feat(access): per-page user/group grants, snap-in-local
A snap-in-owned access mechanism. Adds:
- unifi_page_grants table (nav_item_id, grantee_type, grantee_id)
with cascadeOnDelete from nav_items so uninstalling the snap-in
wipes its grant rows automatically
- UnifiPageGrant model + ::userCanAccess(user, navItem) helper
- UnifiPagesAccessController (index + update), super-admin only
- RouteMatched listener in UnifiServiceProvider that 403s any
unifi.* route if the matched nav_item has grants and the user
isn't a super-admin / granted user / member of a granted group
Semantics: a page with NO grants stays open per the existing
permission middleware (no behaviour change). The moment grants are
added, ONLY super-admins and listed users/groups can see/open the
page. Super-admins always pass; their access can't be removed.
v1.4.0.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,38 @@
|
||||
<?php
|
||||
|
||||
use Illuminate\Database\Migrations\Migration;
|
||||
use Illuminate\Database\Schema\Blueprint;
|
||||
use Illuminate\Support\Facades\Schema;
|
||||
|
||||
return new class extends Migration
|
||||
{
|
||||
/**
|
||||
* Per-page access grants for unifi pages. A user can access a unifi
|
||||
* page if ANY of these hold:
|
||||
* - is_super_admin (always)
|
||||
* - user has the page's required_permission (existing nav_items column)
|
||||
* - user is in the page's required_group_id (existing column)
|
||||
* - a row here grants them as a user, or via a group they're in
|
||||
*
|
||||
* Snap-in-local table — disappears with the snap-in if uninstalled.
|
||||
*/
|
||||
public function up(): void
|
||||
{
|
||||
Schema::create('unifi_page_grants', function (Blueprint $table) {
|
||||
$table->id();
|
||||
$table->foreignId('nav_item_id')->constrained('nav_items')->cascadeOnDelete();
|
||||
$table->enum('grantee_type', ['user', 'group']);
|
||||
$table->unsignedBigInteger('grantee_id');
|
||||
$table->foreignId('granted_by_user_id')->nullable()->constrained('users')->nullOnDelete();
|
||||
$table->timestamps();
|
||||
|
||||
$table->unique(['nav_item_id', 'grantee_type', 'grantee_id'], 'unifi_page_grants_unique');
|
||||
$table->index(['grantee_type', 'grantee_id']);
|
||||
});
|
||||
}
|
||||
|
||||
public function down(): void
|
||||
{
|
||||
Schema::dropIfExists('unifi_page_grants');
|
||||
}
|
||||
};
|
||||
Reference in New Issue
Block a user