9705b335ef
Les ressources métier (ProjectManagement, Directory, TimeTracking) étaient
gardées par is_granted('ROLE_USER')/'ROLE_ADMIN', ignorant les permissions
RBAC granulaires déclarées par les modules : un utilisateur sans permission
voyait quand même projets, tâches, clients, etc.
- PermissionVoter : le regex excluait les tirets, donc project-management.* et
time-tracking.* n'étaient supportées par aucun voter (refus pour tous, admin
compris car le bypass ROLE_ADMIN est interne au voter). Ajout du tiret.
- Câblage des permissions *.view (lecture) / *.manage (écriture) sur les 17
ressources métier. Métadonnées tâches lisibles via projects.view OR tasks.view.
Directory partagé client/prospect via clients.* OR prospects.*. TimeEntry
conserve le self-service (object.getUser() == user).
- Sidebar : gating par permission effective des onglets Projets / Mes tâches /
Suivi du temps (config/sidebar.php).
- Test fonctionnel ProjectAccessControlTest (0 perm -> 403, view -> 200,
view ne donne pas l'écriture -> 403).
188 lines
5.5 KiB
PHP
188 lines
5.5 KiB
PHP
<?php
|
|
|
|
declare(strict_types=1);
|
|
|
|
namespace App\Module\Directory\Domain\Entity;
|
|
|
|
use ApiPlatform\Doctrine\Orm\Filter\SearchFilter;
|
|
use ApiPlatform\Metadata\ApiFilter;
|
|
use ApiPlatform\Metadata\ApiResource;
|
|
use ApiPlatform\Metadata\Delete;
|
|
use ApiPlatform\Metadata\Get;
|
|
use ApiPlatform\Metadata\GetCollection;
|
|
use ApiPlatform\Metadata\Patch;
|
|
use ApiPlatform\Metadata\Post;
|
|
use App\Module\Directory\Domain\Enum\ReportType;
|
|
use App\Module\Directory\Infrastructure\Doctrine\DoctrineCommercialReportRepository;
|
|
use App\Shared\Domain\Contract\TimestampableInterface;
|
|
use App\Shared\Domain\Contract\UserInterface;
|
|
use App\Shared\Domain\Trait\TimestampableBlamableTrait;
|
|
use DateTimeImmutable;
|
|
use Doctrine\Common\Collections\ArrayCollection;
|
|
use Doctrine\Common\Collections\Collection;
|
|
use Doctrine\DBAL\Types\Types;
|
|
use Doctrine\ORM\Mapping as ORM;
|
|
use Symfony\Component\Serializer\Attribute\Groups;
|
|
|
|
#[ApiResource(
|
|
operations: [
|
|
new GetCollection(paginationEnabled: false, security: "is_granted('directory.clients.view') or is_granted('directory.prospects.view')"),
|
|
new Get(security: "is_granted('directory.clients.view') or is_granted('directory.prospects.view')"),
|
|
new Post(security: "is_granted('directory.clients.manage') or is_granted('directory.prospects.manage')"),
|
|
new Patch(security: "is_granted('directory.clients.manage') or is_granted('directory.prospects.manage')"),
|
|
new Delete(security: "is_granted('directory.clients.manage') or is_granted('directory.prospects.manage')"),
|
|
],
|
|
normalizationContext: ['groups' => ['commercial_report:read']],
|
|
denormalizationContext: ['groups' => ['commercial_report:write']],
|
|
order: ['occurredAt' => 'DESC'],
|
|
)]
|
|
#[ApiFilter(SearchFilter::class, properties: ['client' => 'exact', 'prospect' => 'exact'])]
|
|
#[ORM\Entity(repositoryClass: DoctrineCommercialReportRepository::class)]
|
|
#[ORM\Table(name: 'commercial_report')]
|
|
class CommercialReport implements TimestampableInterface
|
|
{
|
|
use TimestampableBlamableTrait;
|
|
|
|
#[ORM\Id]
|
|
#[ORM\GeneratedValue]
|
|
#[ORM\Column]
|
|
#[Groups(['commercial_report:read'])]
|
|
private ?int $id = null;
|
|
|
|
#[ORM\Column(length: 255)]
|
|
#[Groups(['commercial_report:read', 'commercial_report:write'])]
|
|
private ?string $subject = null;
|
|
|
|
#[ORM\Column(type: Types::TEXT, nullable: true)]
|
|
#[Groups(['commercial_report:read', 'commercial_report:write'])]
|
|
private ?string $body = null;
|
|
|
|
#[ORM\Column(type: Types::DATE_IMMUTABLE)]
|
|
#[Groups(['commercial_report:read', 'commercial_report:write'])]
|
|
private ?DateTimeImmutable $occurredAt = null;
|
|
|
|
#[ORM\Column(type: Types::STRING, length: 32, enumType: ReportType::class)]
|
|
#[Groups(['commercial_report:read', 'commercial_report:write'])]
|
|
private ReportType $type = ReportType::Note;
|
|
|
|
#[ORM\ManyToOne(targetEntity: UserInterface::class)]
|
|
#[ORM\JoinColumn(name: 'author_id', referencedColumnName: 'id', nullable: true, onDelete: 'SET NULL')]
|
|
#[Groups(['commercial_report:read'])]
|
|
private ?UserInterface $author = null;
|
|
|
|
#[ORM\ManyToOne(targetEntity: Client::class)]
|
|
#[ORM\JoinColumn(name: 'client_id', referencedColumnName: 'id', nullable: true, onDelete: 'CASCADE')]
|
|
#[Groups(['commercial_report:read', 'commercial_report:write'])]
|
|
private ?Client $client = null;
|
|
|
|
#[ORM\ManyToOne(targetEntity: Prospect::class)]
|
|
#[ORM\JoinColumn(name: 'prospect_id', referencedColumnName: 'id', nullable: true, onDelete: 'CASCADE')]
|
|
#[Groups(['commercial_report:read', 'commercial_report:write'])]
|
|
private ?Prospect $prospect = null;
|
|
|
|
/** @var Collection<int, ReportDocument> */
|
|
#[ORM\OneToMany(targetEntity: ReportDocument::class, mappedBy: 'commercialReport', cascade: ['remove'])]
|
|
#[Groups(['commercial_report:read'])]
|
|
private Collection $documents;
|
|
|
|
public function __construct()
|
|
{
|
|
$this->documents = new ArrayCollection();
|
|
}
|
|
|
|
public function getId(): ?int
|
|
{
|
|
return $this->id;
|
|
}
|
|
|
|
public function getSubject(): ?string
|
|
{
|
|
return $this->subject;
|
|
}
|
|
|
|
public function setSubject(string $subject): static
|
|
{
|
|
$this->subject = $subject;
|
|
|
|
return $this;
|
|
}
|
|
|
|
public function getBody(): ?string
|
|
{
|
|
return $this->body;
|
|
}
|
|
|
|
public function setBody(?string $body): static
|
|
{
|
|
$this->body = $body;
|
|
|
|
return $this;
|
|
}
|
|
|
|
public function getOccurredAt(): ?DateTimeImmutable
|
|
{
|
|
return $this->occurredAt;
|
|
}
|
|
|
|
public function setOccurredAt(DateTimeImmutable $occurredAt): static
|
|
{
|
|
$this->occurredAt = $occurredAt;
|
|
|
|
return $this;
|
|
}
|
|
|
|
public function getType(): ReportType
|
|
{
|
|
return $this->type;
|
|
}
|
|
|
|
public function setType(ReportType $type): static
|
|
{
|
|
$this->type = $type;
|
|
|
|
return $this;
|
|
}
|
|
|
|
public function getAuthor(): ?UserInterface
|
|
{
|
|
return $this->author;
|
|
}
|
|
|
|
public function setAuthor(?UserInterface $author): static
|
|
{
|
|
$this->author = $author;
|
|
|
|
return $this;
|
|
}
|
|
|
|
public function getClient(): ?Client
|
|
{
|
|
return $this->client;
|
|
}
|
|
|
|
public function setClient(?Client $client): static
|
|
{
|
|
$this->client = $client;
|
|
|
|
return $this;
|
|
}
|
|
|
|
public function getProspect(): ?Prospect
|
|
{
|
|
return $this->prospect;
|
|
}
|
|
|
|
public function setProspect(?Prospect $prospect): static
|
|
{
|
|
$this->prospect = $prospect;
|
|
|
|
return $this;
|
|
}
|
|
|
|
/** @return Collection<int, ReportDocument> */
|
|
public function getDocuments(): Collection
|
|
{
|
|
return $this->documents;
|
|
}
|
|
}
|