feat: restrict access to booking edit and invoice to applicant

This commit is contained in:
Björn Fromme
2025-09-10 15:30:36 +02:00
parent 297becf7a0
commit b197152f12
4 changed files with 58 additions and 54 deletions
Generated
+48 -48
View File
@@ -230,16 +230,16 @@
}, },
{ {
"name": "doctrine/dbal", "name": "doctrine/dbal",
"version": "3.10.1", "version": "3.10.2",
"source": { "source": {
"type": "git", "type": "git",
"url": "https://github.com/doctrine/dbal.git", "url": "https://github.com/doctrine/dbal.git",
"reference": "3626601014388095d3af9de7e9e958623b7ef005" "reference": "c6c16cf787eaba3112203dfcd715fa2059c62282"
}, },
"dist": { "dist": {
"type": "zip", "type": "zip",
"url": "https://api.github.com/repos/doctrine/dbal/zipball/3626601014388095d3af9de7e9e958623b7ef005", "url": "https://api.github.com/repos/doctrine/dbal/zipball/c6c16cf787eaba3112203dfcd715fa2059c62282",
"reference": "3626601014388095d3af9de7e9e958623b7ef005", "reference": "c6c16cf787eaba3112203dfcd715fa2059c62282",
"shasum": "" "shasum": ""
}, },
"require": { "require": {
@@ -255,10 +255,10 @@
}, },
"require-dev": { "require-dev": {
"doctrine/cache": "^1.11|^2.0", "doctrine/cache": "^1.11|^2.0",
"doctrine/coding-standard": "13.0.0", "doctrine/coding-standard": "13.0.1",
"fig/log-test": "^1", "fig/log-test": "^1",
"jetbrains/phpstorm-stubs": "2023.1", "jetbrains/phpstorm-stubs": "2023.1",
"phpstan/phpstan": "2.1.17", "phpstan/phpstan": "2.1.22",
"phpstan/phpstan-strict-rules": "^2", "phpstan/phpstan-strict-rules": "^2",
"phpunit/phpunit": "9.6.23", "phpunit/phpunit": "9.6.23",
"slevomat/coding-standard": "8.16.2", "slevomat/coding-standard": "8.16.2",
@@ -324,7 +324,7 @@
], ],
"support": { "support": {
"issues": "https://github.com/doctrine/dbal/issues", "issues": "https://github.com/doctrine/dbal/issues",
"source": "https://github.com/doctrine/dbal/tree/3.10.1" "source": "https://github.com/doctrine/dbal/tree/3.10.2"
}, },
"funding": [ "funding": [
{ {
@@ -340,7 +340,7 @@
"type": "tidelift" "type": "tidelift"
} }
], ],
"time": "2025-08-05T12:18:06+00:00" "time": "2025-09-04T23:51:27+00:00"
}, },
{ {
"name": "doctrine/deprecations", "name": "doctrine/deprecations",
@@ -392,16 +392,16 @@
}, },
{ {
"name": "doctrine/doctrine-bundle", "name": "doctrine/doctrine-bundle",
"version": "2.15.1", "version": "2.16.1",
"source": { "source": {
"type": "git", "type": "git",
"url": "https://github.com/doctrine/DoctrineBundle.git", "url": "https://github.com/doctrine/DoctrineBundle.git",
"reference": "5a305c5e776f9d3eb87f5b94d40d50aff439211d" "reference": "152d5083f0cd205a278131dc4351a8c94d007fe1"
}, },
"dist": { "dist": {
"type": "zip", "type": "zip",
"url": "https://api.github.com/repos/doctrine/DoctrineBundle/zipball/5a305c5e776f9d3eb87f5b94d40d50aff439211d", "url": "https://api.github.com/repos/doctrine/DoctrineBundle/zipball/152d5083f0cd205a278131dc4351a8c94d007fe1",
"reference": "5a305c5e776f9d3eb87f5b94d40d50aff439211d", "reference": "152d5083f0cd205a278131dc4351a8c94d007fe1",
"shasum": "" "shasum": ""
}, },
"require": { "require": {
@@ -438,6 +438,7 @@
"phpunit/phpunit": "^9.6.22", "phpunit/phpunit": "^9.6.22",
"psr/log": "^1.1.4 || ^2.0 || ^3.0", "psr/log": "^1.1.4 || ^2.0 || ^3.0",
"symfony/doctrine-messenger": "^6.4 || ^7.0", "symfony/doctrine-messenger": "^6.4 || ^7.0",
"symfony/expression-language": "^6.4 || ^7.0",
"symfony/messenger": "^6.4 || ^7.0", "symfony/messenger": "^6.4 || ^7.0",
"symfony/phpunit-bridge": "^7.2", "symfony/phpunit-bridge": "^7.2",
"symfony/property-info": "^6.4 || ^7.0", "symfony/property-info": "^6.4 || ^7.0",
@@ -494,7 +495,7 @@
], ],
"support": { "support": {
"issues": "https://github.com/doctrine/DoctrineBundle/issues", "issues": "https://github.com/doctrine/DoctrineBundle/issues",
"source": "https://github.com/doctrine/DoctrineBundle/tree/2.15.1" "source": "https://github.com/doctrine/DoctrineBundle/tree/2.16.1"
}, },
"funding": [ "funding": [
{ {
@@ -510,7 +511,7 @@
"type": "tidelift" "type": "tidelift"
} }
], ],
"time": "2025-07-30T15:48:28+00:00" "time": "2025-09-05T15:24:53+00:00"
}, },
{ {
"name": "doctrine/doctrine-migrations-bundle", "name": "doctrine/doctrine-migrations-bundle",
@@ -2634,16 +2635,16 @@
}, },
{ {
"name": "nesbot/carbon", "name": "nesbot/carbon",
"version": "3.10.2", "version": "3.10.3",
"source": { "source": {
"type": "git", "type": "git",
"url": "https://github.com/CarbonPHP/carbon.git", "url": "https://github.com/CarbonPHP/carbon.git",
"reference": "76b5c07b8a9d2025ed1610e14cef1f3fd6ad2c24" "reference": "8e3643dcd149ae0fe1d2ff4f2c8e4bbfad7c165f"
}, },
"dist": { "dist": {
"type": "zip", "type": "zip",
"url": "https://api.github.com/repos/CarbonPHP/carbon/zipball/76b5c07b8a9d2025ed1610e14cef1f3fd6ad2c24", "url": "https://api.github.com/repos/CarbonPHP/carbon/zipball/8e3643dcd149ae0fe1d2ff4f2c8e4bbfad7c165f",
"reference": "76b5c07b8a9d2025ed1610e14cef1f3fd6ad2c24", "reference": "8e3643dcd149ae0fe1d2ff4f2c8e4bbfad7c165f",
"shasum": "" "shasum": ""
}, },
"require": { "require": {
@@ -2661,13 +2662,13 @@
"require-dev": { "require-dev": {
"doctrine/dbal": "^3.6.3 || ^4.0", "doctrine/dbal": "^3.6.3 || ^4.0",
"doctrine/orm": "^2.15.2 || ^3.0", "doctrine/orm": "^2.15.2 || ^3.0",
"friendsofphp/php-cs-fixer": "^3.75.0", "friendsofphp/php-cs-fixer": "^v3.87.1",
"kylekatarnls/multi-tester": "^2.5.3", "kylekatarnls/multi-tester": "^2.5.3",
"phpmd/phpmd": "^2.15.0", "phpmd/phpmd": "^2.15.0",
"phpstan/extension-installer": "^1.4.3", "phpstan/extension-installer": "^1.4.3",
"phpstan/phpstan": "^2.1.17", "phpstan/phpstan": "^2.1.22",
"phpunit/phpunit": "^10.5.46", "phpunit/phpunit": "^10.5.53",
"squizlabs/php_codesniffer": "^3.13.0" "squizlabs/php_codesniffer": "^3.13.4"
}, },
"bin": [ "bin": [
"bin/carbon" "bin/carbon"
@@ -2735,7 +2736,7 @@
"type": "tidelift" "type": "tidelift"
} }
], ],
"time": "2025-08-02T09:36:06+00:00" "time": "2025-09-06T13:39:36+00:00"
}, },
{ {
"name": "nyholm/psr7", "name": "nyholm/psr7",
@@ -10807,16 +10808,16 @@
}, },
{ {
"name": "friendsofphp/php-cs-fixer", "name": "friendsofphp/php-cs-fixer",
"version": "v3.86.0", "version": "v3.87.2",
"source": { "source": {
"type": "git", "type": "git",
"url": "https://github.com/PHP-CS-Fixer/PHP-CS-Fixer.git", "url": "https://github.com/PHP-CS-Fixer/PHP-CS-Fixer.git",
"reference": "4a952bd19dc97879b0620f495552ef09b55f7d36" "reference": "da5f0a7858c79b56fc0b8c36d3efcfe5f37f0992"
}, },
"dist": { "dist": {
"type": "zip", "type": "zip",
"url": "https://api.github.com/repos/PHP-CS-Fixer/PHP-CS-Fixer/zipball/4a952bd19dc97879b0620f495552ef09b55f7d36", "url": "https://api.github.com/repos/PHP-CS-Fixer/PHP-CS-Fixer/zipball/da5f0a7858c79b56fc0b8c36d3efcfe5f37f0992",
"reference": "4a952bd19dc97879b0620f495552ef09b55f7d36", "reference": "da5f0a7858c79b56fc0b8c36d3efcfe5f37f0992",
"shasum": "" "shasum": ""
}, },
"require": { "require": {
@@ -10827,39 +10828,38 @@
"ext-hash": "*", "ext-hash": "*",
"ext-json": "*", "ext-json": "*",
"ext-tokenizer": "*", "ext-tokenizer": "*",
"fidry/cpu-core-counter": "^1.2", "fidry/cpu-core-counter": "^1.3",
"php": "^7.4 || ^8.0", "php": "^7.4 || ^8.0",
"react/child-process": "^0.6.6", "react/child-process": "^0.6.6",
"react/event-loop": "^1.5", "react/event-loop": "^1.5",
"react/promise": "^3.2", "react/promise": "^3.3",
"react/socket": "^1.16", "react/socket": "^1.16",
"react/stream": "^1.4", "react/stream": "^1.4",
"sebastian/diff": "^4.0.6 || ^5.1.1 || ^6.0.2 || ^7.0", "sebastian/diff": "^4.0.6 || ^5.1.1 || ^6.0.2 || ^7.0",
"symfony/console": "^5.4.47 || ^6.4.13 || ^7.0", "symfony/console": "^5.4.47 || ^6.4.24 || ^7.0",
"symfony/event-dispatcher": "^5.4.45 || ^6.4.13 || ^7.0", "symfony/event-dispatcher": "^5.4.45 || ^6.4.24 || ^7.0",
"symfony/filesystem": "^5.4.45 || ^6.4.13 || ^7.0", "symfony/filesystem": "^5.4.45 || ^6.4.24 || ^7.0",
"symfony/finder": "^5.4.45 || ^6.4.17 || ^7.0", "symfony/finder": "^5.4.45 || ^6.4.24 || ^7.0",
"symfony/options-resolver": "^5.4.45 || ^6.4.16 || ^7.0", "symfony/options-resolver": "^5.4.45 || ^6.4.24 || ^7.0",
"symfony/polyfill-mbstring": "^1.32", "symfony/polyfill-mbstring": "^1.33",
"symfony/polyfill-php80": "^1.32", "symfony/polyfill-php80": "^1.33",
"symfony/polyfill-php81": "^1.32", "symfony/polyfill-php81": "^1.33",
"symfony/process": "^5.4.47 || ^6.4.20 || ^7.2", "symfony/process": "^5.4.47 || ^6.4.24 || ^7.2",
"symfony/stopwatch": "^5.4.45 || ^6.4.19 || ^7.0" "symfony/stopwatch": "^5.4.45 || ^6.4.24 || ^7.0"
}, },
"require-dev": { "require-dev": {
"facile-it/paraunit": "^1.3.1 || ^2.6", "facile-it/paraunit": "^1.3.1 || ^2.7",
"infection/infection": "^0.29.14", "infection/infection": "^0.29.14",
"justinrainbow/json-schema": "^5.3 || ^6.4", "justinrainbow/json-schema": "^6.5",
"keradus/cli-executor": "^2.2", "keradus/cli-executor": "^2.2",
"mikey179/vfsstream": "^1.6.12", "mikey179/vfsstream": "^1.6.12",
"php-coveralls/php-coveralls": "^2.8", "php-coveralls/php-coveralls": "^2.8",
"php-cs-fixer/accessible-object": "^1.1",
"php-cs-fixer/phpunit-constraint-isidenticalstring": "^1.6", "php-cs-fixer/phpunit-constraint-isidenticalstring": "^1.6",
"php-cs-fixer/phpunit-constraint-xmlmatchesxsd": "^1.6", "php-cs-fixer/phpunit-constraint-xmlmatchesxsd": "^1.6",
"phpunit/phpunit": "^9.6.23 || ^10.5.47 || ^11.5.25", "phpunit/phpunit": "^9.6.25 || ^10.5.53 || ^11.5.34",
"symfony/polyfill-php84": "^1.32", "symfony/polyfill-php84": "^1.33",
"symfony/var-dumper": "^5.4.48 || ^6.4.23 || ^7.3.1", "symfony/var-dumper": "^5.4.48 || ^6.4.24 || ^7.3.2",
"symfony/yaml": "^5.4.45 || ^6.4.23 || ^7.3.1" "symfony/yaml": "^5.4.45 || ^6.4.24 || ^7.3.2"
}, },
"suggest": { "suggest": {
"ext-dom": "For handling output formats in XML", "ext-dom": "For handling output formats in XML",
@@ -10900,7 +10900,7 @@
], ],
"support": { "support": {
"issues": "https://github.com/PHP-CS-Fixer/PHP-CS-Fixer/issues", "issues": "https://github.com/PHP-CS-Fixer/PHP-CS-Fixer/issues",
"source": "https://github.com/PHP-CS-Fixer/PHP-CS-Fixer/tree/v3.86.0" "source": "https://github.com/PHP-CS-Fixer/PHP-CS-Fixer/tree/v3.87.2"
}, },
"funding": [ "funding": [
{ {
@@ -10908,7 +10908,7 @@
"type": "github" "type": "github"
} }
], ],
"time": "2025-08-13T22:36:21+00:00" "time": "2025-09-10T09:51:40+00:00"
}, },
{ {
"name": "myclabs/deep-copy", "name": "myclabs/deep-copy",
+1
View File
@@ -8,6 +8,7 @@ class Booking
public ?int $agencyId = null; public ?int $agencyId = null;
public ?int $bookingNumber = null; public ?int $bookingNumber = null;
public ?string $status = null; public ?string $status = null;
public ?int $applicantId = null;
public ?PersonalData $applicant = null; public ?PersonalData $applicant = null;
public ?int $participantCount = null; public ?int $participantCount = null;
public ?float $price = null; public ?float $price = null;
@@ -21,6 +21,7 @@ class BookingsParser extends AbstractParser
$booking = new Booking(); $booking = new Booking();
$booking->id = $this->getIntOrNullValue($node->filterXPath('//id')); $booking->id = $this->getIntOrNullValue($node->filterXPath('//id'));
$booking->applicantId = $this->getIntOrNullValue($node->filterXPath('//idadresse_anmelder'));
$booking->bookingNumber = $this->getIntOrNullValue($node->filterXPath('//vorgangsnummer')); $booking->bookingNumber = $this->getIntOrNullValue($node->filterXPath('//vorgangsnummer'));
$booking->status = $this->getStringOrNullValue($node->filterXPath('//status')); $booking->status = $this->getStringOrNullValue($node->filterXPath('//status'));
$booking->participantCount = $this->getIntOrNullValue($node->filterXPath('//personen')); $booking->participantCount = $this->getIntOrNullValue($node->filterXPath('//personen'));
+8 -6
View File
@@ -64,18 +64,20 @@
</td> </td>
<td class="px-2 py-1 md:p-2"> <td class="px-2 py-1 md:p-2">
<div class="flex md:flex-col space-x-2 md:space-x-0 md:space-y-1"> <div class="flex md:flex-col space-x-2 md:space-x-0 md:space-y-1">
{% if booking.editable %} {% if booking.editable and booking.applicantId == app.user.addressId %}
<a href="{{ path('app_booking_edit', { 'id': booking.id }) }}" <a href="{{ path('app_booking_edit', { 'id': booking.id }) }}"
{{ stimulus_action('loading', 'toggle') }} {{ stimulus_action('loading', 'toggle') }}
class="button bg-button bg-button--secondary button--small"> class="button bg-button bg-button--secondary button--small">
bearbeiten bearbeiten
</a> </a>
{% endif %} {% endif %}
<a href="{{ path('app_booking_invoice', { 'id': booking.id }) }}" {% if booking.applicantId == app.user.addressId %}
class="button bg-button button--small" <a href="{{ path('app_booking_invoice', { 'id': booking.id }) }}"
target="_blank"> class="button bg-button button--small"
Rechnung target="_blank">
</a> Rechnung
</a>
{% endif %}
{% if booking.travelInfoUrl is not null %} {% if booking.travelInfoUrl is not null %}
<a href="{{ booking.travelInfoUrl }}" <a href="{{ booking.travelInfoUrl }}"
class="button bg-button bg-pink button--small" class="button bg-button bg-pink button--small"