-
Notifications
You must be signed in to change notification settings - Fork 7
Expand file tree
/
Copy pathUserPasswordVoter.php
More file actions
69 lines (56 loc) · 2 KB
/
UserPasswordVoter.php
File metadata and controls
69 lines (56 loc) · 2 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
<?php
declare(strict_types=1);
/**
* This source file is available under the terms of the
* Pimcore Open Core License (POCL)
* Full copyright and license information is available in
* LICENSE.md which is distributed with this source code.
*
* @copyright Copyright (c) Pimcore GmbH (https://www.pimcore.com)
* @license Pimcore Open Core License (POCL)
*/
namespace Pimcore\Bundle\StudioBackendBundle\Security\Voter;
use Pimcore\Bundle\StudioBackendBundle\Exception\Api\AccessDeniedException;
use Pimcore\Bundle\StudioBackendBundle\Security\Service\SecurityServiceInterface;
use Pimcore\Bundle\StudioBackendBundle\Util\Constant\UserPermissions;
use Pimcore\Bundle\StudioBackendBundle\Util\Trait\RequestTrait;
use Symfony\Component\HttpFoundation\RequestStack;
use Symfony\Component\Security\Core\Authentication\Token\TokenInterface;
use Symfony\Component\Security\Core\Authorization\Voter\Voter;
/**
* @internal
*/
final class UserPasswordVoter extends Voter
{
use RequestTrait;
public function __construct(
private readonly RequestStack $requestStack,
private readonly SecurityServiceInterface $securityService
) {
}
/**
* {@inheritdoc}
*/
protected function supports(string $attribute, mixed $subject): bool
{
return $attribute === UserPermissions::USER_PASSWORD->value;
}
/**
* @throws AccessDeniedException
*/
protected function voteOnAttribute(string $attribute, mixed $subject, TokenInterface $token): bool
{
$userId = $this->getUserIdFromRequest();
$currentUser = $this->securityService->getCurrentUser();
if ($userId === $currentUser->getId()) {
// Allow user to update their own password
return true;
}
return $currentUser->isAllowed(UserPermissions::USER_MANAGEMENT->value);
}
private function getUserIdFromRequest(): int
{
$request = $this->getCurrentRequest($this->requestStack);
return $request->attributes->getInt('id');
}
}