<?php
namespace App\Security\Voter;
use App\Entity\Company\User;
use App\Entity\Invoice\ImportedInvoice;
use App\Entity\Invoice\Invoice;
use Symfony\Component\Security\Core\Authentication\Token\TokenInterface;
use Symfony\Component\Security\Core\Authorization\Voter\Voter;
use Symfony\Component\Security\Core\User\UserInterface;
class InvoiceVoter extends Voter
{
public const EDIT = 'EDIT';
public const VIEW = 'VIEW';
public const DELETE = 'DELETE';
public const CONTINUE = 'CONTINUE';
public const SEND_MAIL = 'SEND_MAIL';
public const PAYMENT = 'PAYMENT';
protected function supports(string $attribute, mixed $subject): bool
{
return $subject instanceof Invoice;
}
protected function voteOnAttribute(string $attribute, mixed $subject, TokenInterface $token): bool
{
$user = $token->getUser();
if (!$user instanceof UserInterface) {
return false;
}
return match ($attribute) {
self::EDIT => $this->canPerformSimpleAction($subject, $user),
self::VIEW => $this->canPerformSimpleAction($subject, $user),
self::DELETE => $this->canPerformSimpleAction($subject, $user),
self::CONTINUE => $this->canContinue($subject, $user),
self::SEND_MAIL => $this->canSendMail($subject, $user),
self::PAYMENT => $this->canPayInvoice($subject, $user)
};
}
/**
*
* @param Invoice $invoice
* @param User $user
* @return boolean
*/
private function canPerformSimpleAction(Invoice $invoice, User $user): bool
{
return $invoice->getCompany()->getId() == $user->getCompany()->getId();
}
/**
*
* @param Invoice $invoice
* @param User $user
* @return boolean
*/
private function canContinue(Invoice $invoice, User $user): bool
{
return $this->canPerformSimpleAction($invoice, $user) && $invoice->getStatus() == 0;
}
/**
*
* @param Invoice $invoice
* @param User $user
* @return boolean
*/
private function canSendMail(Invoice $invoice, User $user): bool
{
return $this->canPerformSimpleAction($invoice, $user) && $invoice->getStatus() == 1;
}
private function canPayInvoice(Invoice|ImportedInvoice $invoice, User $user): bool
{
if ($invoice instanceof Invoice) {
return $user->getCustomerCompany()->getStripeCustomer() != null &&
$invoice->getQuote()?->getPurchaseOrder()?->getConstructionSiteOffer()?->getConstructionSite()?->getCustomerCompany()?->getId() == $user->getCustomerCompany()->getId() &&
in_array($invoice->getStatus(), [1, 2]);
} else {
return $user->getCustomerCompany()->getStripeCustomer() != null &&
$invoice->getPurchaseOrder()?->getConstructionSiteOffer()?->getConstructionSite()?->getCustomerCompany()?->getId() == $user->getCustomerCompany()->getId() &&
in_array($invoice->getStatus(), [1, 2]);
}
}
}