src/Security/Voter/SubjectVoter.php line 10

Open in your IDE?
  1. <?php
  2. namespace App\Security\Voter;
  3. use App\Entity\Subject;
  4. use Symfony\Component\Security\Core\Authentication\Token\TokenInterface;
  5. use Symfony\Component\Security\Core\Authorization\Voter\Voter;
  6. use Symfony\Component\Security\Core\User\UserInterface;
  7. class SubjectVoter extends Voter
  8. {
  9.     protected function supports($attribute$targetEntity)
  10.     {
  11.         return in_array($attribute, ['USER_CAN_EDIT_SUBJECT''ALT_MANAGER_CAN_SEE_SUBJECT'])
  12.             && $targetEntity instanceof \App\Entity\Subject;
  13.     }
  14.     protected function voteOnAttribute($attribute$targetEntityTokenInterface $token)
  15.     {
  16.         $user $token->getUser();
  17.         if (!$user instanceof UserInterface) {
  18.             return false;
  19.         }
  20.         if(in_array('ROLE_ADMIN'$user->getRoles())) {
  21.             return true;
  22.         }
  23.         if(in_array('ROLE_SUPER_ADMIN'$user->getRoles())) {
  24.             return true;
  25.         }
  26.         switch ($attribute) {
  27.             case 'USER_CAN_EDIT_SUBJECT':
  28.                 if ($targetEntity->getAuthor()->getId() == $user->getId()) {
  29.                     return true;
  30.                 }
  31.                 break;
  32.             case 'ALT_MANAGER_CAN_SEE_SUBJECT':
  33.                 if(!in_array('ROLE_ALTERNATIVE_MANAGER'$user->getRoles())) {
  34.                     return false;
  35.                 }
  36.                 if ($targetEntity->getIsViewableForAlternativeManager() == 1  ) {
  37.                     return true;
  38.                 }
  39.                 break;
  40.         }
  41.         return false;
  42.     }
  43. }