initial commit
This commit is contained in:
@@ -12,13 +12,18 @@ use Illuminate\Support\Facades\View;
|
||||
use Illuminate\Support\ServiceProvider;
|
||||
use Illuminate\Support\Facades\Cache;
|
||||
use Illuminate\Support\Facades\Gate; // Import Gate untuk sistem permission
|
||||
use Illuminate\Support\Facades\URL;
|
||||
|
||||
class AppServiceProvider extends ServiceProvider
|
||||
{
|
||||
public function register(): void { /* ... */ }
|
||||
|
||||
|
||||
public function boot(): void
|
||||
{
|
||||
|
||||
if (config('app.env') === 'production') {
|
||||
URL::forceScheme('https');
|
||||
}
|
||||
// 1. DAFTARKAN OBSERVERS (Tetap Utuh & Aman)
|
||||
if (Schema::hasTable('medicines')) {
|
||||
Medicine::observe(MedicineObserver::class);
|
||||
@@ -51,29 +56,33 @@ class AppServiceProvider extends ServiceProvider
|
||||
$view->with($stockData);
|
||||
});
|
||||
|
||||
// 4. SISTEM OTORISASI GLOBAL (Gate Permission)
|
||||
// 4. SISTEM OTORISASI GLOBAL (Gate Permission)
|
||||
Gate::define('check-access', function ($user, $module, $permission) {
|
||||
// Hindari pengecekan jika user tidak memiliki role_id atau data role
|
||||
if (!$user->role_id && !$user->role) return false;
|
||||
|
||||
// Deteksi Role: Apakah string (lama) atau object (baru)
|
||||
// Jika $user->role adalah string, ambil langsung. Jika object, ambil slug-nya.
|
||||
$roleIdentifier = is_object($user->role) ? $user->role->slug : $user->role;
|
||||
|
||||
// Admin Bypass: Role admin memiliki akses ke seluruh fitur
|
||||
if ($roleIdentifier === 'admin') {
|
||||
// Dukungan akun legacy yang masih menyimpan role sebagai string.
|
||||
if ($user->getRawOriginal('role') === 'admin') {
|
||||
return true;
|
||||
}
|
||||
|
||||
if (!$user->role_id) {
|
||||
return false;
|
||||
}
|
||||
|
||||
$role = $user->roleModel;
|
||||
if ($role?->slug === 'admin') {
|
||||
return true;
|
||||
}
|
||||
|
||||
// Menyelaraskan nama kolom (can_read, can_create, can_update, can_delete)
|
||||
$column = str_starts_with($permission, 'can_') ? $permission : 'can_' . $permission;
|
||||
|
||||
// Cek matriks di tabel role_permissions berdasarkan role_id
|
||||
return \App\Models\RolePermission::where('role_id', $user->role_id)
|
||||
->where('module_slug', $module)
|
||||
->where($column, 1)
|
||||
->exists();
|
||||
try {
|
||||
return \App\Models\RolePermission::where('role_id', $user->role_id)
|
||||
->where('module_slug', $module)
|
||||
->where($column, 1)
|
||||
->exists();
|
||||
} catch (\Throwable $e) {
|
||||
return false;
|
||||
}
|
||||
});
|
||||
}
|
||||
}
|
||||
|
||||
}
|
||||
Reference in New Issue
Block a user