isSuperAdmin()) { if ($requestedSiteId !== null && $requestedSiteId > 0) { return $requestedSiteId; } return (int) (AdminSite::query()->where('is_default', true)->value('id') ?? AdminSite::query()->orderBy('id')->value('id')); } $actor = AdminAgentScope::primaryAgentNode($admin); if ($actor === null) { return null; } if ($requestedSiteId !== null && $requestedSiteId > 0 && $requestedSiteId !== (int) $actor->admin_site_id) { return null; } return (int) $actor->admin_site_id; } public static function denyUnlessSiteResolved(AdminUser $admin, ?int $siteId): ?JsonResponse { if ($siteId !== null && $siteId > 0) { return null; } return ApiMessage::errorResponse( request(), 'admin.agent_site_access_denied', ErrorCode::AdminForbidden->value, null, 403, ); } public static function denyUnlessNodeVisible(AdminUser $admin, AgentNode $node): ?JsonResponse { if (AdminAgentScope::nodeVisibleTo($admin, $node)) { return null; } return ApiMessage::errorResponse( request(), 'admin.agent_node_access_denied', ErrorCode::AdminForbidden->value, null, 403, ); } public static function denyUnlessCanManageParent(AdminUser $admin, AgentNode $parent): ?JsonResponse { if (! AdminAgentScope::nodeManageableBy($admin, $parent)) { return ApiMessage::errorResponse( request(), 'admin.agent_node_manage_denied', ErrorCode::AdminForbidden->value, null, 403, ); } if ($parent->isRoot() && ! $admin->isSuperAdmin()) { return ApiMessage::errorResponse( request(), 'admin.agent_root_create_denied', ErrorCode::AdminForbidden->value, null, 403, ); } return null; } }