src/Security/Voter/Profile/Commission/CommissionVoter.php line 12

Open in your IDE?
  1. <?php
  2. namespace App\Security\Voter\Profile\Commission;
  3. use App\Model\User\Entity\User\Role\Permission;
  4. use App\ReadModel\Profile\DetailView;
  5. use App\Security\UserIdentity;
  6. use Symfony\Component\Security\Core\Authentication\Token\TokenInterface;
  7. use Symfony\Component\Security\Core\Authorization\Voter\Voter;
  8. use Symfony\Component\Security\Core\Security;
  9. class CommissionVoter extends Voter
  10. {
  11.     public const PROFILE_COMMISSION_LIST 'profile_commission_list';
  12.     public const PROFILE_COMMISSION_CREATE 'profile_commission_create';
  13.     public const PROFILE_COMMISSION_SHOW 'profile_commission_show';
  14.     public const PROFILE_COMMISSION_DELETE 'profile_commission_delete';
  15.     private $security;
  16.     public function __construct(Security $security)
  17.     {
  18.         $this->security $security;
  19.     }
  20.     protected function supports(string $attribute$subject)
  21.     {
  22.         return in_array($attribute, [
  23.             self::PROFILE_COMMISSION_LIST,
  24.             self::PROFILE_COMMISSION_CREATE,
  25.             self::PROFILE_COMMISSION_SHOW,
  26.             self::PROFILE_COMMISSION_DELETE
  27.         ], true);
  28.     }
  29.     protected function voteOnAttribute(string $attribute$subjectTokenInterface $token): bool
  30.     {
  31.         if ($this->security->isGranted('ROLE_MODERATOR')) {
  32.             return true;
  33.         }
  34.         $user $token->getUser();
  35.         if (!$user instanceof UserIdentity) {
  36.             return false;
  37.         }
  38.         if (!$subject instanceof DetailView) {
  39.             return false;
  40.         }
  41.         if ($user->getId() !== $subject->user_id) {
  42.             return false;
  43.         }
  44.         switch ($attribute) {
  45.             case self::PROFILE_COMMISSION_LIST:
  46.                 return $user->isPermission(Permission::PROFILE_COMMISSION_LIST);
  47.                 break;
  48.             case self::PROFILE_COMMISSION_CREATE:
  49.                 return $user->isPermission(Permission::PROFILE_COMMISSION_CREATE);
  50.                 break;
  51.             case self::PROFILE_COMMISSION_SHOW:
  52.                 return $user->isPermission(Permission::PROFILE_COMMISSION_SHOW);
  53.                 break;
  54.             case self::PROFILE_COMMISSION_DELETE:
  55.                 return $user->isPermission(Permission::PROFILE_COMMISSION_DELETE);
  56.                 break;
  57.         }
  58.         return false;
  59.     }
  60. }