feat: enhance agent management and validation logic
- Updated AGENTS.md to clarify agent account restrictions and permissions. - Implemented checks in AgentNodeAdminUserStoreController and AgentNodeRoleStoreController to restrict admin user and role creation to the agent's own node. - Enhanced validation in AdminPlayerStoreController and AdminPlayerUpdateController to enforce credit limit and rebate rate rules based on player funding mode. - Refactored various request classes to utilize shared admin account field rules for consistency. - Improved error handling in services related to credit allocation and rebate limits to ensure proper validation and messaging.
This commit is contained in:
@@ -11,9 +11,32 @@ final class AdminAgentProfileUpdateRequest extends ApiFormRequest
|
||||
|
||||
public function authorize(): bool
|
||||
{
|
||||
$admin = $this->user();
|
||||
if (! $admin instanceof \App\Models\AdminUser) {
|
||||
return false;
|
||||
}
|
||||
|
||||
$agentNode = $this->route('agent_node');
|
||||
if (! $agentNode instanceof \App\Models\AgentNode) {
|
||||
return false;
|
||||
}
|
||||
|
||||
if (! \App\Support\AdminAgentScope::nodeVisibleTo($admin, $agentNode)) {
|
||||
return false;
|
||||
}
|
||||
|
||||
if (! \App\Support\AdminAgentScope::nodeProfileEditableBy($admin, $agentNode)) {
|
||||
return false;
|
||||
}
|
||||
|
||||
return true;
|
||||
}
|
||||
|
||||
protected function failedAuthorization(): void
|
||||
{
|
||||
abort(403, 'admin.permission_denied');
|
||||
}
|
||||
|
||||
protected function prepareForValidation(): void
|
||||
{
|
||||
$this->prepareAgentProfileFieldsForValidation();
|
||||
|
||||
Reference in New Issue
Block a user