2019-04-22 19:01:39 -05:00
|
|
|
<?php
|
|
|
|
|
|
|
|
|
|
namespace App\Policies;
|
|
|
|
|
|
|
|
|
|
use App\Models\User;
|
|
|
|
|
use Illuminate\Auth\Access\HandlesAuthorization;
|
|
|
|
|
|
|
|
|
|
class UserPolicy
|
|
|
|
|
{
|
|
|
|
|
use HandlesAuthorization;
|
|
|
|
|
|
|
|
|
|
/**
|
|
|
|
|
* Determine whether the user can manage users.
|
|
|
|
|
*
|
|
|
|
|
* @param \App\Models\User $user
|
|
|
|
|
* @return bool
|
|
|
|
|
*/
|
|
|
|
|
public function manage(User $user)
|
|
|
|
|
{
|
|
|
|
|
return $user->isAdmin();
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/**
|
|
|
|
|
* Determine whether the user can view the user.
|
|
|
|
|
*
|
|
|
|
|
* @param \App\Models\User $user
|
|
|
|
|
* @param \App\Models\User $target
|
|
|
|
|
* @return bool
|
|
|
|
|
*/
|
|
|
|
|
public function view(User $user, User $target)
|
|
|
|
|
{
|
|
|
|
|
return $user->isAdmin() || $target->is($user);
|
|
|
|
|
}
|
|
|
|
|
|
2020-05-23 19:05:18 +02:00
|
|
|
/**
|
|
|
|
|
* Determine whether the user can view any user.
|
|
|
|
|
*
|
|
|
|
|
* @param \App\User $user
|
|
|
|
|
* @return mixed
|
|
|
|
|
*/
|
|
|
|
|
public function viewAny(User $user)
|
|
|
|
|
{
|
|
|
|
|
return $user->isAdmin();
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
2019-04-22 19:01:39 -05:00
|
|
|
/**
|
|
|
|
|
* Determine whether the user can create users.
|
|
|
|
|
*
|
|
|
|
|
* @param \App\Models\User $user
|
|
|
|
|
* @return bool
|
|
|
|
|
*/
|
|
|
|
|
public function create(User $user)
|
|
|
|
|
{
|
|
|
|
|
return $user->isAdmin();
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/**
|
|
|
|
|
* Determine whether the user can update the user.
|
|
|
|
|
*
|
|
|
|
|
* @param \App\Models\User $user
|
|
|
|
|
* @param \App\Models\User $target
|
|
|
|
|
* @return bool
|
|
|
|
|
*/
|
|
|
|
|
public function update(User $user, User $target)
|
|
|
|
|
{
|
|
|
|
|
return $user->isAdmin() || $target->is($user);
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/**
|
|
|
|
|
* Determine whether the user can delete the user.
|
|
|
|
|
*
|
|
|
|
|
* @param \App\Models\User $user
|
|
|
|
|
* @param \App\Models\User $target
|
|
|
|
|
* @return bool
|
|
|
|
|
*/
|
|
|
|
|
public function delete(User $user, User $target)
|
|
|
|
|
{
|
|
|
|
|
return $user->isAdmin();
|
|
|
|
|
}
|
|
|
|
|
}
|