 +02:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2024-12-22 08:43:12 +01:00
										 |  |  |     public function viewAccountBalances(User $user, Account $account): bool | 
					
						
							| 
									
										
										
										
											2024-08-05 20:37:29 +02:00
										 |  |  |     { | 
					
						
							| 
									
										
										
										
											2024-12-22 08:43:12 +01:00
										 |  |  |         return $this->view($user, $account); | 
					
						
							| 
									
										
										
										
											2024-08-05 19:45:04 +02:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2025-05-04 17:41:26 +02:00
										 |  |  |     /** | 
					
						
							|  |  |  |      * TODO needs better authentication, also for group. | 
					
						
							|  |  |  |      */ | 
					
						
							|  |  |  |     public function view(User $user, Account $account): bool | 
					
						
							|  |  |  |     { | 
					
						
							|  |  |  |         return auth()->check() && $user->id === $account->user_id; | 
					
						
							|  |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2024-05-10 06:43:18 +02:00
										 |  |  |     /** | 
					
						
							|  |  |  |      * Everybody can do this, but selection should limit to user. | 
					
						
							|  |  |  |      */ | 
					
						
							|  |  |  |     public function viewAny(): bool | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2024-08-03 06:00:22 +02:00
										 |  |  |         Log::debug(__METHOD__); | 
					
						
							| 
									
										
										
										
											2024-08-05 05:06:53 +02:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2024-05-10 06:43:18 +02:00
										 |  |  |         return auth()->check(); | 
					
						
							|  |  |  |     } | 
					
						
							| 
									
										
										
										
											2024-05-10 12:51:02 +02:00
										 |  |  | 
 | 
					
						
							|  |  |  |     /** | 
					
						
							|  |  |  |      * Everybody can do this, but selection should limit to user. | 
					
						
							|  |  |  |      */ | 
					
						
							|  |  |  |     public function viewUser(User $user, Account $account): bool | 
					
						
							|  |  |  |     { | 
					
						
							|  |  |  |         return $this->view($user, $account); | 
					
						
							|  |  |  |     } | 
					
						
							| 
									
										
										
										
											2024-05-10 06:43:18 +02:00
										 |  |  | } |