feat: enhance agent management and validation logic
- Updated AGENTS.md to clarify agent account restrictions and permissions. - Implemented checks in AgentNodeAdminUserStoreController and AgentNodeRoleStoreController to restrict admin user and role creation to the agent's own node. - Enhanced validation in AdminPlayerStoreController and AdminPlayerUpdateController to enforce credit limit and rebate rate rules based on player funding mode. - Refactored various request classes to utilize shared admin account field rules for consistency. - Improved error handling in services related to credit allocation and rebate limits to ensure proper validation and messaging.
This commit is contained in:
@@ -15,7 +15,15 @@ final class AgentAdminUserAuthorization
|
||||
|
||||
$agent = $target->primaryAgentNode();
|
||||
if ($agent === null) {
|
||||
return false;
|
||||
// Target is a platform account (site admin)
|
||||
// Check if admin can access the same sites
|
||||
$adminSiteIds = $admin->accessibleAdminSiteIds();
|
||||
$targetSiteIds = $target->accessibleAdminSiteIds();
|
||||
if ($adminSiteIds === null || $targetSiteIds === null) {
|
||||
return false;
|
||||
}
|
||||
// Check if they share any accessible sites
|
||||
return !empty(array_intersect($adminSiteIds, $targetSiteIds));
|
||||
}
|
||||
|
||||
return AdminAgentScope::nodeVisibleTo($admin, $agent);
|
||||
@@ -36,8 +44,13 @@ final class AgentAdminUserAuthorization
|
||||
}
|
||||
|
||||
$agent = $target->primaryAgentNode();
|
||||
if ($agent === null) {
|
||||
// Target is a platform account (site admin)
|
||||
// Platform accounts can manage other platform accounts in the same site
|
||||
return true;
|
||||
}
|
||||
|
||||
return $agent !== null && AdminAgentScope::nodeManageableBy($admin, $agent);
|
||||
return AdminAgentScope::nodeManageableBy($admin, $agent);
|
||||
}
|
||||
|
||||
public static function denyUnlessUserManageable(AdminUser $admin, AdminUser $target): ?\Illuminate\Http\JsonResponse
|
||||
|
||||
Reference in New Issue
Block a user