3 namespace BookStack\Http\Controllers;
6 use HttpRequestException;
7 use Illuminate\Foundation\Bus\DispatchesJobs;
8 use Illuminate\Http\Exception\HttpResponseException;
9 use Illuminate\Routing\Controller as BaseController;
10 use Illuminate\Foundation\Validation\ValidatesRequests;
11 use Illuminate\Support\Facades\Auth;
12 use Illuminate\Support\Facades\Session;
15 abstract class Controller extends BaseController
17 use DispatchesJobs, ValidatesRequests;
22 protected $currentUser;
29 * Controller constructor.
31 public function __construct()
33 // Get a user instance for the current user
34 $user = auth()->user();
35 if (!$user) $user = User::getDefault();
37 // Share variables with views
38 view()->share('signedIn', auth()->check());
39 view()->share('currentUser', $user);
41 // Share variables with controllers
42 $this->currentUser = $user;
43 $this->signedIn = auth()->check();
47 * Stops the application and shows a permission error if
48 * the application is in demo mode.
50 protected function preventAccessForDemoUsers()
52 if (config('app.env') === 'demo') $this->showPermissionError();
56 * Adds the page title into the view.
59 public function setPageTitle($title)
61 view()->share('pageTitle', $title);
65 * On a permission error redirect to home and display.
66 * the error as a notification.
68 protected function showPermissionError()
70 Session::flash('error', trans('errors.permission'));
71 throw new HttpResponseException(
77 * Checks for a permission.
78 * @param string $permissionName
79 * @return bool|\Illuminate\Http\RedirectResponse
81 protected function checkPermission($permissionName)
83 if (!$this->currentUser || !$this->currentUser->can($permissionName)) {
84 $this->showPermissionError();
90 * Check the current user's permissions against an ownable item.
92 * @param Ownable $ownable
95 protected function checkOwnablePermission($permission, Ownable $ownable)
97 $permissionBaseName = strtolower($permission) . '-';
98 if (userCan($permissionBaseName . 'all')) return true;
99 if (userCan($permissionBaseName . 'own') && $ownable->createdBy->id === $this->currentUser->id) return true;
100 $this->showPermissionError();
104 * Check if a user has a permission or bypass if the callback is true.
105 * @param $permissionName
109 protected function checkPermissionOr($permissionName, $callback)
111 $callbackResult = $callback();
112 if ($callbackResult === false) $this->checkPermission($permissionName);