Critical: - Fix EnsureUserSetupIsComplete middleware route name prefixes and redirect Subscription step to subscribe page (not onboarding) - Fix MCP session pollution: Auth::setUser() instead of Auth::login() - Remove dead BillingController::addWorkspace/removeWorkspace methods - Remove broken Workspace::pendingInvites() method Security (IDOR): - MediaController: add workspace ownership verification on all endpoints - UpdatePostRequest: scope label_ids validation to current workspace - UpdatePostRequest: scope platform IDs validation to current post Security (other): - Fix open redirect in login and registration (validate internal URLs) - Add validation to API PostController store/update (was $request->all()) - Prevent Owner role assignment via updateRole endpoint - Fix API post author attribution to use workspace owner Authorization: - PostController: use createPost policy instead of view for store/update/destroy Logic: - Post Status enum labels now use translation system instead of hardcoded Portuguese - Workspace deletion cleans up current_workspace_id for all affected members - StoreWorkspaceInviteRequest: replace Portuguese validation messages with __() Rename onboarding: - Step1.vue -> Role.vue, Step2.vue -> Connect.vue - Controller methods: step1->role, storeStep1->storeRole, step2->connect, storeStep2->storeConnect All 728 tests passing.
48 lines
1.3 KiB
PHP
48 lines
1.3 KiB
PHP
<?php
|
|
|
|
declare(strict_types=1);
|
|
|
|
namespace App\Http\Requests\App\Invite;
|
|
|
|
use App\Enums\UserWorkspace\Role as WorkspaceRole;
|
|
use Illuminate\Contracts\Validation\ValidationRule;
|
|
use Illuminate\Foundation\Http\FormRequest;
|
|
use Illuminate\Validation\Rule;
|
|
|
|
class StoreWorkspaceInviteRequest extends FormRequest
|
|
{
|
|
/**
|
|
* Determine if the user is authorized to make this request.
|
|
*/
|
|
public function authorize(): bool
|
|
{
|
|
return true;
|
|
}
|
|
|
|
/**
|
|
* Get the validation rules that apply to the request.
|
|
*
|
|
* @return array<string, ValidationRule|array<mixed>|string>
|
|
*/
|
|
public function rules(): array
|
|
{
|
|
return [
|
|
'email' => ['required', 'email', 'max:255'],
|
|
'role' => ['nullable', Rule::in([WorkspaceRole::Admin->value, WorkspaceRole::Member->value])],
|
|
];
|
|
}
|
|
|
|
/**
|
|
* Get custom messages for validation errors.
|
|
*
|
|
* @return array<string, string>
|
|
*/
|
|
public function messages(): array
|
|
{
|
|
return [
|
|
'email.required' => __('validation.required', ['attribute' => 'email']),
|
|
'email.email' => __('validation.email', ['attribute' => 'email']),
|
|
'email.max' => __('validation.max.string', ['attribute' => 'email', 'max' => 255]),
|
|
];
|
|
}
|
|
}
|