Critical: - Fix EnsureUserSetupIsComplete middleware route name prefixes and redirect Subscription step to subscribe page (not onboarding) - Fix MCP session pollution: Auth::setUser() instead of Auth::login() - Remove dead BillingController::addWorkspace/removeWorkspace methods - Remove broken Workspace::pendingInvites() method Security (IDOR): - MediaController: add workspace ownership verification on all endpoints - UpdatePostRequest: scope label_ids validation to current workspace - UpdatePostRequest: scope platform IDs validation to current post Security (other): - Fix open redirect in login and registration (validate internal URLs) - Add validation to API PostController store/update (was $request->all()) - Prevent Owner role assignment via updateRole endpoint - Fix API post author attribution to use workspace owner Authorization: - PostController: use createPost policy instead of view for store/update/destroy Logic: - Post Status enum labels now use translation system instead of hardcoded Portuguese - Workspace deletion cleans up current_workspace_id for all affected members - StoreWorkspaceInviteRequest: replace Portuguese validation messages with __() Rename onboarding: - Step1.vue -> Role.vue, Step2.vue -> Connect.vue - Controller methods: step1->role, storeStep1->storeRole, step2->connect, storeStep2->storeConnect All 728 tests passing.
95 lines
2.3 KiB
PHP
95 lines
2.3 KiB
PHP
<?php
|
|
|
|
declare(strict_types=1);
|
|
|
|
namespace App\Models;
|
|
|
|
use App\Models\Traits\HasMedia;
|
|
use Database\Factories\WorkspaceFactory;
|
|
use Illuminate\Database\Eloquent\Concerns\HasUuids;
|
|
use Illuminate\Database\Eloquent\Factories\HasFactory;
|
|
use Illuminate\Database\Eloquent\Model;
|
|
use Illuminate\Database\Eloquent\Relations\BelongsTo;
|
|
use Illuminate\Database\Eloquent\Relations\BelongsToMany;
|
|
use Illuminate\Database\Eloquent\Relations\HasMany;
|
|
|
|
class Workspace extends Model
|
|
{
|
|
/** @use HasFactory<WorkspaceFactory> */
|
|
use HasFactory, HasMedia, HasUuids;
|
|
|
|
protected $fillable = [
|
|
'user_id',
|
|
'name',
|
|
'timezone',
|
|
];
|
|
|
|
protected $appends = ['has_logo', 'logo_url'];
|
|
|
|
public function getHasLogoAttribute(): bool
|
|
{
|
|
return $this->getFirstMedia('logo') !== null;
|
|
}
|
|
|
|
public function getLogoUrlAttribute(): ?string
|
|
{
|
|
return $this->getFirstMediaUrl('logo') ?: null;
|
|
}
|
|
|
|
public function owner(): BelongsTo
|
|
{
|
|
return $this->belongsTo(User::class, 'user_id');
|
|
}
|
|
|
|
public function members(): BelongsToMany
|
|
{
|
|
return $this->belongsToMany(User::class)
|
|
->withPivot('role')
|
|
->withTimestamps();
|
|
}
|
|
|
|
public function socialAccounts(): HasMany
|
|
{
|
|
return $this->hasMany(SocialAccount::class);
|
|
}
|
|
|
|
public function posts(): HasMany
|
|
{
|
|
return $this->hasMany(Post::class);
|
|
}
|
|
|
|
public function invites(): HasMany
|
|
{
|
|
return $this->hasMany(WorkspaceInvite::class);
|
|
}
|
|
|
|
public function hashtags(): HasMany
|
|
{
|
|
return $this->hasMany(WorkspaceHashtag::class);
|
|
}
|
|
|
|
public function labels(): HasMany
|
|
{
|
|
return $this->hasMany(WorkspaceLabel::class);
|
|
}
|
|
|
|
public function apiTokens(): HasMany
|
|
{
|
|
return $this->hasMany(ApiToken::class);
|
|
}
|
|
|
|
public function hasMember(User $user): bool
|
|
{
|
|
return $this->user_id === $user->id || $this->members()->where('user_id', $user->id)->exists();
|
|
}
|
|
|
|
public function hasConnectedPlatform(string $platform): bool
|
|
{
|
|
return $this->socialAccounts()->where('platform', $platform)->exists();
|
|
}
|
|
|
|
public function getSocialAccount(string $platform): ?SocialAccount
|
|
{
|
|
return $this->socialAccounts()->where('platform', $platform)->first();
|
|
}
|
|
}
|