- Updated AGENTS.md to clarify agent account restrictions and permissions. - Implemented checks in AgentNodeAdminUserStoreController and AgentNodeRoleStoreController to restrict admin user and role creation to the agent's own node. - Enhanced validation in AdminPlayerStoreController and AdminPlayerUpdateController to enforce credit limit and rebate rate rules based on player funding mode. - Refactored various request classes to utilize shared admin account field rules for consistency. - Improved error handling in services related to credit allocation and rebate limits to ensure proper validation and messaging.
51 lines
1.2 KiB
PHP
51 lines
1.2 KiB
PHP
<?php
|
|
|
|
namespace App\Http\Requests\Admin;
|
|
|
|
use App\Http\Requests\Admin\Concerns\AgentProfileFieldRules;
|
|
use App\Http\Requests\ApiFormRequest;
|
|
|
|
final class AdminAgentProfileUpdateRequest extends ApiFormRequest
|
|
{
|
|
use AgentProfileFieldRules;
|
|
|
|
public function authorize(): bool
|
|
{
|
|
$admin = $this->user();
|
|
if (! $admin instanceof \App\Models\AdminUser) {
|
|
return false;
|
|
}
|
|
|
|
$agentNode = $this->route('agent_node');
|
|
if (! $agentNode instanceof \App\Models\AgentNode) {
|
|
return false;
|
|
}
|
|
|
|
if (! \App\Support\AdminAgentScope::nodeVisibleTo($admin, $agentNode)) {
|
|
return false;
|
|
}
|
|
|
|
if (! \App\Support\AdminAgentScope::nodeProfileEditableBy($admin, $agentNode)) {
|
|
return false;
|
|
}
|
|
|
|
return true;
|
|
}
|
|
|
|
protected function failedAuthorization(): void
|
|
{
|
|
abort(403, 'admin.permission_denied');
|
|
}
|
|
|
|
protected function prepareForValidation(): void
|
|
{
|
|
$this->prepareAgentProfileFieldsForValidation();
|
|
}
|
|
|
|
/** @return array<string, mixed> */
|
|
public function rules(): array
|
|
{
|
|
return $this->agentProfileFieldRules();
|
|
}
|
|
}
|