|
5 | 5 | use App\Models\Application; |
6 | 6 | use App\Models\Environment; |
7 | 7 | use App\Models\Project; |
| 8 | +use App\Models\Server; |
8 | 9 | use App\Models\Service; |
9 | 10 | use App\Models\ServiceApplication; |
10 | 11 | use App\Models\ServiceDatabase; |
|
23 | 24 |
|
24 | 25 | class CanUpdateResource |
25 | 26 | { |
| 27 | + /** |
| 28 | + * @var array<string, list<class-string>> |
| 29 | + */ |
| 30 | + private const ROUTE_RESOURCE_MODELS = [ |
| 31 | + 'application_uuid' => [Application::class], |
| 32 | + 'database_uuid' => [ |
| 33 | + StandalonePostgresql::class, |
| 34 | + StandaloneMysql::class, |
| 35 | + StandaloneMariadb::class, |
| 36 | + StandaloneRedis::class, |
| 37 | + StandaloneKeydb::class, |
| 38 | + StandaloneDragonfly::class, |
| 39 | + StandaloneClickhouse::class, |
| 40 | + StandaloneMongodb::class, |
| 41 | + ], |
| 42 | + 'stack_service_uuid' => [ServiceApplication::class, ServiceDatabase::class], |
| 43 | + 'service_uuid' => [Service::class], |
| 44 | + 'server_uuid' => [Server::class], |
| 45 | + 'environment_uuid' => [Environment::class], |
| 46 | + 'project_uuid' => [Project::class], |
| 47 | + ]; |
| 48 | + |
26 | 49 | public function handle(Request $request, Closure $next): Response |
27 | 50 | { |
| 51 | + $resource = $this->resourceFromRoute($request); |
| 52 | + |
| 53 | + if (! $resource) { |
| 54 | + abort(404, 'Resource not found.'); |
| 55 | + } |
| 56 | + |
| 57 | + if (! Gate::allows('update', $resource)) { |
| 58 | + abort(403, 'You do not have permission to update this resource.'); |
| 59 | + } |
| 60 | + |
28 | 61 | return $next($request); |
| 62 | + } |
29 | 63 |
|
30 | | - // Get resource from route parameters |
31 | | - // $resource = null; |
32 | | - // if ($request->route('application_uuid')) { |
33 | | - // $resource = Application::where('uuid', $request->route('application_uuid'))->first(); |
34 | | - // } elseif ($request->route('service_uuid')) { |
35 | | - // $resource = Service::where('uuid', $request->route('service_uuid'))->first(); |
36 | | - // } elseif ($request->route('stack_service_uuid')) { |
37 | | - // // Handle ServiceApplication or ServiceDatabase |
38 | | - // $stack_service_uuid = $request->route('stack_service_uuid'); |
39 | | - // $resource = ServiceApplication::where('uuid', $stack_service_uuid)->first() ?? |
40 | | - // ServiceDatabase::where('uuid', $stack_service_uuid)->first(); |
41 | | - // } elseif ($request->route('database_uuid')) { |
42 | | - // // Try different database types |
43 | | - // $database_uuid = $request->route('database_uuid'); |
44 | | - // $resource = StandalonePostgresql::where('uuid', $database_uuid)->first() ?? |
45 | | - // StandaloneMysql::where('uuid', $database_uuid)->first() ?? |
46 | | - // StandaloneMariadb::where('uuid', $database_uuid)->first() ?? |
47 | | - // StandaloneRedis::where('uuid', $database_uuid)->first() ?? |
48 | | - // StandaloneKeydb::where('uuid', $database_uuid)->first() ?? |
49 | | - // StandaloneDragonfly::where('uuid', $database_uuid)->first() ?? |
50 | | - // StandaloneClickhouse::where('uuid', $database_uuid)->first() ?? |
51 | | - // StandaloneMongodb::where('uuid', $database_uuid)->first(); |
52 | | - // } elseif ($request->route('server_uuid')) { |
53 | | - // // For server routes, check if user can manage servers |
54 | | - // if (! auth()->user()->isAdmin()) { |
55 | | - // abort(403, 'You do not have permission to access this resource.'); |
56 | | - // } |
| 64 | + private function resourceFromRoute(Request $request): ?object |
| 65 | + { |
| 66 | + foreach (self::ROUTE_RESOURCE_MODELS as $routeParameter => $models) { |
| 67 | + $uuid = $request->route($routeParameter); |
57 | 68 |
|
58 | | - // return $next($request); |
59 | | - // } elseif ($request->route('environment_uuid')) { |
60 | | - // $resource = Environment::where('uuid', $request->route('environment_uuid'))->first(); |
61 | | - // } elseif ($request->route('project_uuid')) { |
62 | | - // $resource = Project::ownedByCurrentTeam()->where('uuid', $request->route('project_uuid'))->first(); |
63 | | - // } |
| 69 | + if (! $uuid) { |
| 70 | + continue; |
| 71 | + } |
64 | 72 |
|
65 | | - // if (! $resource) { |
66 | | - // abort(404, 'Resource not found.'); |
67 | | - // } |
| 73 | + foreach ($models as $model) { |
| 74 | + $resource = $model::where('uuid', $uuid)->first(); |
68 | 75 |
|
69 | | - // if (! Gate::allows('update', $resource)) { |
70 | | - // abort(403, 'You do not have permission to update this resource.'); |
71 | | - // } |
| 76 | + if ($resource) { |
| 77 | + return $resource; |
| 78 | + } |
| 79 | + } |
| 80 | + } |
72 | 81 |
|
73 | | - // return $next($request); |
| 82 | + return null; |
74 | 83 | } |
75 | 84 | } |
0 commit comments