feat(secretary): grant staff/discounts/sms/appointment_settings/clinic_doctors (phase B)
Extends the secretary permission system to five previously owner-only modules, so a clinic/doctor can delegate each page to a secretary. All were unreachable by secretaries before (role-based tenant resolution returned "unknown" → 403). New permission resources (default-deny, three-place add: entity default, SecretaryPermissions type, both MySecretariesPage + admin SecretariesPage): staff, discounts, sms, appointment_settings (view/update only), clinic_doctors (clinic-only — hidden from independent doctors via `clinicOnly` section filter). Backend enforcement (SecretaryAccessChecker, three new reusable helpers): - resolveOwnerEntity(): owner pair from active context — used by StaffController, DiscountController, SmsWalletController (now secretary-aware resolveEntity). - canForDoctor(): per-doctor-scoped check (assigned doctor + toggle) — wired into AppointmentSettingsController::denyDoctorAccess. - canForClinic(): clinic-scoped check — wired into ClinicController::detachDoctor, ClinicDoctorPermissionController (view/update), ClinicInvitationController (create/view/update/delete). clinic_doctors is clinic-context only. Guards run ahead of any subscription gate; non-secretary roles pass unchanged. Frontend: - RoleRoute: staff, discounts, sms-wallet, appointment-settings (doctor+clinic variants), settings/clinic-doctors routes accept secretary + permission gate. - Sidebar (secretary branch): five new items gated by can(); appointment_settings route follows active scope; clinic_doctors only in clinic scope. Tests: SecretaryResourceEnforcementTest — denied-by-default + allowed-when-granted for all five (18 total). Sidebar.test — B-resource gating + clinic_doctors scope rule. docs/api/secretary.md resource list, enforcement map, JSON example updated. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -9,6 +9,7 @@ use App\Discount\Repository\DiscountRuleRepository;
|
||||
use App\Discount\Service\DiscountEngine;
|
||||
use App\Doctor\Repository\DoctorRepository;
|
||||
use App\Patient\Repository\PatientSessionRepository;
|
||||
use App\Secretary\Security\SecretaryAccessChecker;
|
||||
use App\Shared\Constant\ErrorCodes;
|
||||
use App\Shared\Controller\BaseController;
|
||||
use Symfony\Component\HttpFoundation\JsonResponse;
|
||||
@@ -25,6 +26,7 @@ class DiscountController extends BaseController
|
||||
private readonly DoctorRepository $doctorRepo,
|
||||
private readonly ClinicRepository $clinicRepo,
|
||||
private readonly PatientSessionRepository $sessionRepo,
|
||||
private readonly SecretaryAccessChecker $secretaryAccess,
|
||||
) {}
|
||||
|
||||
/** @return array{0: string, 1: ?int} */
|
||||
@@ -36,6 +38,10 @@ class DiscountController extends BaseController
|
||||
if ($user->hasRole('ROLE_CLINIC')) {
|
||||
return ['clinic', $this->clinicRepo->findByUser($user)?->getId()];
|
||||
}
|
||||
// منشی روی tenantِ محیطِ فعال؛ مجوز جدا با denyUnlessGranted.
|
||||
if ($user->hasRole('ROLE_SECRETARY')) {
|
||||
return $this->secretaryAccess->resolveOwnerEntity($user);
|
||||
}
|
||||
return ['unknown', null];
|
||||
}
|
||||
|
||||
@@ -45,6 +51,7 @@ class DiscountController extends BaseController
|
||||
#[IsGranted('IS_AUTHENTICATED_FULLY')]
|
||||
public function list(#[CurrentUser] User $user): JsonResponse
|
||||
{
|
||||
$this->secretaryAccess->denyUnlessGranted($user, 'discounts', 'view');
|
||||
[$ownerType, $ownerId] = $this->resolveOwner($user);
|
||||
if ($ownerId === null) {
|
||||
return $this->error(ErrorCodes::ERR_AUTH_006, 'دسترسی ممنوع', 403);
|
||||
@@ -57,6 +64,7 @@ class DiscountController extends BaseController
|
||||
#[IsGranted('IS_AUTHENTICATED_FULLY')]
|
||||
public function create(Request $request, #[CurrentUser] User $user): JsonResponse
|
||||
{
|
||||
$this->secretaryAccess->denyUnlessGranted($user, 'discounts', 'create');
|
||||
[$ownerType, $ownerId] = $this->resolveOwner($user);
|
||||
if ($ownerId === null) {
|
||||
return $this->error(ErrorCodes::ERR_AUTH_006, 'دسترسی ممنوع', 403);
|
||||
@@ -84,6 +92,7 @@ class DiscountController extends BaseController
|
||||
#[IsGranted('IS_AUTHENTICATED_FULLY')]
|
||||
public function update(string $uuid, Request $request, #[CurrentUser] User $user): JsonResponse
|
||||
{
|
||||
$this->secretaryAccess->denyUnlessGranted($user, 'discounts', 'update');
|
||||
[$ownerType, $ownerId] = $this->resolveOwner($user);
|
||||
if ($ownerId === null) {
|
||||
return $this->error(ErrorCodes::ERR_AUTH_006, 'دسترسی ممنوع', 403);
|
||||
@@ -117,6 +126,7 @@ class DiscountController extends BaseController
|
||||
#[IsGranted('IS_AUTHENTICATED_FULLY')]
|
||||
public function delete(string $uuid, #[CurrentUser] User $user): JsonResponse
|
||||
{
|
||||
$this->secretaryAccess->denyUnlessGranted($user, 'discounts', 'delete');
|
||||
[$ownerType, $ownerId] = $this->resolveOwner($user);
|
||||
if ($ownerId === null) {
|
||||
return $this->error(ErrorCodes::ERR_AUTH_006, 'دسترسی ممنوع', 403);
|
||||
|
||||
Reference in New Issue
Block a user