* fix deprecations * remove unused config * replace invalid annotation type with attribute * use AsDoctrineListener to fix deprecation * new ModifiedSubscriber to support custom logic and fix deprecation * removed inheritdoc comment * new ModifiedSubscriber to support custom logic and fix deprecation * cleanup event dispatcher interface * re-order annotation params * one more doctrine based deprecation * fix query to count active timesheets * link to "all times" to identify active timesheets * link icon instead of text * fix "skin" translation in wizard * use duration filter to show duration * added login link command and controller * bump tabler theme to 1.0 * added wizard to force password reset by user * allow to configure that new accounts need to reset their password * prevent uploading twig templates by default * bump composer packages * enable sandbox and basic security measures for custom twig templates for invoice and export * bump to symfony 6.3.5 * allow to export single user reports to excel * removed broken method to reload twig cache * added api parameter to fetch user collection fully serialized * allow to replace or append description via timesheet batch update * show api username above form
42 lines
1014 B
PHP
42 lines
1014 B
PHP
<?php
|
|
|
|
/*
|
|
* This file is part of the Kimai time-tracking app.
|
|
*
|
|
* For the full copyright and license information, please view the LICENSE
|
|
* file that was distributed with this source code.
|
|
*/
|
|
|
|
namespace App\Twig\SecurityPolicy;
|
|
|
|
use Twig\Sandbox\SecurityPolicyInterface;
|
|
|
|
/**
|
|
* Represents the security policy for custom Twig export templates.
|
|
*/
|
|
final class ExportPolicy implements SecurityPolicyInterface
|
|
{
|
|
private ChainPolicy $policy;
|
|
|
|
public function __construct()
|
|
{
|
|
$this->policy = new ChainPolicy();
|
|
$this->policy->addPolicy(new DefaultPolicy());
|
|
}
|
|
|
|
public function checkSecurity($tags, $filters, $functions): void
|
|
{
|
|
$this->policy->checkSecurity($tags, $filters, $functions);
|
|
}
|
|
|
|
public function checkMethodAllowed($obj, $method): void
|
|
{
|
|
$this->policy->checkMethodAllowed($obj, $method);
|
|
}
|
|
|
|
public function checkPropertyAllowed($obj, $property): void
|
|
{
|
|
$this->policy->checkPropertyAllowed($obj, $property);
|
|
}
|
|
}
|