permissionManager = $permissionManager; } /** * @param string $attribute * @param Activity $subject * @return bool */ protected function supports($attribute, $subject) { if (!($subject instanceof Activity)) { return false; } if (!\in_array($attribute, self::ALLOWED_ATTRIBUTES)) { return false; } return true; } /** * @param string $attribute * @param Activity $subject * @param TokenInterface $token * @return bool */ protected function voteOnAttribute($attribute, $subject, TokenInterface $token) { $user = $token->getUser(); if (!$user instanceof User) { return false; } if ($this->permissionManager->hasRolePermission($user, $attribute . '_activity')) { return true; } // those cannot be assigned to teams if (\in_array($attribute, ['create', 'delete'])) { return false; } $hasTeamleadPermission = $this->permissionManager->hasRolePermission($user, $attribute . '_teamlead_activity'); $hasTeamPermission = $this->permissionManager->hasRolePermission($user, $attribute . '_team_activity'); if (!$hasTeamleadPermission && !$hasTeamPermission) { return false; } /** @var Team $team */ foreach ($subject->getTeams() as $team) { if ($hasTeamleadPermission && $user->isTeamleadOf($team)) { return true; } if ($hasTeamPermission && $user->isInTeam($team)) { return true; } } // new and global activities have no project if (null === ($project = $subject->getProject())) { return false; } /** @var Team $team */ foreach ($project->getTeams() as $team) { if ($hasTeamleadPermission && $user->isTeamleadOf($team)) { return true; } if ($hasTeamPermission && $user->isInTeam($team)) { return true; } } if (null === ($customer = $project->getCustomer())) { return false; } /** @var Team $team */ foreach ($customer->getTeams() as $team) { if ($hasTeamleadPermission && $user->isTeamleadOf($team)) { return true; } if ($hasTeamPermission && $user->isInTeam($team)) { return true; } } return false; } }