fix(permissions): make the addresses resource real instead of decorative
A full role-by-role sweep (9 roles x 18 endpoints against the running app) showed
the addresses toggles in the owner's permission form controlled nothing. Grep
confirms it: no gate anywhere referenced 'addresses'. The panel's address list was
gated on appointment_settings.view instead — the same borrowed-permission pattern
already fixed for resources and treatment.
GET /api/v1/addresses now gates on addresses.view.
The resource drops to view-only. Creating, updating and deleting an address in
ClinicController is explicitly owner-or-admin
($clinic->getUser()->getId() !== $user->getId()), so those three actions could
never be delegated to a secretary or an invited doctor no matter what the form
said. Both role defaults narrow to ['view' => true] to match, and stored JSON
keeps its old keys harmlessly since merge only reads registry keys.
This widens secretary access: addresses.view defaults to true while
appointment_settings.view defaults to false, so secretaries who could not list
addresses now can. That is deliberate and costs no confidentiality — the same
addresses are already served anonymously from
GET /api/v1/clinic/{uuid}/addresses, which is whitelisted in security.yaml.
Verified live in three states: default 200, addresses.view off 403, and
addresses off with appointment_settings on still 403, proving the borrow is gone.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -82,8 +82,15 @@
|
||||
`clinic_info` · `services` · `inventory` · `staff` · `tags` · `discounts` · `sms` ·
|
||||
`appointment_settings` · `resources` · `clinic_doctors` · `subscription`
|
||||
|
||||
اکشنها یکسان نیستند: `subscription` فقط `view/create` دارد، و
|
||||
`clinic_info` / `appointment_settings` / `treatment` فقط `view/update`.
|
||||
اکشنها یکسان نیستند: `subscription` فقط `view/create` دارد،
|
||||
`clinic_info` / `appointment_settings` / `treatment` فقط `view/update`، و
|
||||
`addresses` **فقط `view`**.
|
||||
|
||||
منبعِ `addresses` عمداً `create/update/delete` ندارد: ساخت و ویرایش و حذفِ آدرس در
|
||||
`ClinicController` صریحاً owner-or-admin است
|
||||
(`$clinic->getUser()->getId() !== $user->getId()`) و قابل واگذاری به منشی یا پزشکِ
|
||||
عضو نیست. تا پیش از این هر سهٔ آن توگلها در فرمِ مالک بودند و هیچ چیزی را کنترل
|
||||
نمیکردند.
|
||||
|
||||
### Errors
|
||||
|
||||
|
||||
Reference in New Issue
Block a user