feat(resource): every resource is supervised by a doctor
Supervision now lives on the resource itself instead of being asked for again at booking time, so one relation answers it everywhere. The column is deliberately separate from the existing doctor_id bridge. That bridge means "this resource IS this doctor" and isPerson() uses it to pin capacity at 1; a supervised three-seat device must not become a person resource. The FK is SET NULL rather than CASCADE because deleting a doctor should not take the clinic's laser with it. Required on create and non-clearable on update, enforced in the API where it can give a Persian message. Ownership is checked through Clinic::hasDoctor so a secretary cannot put their device under a doctor of another clinic; that returns 404, not 403, keeping foreign data invisible. The 13 existing resources are backfilled deterministically: a practice resource gets its own doctor, a clinic resource gets that clinic's first doctor. Both are editable from the resource form. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -4,13 +4,16 @@ namespace App\Resource\Service;
|
||||
|
||||
use App\Auth\Entity\User;
|
||||
use App\Doctor\Service\AddressResolver;
|
||||
use App\Doctor\Entity\Doctor;
|
||||
use App\Doctor\Entity\DoctorAddress;
|
||||
use App\Doctor\Repository\DoctorRepository;
|
||||
use App\Resource\Entity\ClinicResource;
|
||||
use App\Resource\Entity\ResourcePool;
|
||||
use App\Resource\Entity\ResourceType;
|
||||
use App\Resource\Entity\Skill;
|
||||
use App\Resource\Repository\ClinicResourceRepository;
|
||||
use App\Resource\Repository\ResourcePoolRepository;
|
||||
use App\Clinic\Repository\ClinicRepository;
|
||||
use App\Resource\Repository\ResourceTypeRepository;
|
||||
use App\Resource\Repository\SkillRepository;
|
||||
use App\Shared\Constant\ErrorCodes;
|
||||
@@ -36,6 +39,8 @@ final class ResourceContext
|
||||
private readonly SkillRepository $skills,
|
||||
private readonly ResourcePoolRepository $pools,
|
||||
private readonly TenantOwnershipChecker $ownership,
|
||||
private readonly DoctorRepository $doctors,
|
||||
private readonly ClinicRepository $clinics,
|
||||
) {}
|
||||
|
||||
/** @return array{0: string, 1: int} */
|
||||
@@ -54,6 +59,38 @@ final class ResourceContext
|
||||
return $this->owned($user, $this->types->findByUuid($uuid), 'نوع منبع یافت نشد');
|
||||
}
|
||||
|
||||
/**
|
||||
* پزشکِ ناظرِ منبع.
|
||||
*
|
||||
* `Doctor` تحت `TenantOwnedTrait` نیست (پزشک میتواند همزمان عضو چند کلینیک باشد)،
|
||||
* پس مالکیت با عضویت سنجیده میشود: در محیط کلینیک باید پزشکِ همان کلینیک باشد، و در
|
||||
* مطب شخصی باید خودِ همان پزشک. بدون این، منشیِ یک کلینیک میتوانست دستگاهش را زیر
|
||||
* نظر پزشک کلینیک دیگری ببرد.
|
||||
*/
|
||||
public function supervisor(User $user, string $uuid): Doctor
|
||||
{
|
||||
$doctor = $this->doctors->findByUuid($uuid);
|
||||
|
||||
if ($doctor === null) {
|
||||
throw new AppException(ErrorCodes::ERR_NOT_FOUND_001, 'پزشک ناظر یافت نشد', 404);
|
||||
}
|
||||
|
||||
[$entityType, $entityId] = $this->pair($user);
|
||||
|
||||
// رابطه از سمت کلینیک تعریف شده (`Clinic::$doctors`)، پس عضویت را خودِ کلینیک
|
||||
// جواب میدهد — `Clinic::hasDoctor()`؛ کوئری تازهای لازم نیست.
|
||||
$clinic = $entityType === 'clinic' ? $this->clinics->find($entityId) : null;
|
||||
$belongs = $entityType === 'clinic'
|
||||
? ($clinic !== null && $clinic->hasDoctor($doctor))
|
||||
: (int) $doctor->getId() === $entityId;
|
||||
|
||||
if (!$belongs) {
|
||||
throw new AppException(ErrorCodes::ERR_NOT_FOUND_001, 'پزشک ناظر یافت نشد', 404);
|
||||
}
|
||||
|
||||
return $doctor;
|
||||
}
|
||||
|
||||
public function resource(User $user, string $uuid): ClinicResource
|
||||
{
|
||||
return $this->owned($user, $this->resources->findByUuid($uuid), 'منبع یافت نشد');
|
||||
|
||||
Reference in New Issue
Block a user