Gallery Route, only allow tour participants+admins, correction of User()->has_tour method

This commit is contained in:
Torsten 2023-10-01 09:53:19 +02:00
parent 529b71d005
commit b3179c957c
5 changed files with 32 additions and 16 deletions

View file

@ -4,6 +4,7 @@ namespace App\Http\Controllers;
use App\Gallery;
use Illuminate\Http\Request;
use Auth;
class GalleryController extends Controller
{
@ -12,10 +13,6 @@ class GalleryController extends Controller
*
* @return \Illuminate\Http\Response
*/
public function index()
{
//
}
/**
* Show the form for creating a new resource.
@ -44,9 +41,15 @@ class GalleryController extends Controller
* @param \App\Gallery $gallery
* @return \Illuminate\Http\Response
*/
public function show(Gallery $gallery)
{
//
public function show($tour_id)
{
//dd("role:" . Auth::user()->role . " id:" . \Auth::id() . " has_tour:" . Auth::user()->has_tour($tour_id, \Auth::id()));
if(Auth::user()->role=="ADMIN" or Auth::user()->has_tour($tour_id, \Auth::id()) ) {
return view('tour/gallery/show');
}
return redirect('/tour/index_old');
}
/**
@ -55,7 +58,7 @@ class GalleryController extends Controller
* @param \App\Gallery $gallery
* @return \Illuminate\Http\Response
*/
public function edit(Gallery $gallery)
public function edit($tour_id)
{
//
}
@ -67,7 +70,7 @@ class GalleryController extends Controller
* @param \App\Gallery $gallery
* @return \Illuminate\Http\Response
*/
public function update(Request $request, Gallery $gallery)
public function update(Request $request, $tour_id)
{
//
}
@ -78,7 +81,7 @@ class GalleryController extends Controller
* @param \App\Gallery $gallery
* @return \Illuminate\Http\Response
*/
public function destroy(Gallery $gallery)
public function destroy($tour_id)
{
//
}

View file

@ -39,10 +39,7 @@
public static function has_tour($tour_id, $user_id)
{
// $tour=Tour::find($tour_id);
// $user=User::first($user_id);
$booking = Booking::where('tour_id', $tour_id)->where('user_id', $user_id);
if ($booking) return true;
return false;
$booking = Booking::where('tour_id', $tour_id)->where('user_id', $user_id)->get();
return $booking->count() > 0;
}
}

View file

@ -0,0 +1,14 @@
@extends('layouts.app')
@section('content')
<div class="container text-center text-light mt-5">
<h1 class="text-center">Galerie</h1>
<div class="container text-primary" style="display:flex">
<ul class="list-group offset-2 col-8">
</ul>
</div>
</div>
@endsection

View file

@ -18,7 +18,7 @@
<li class="list-group-item d-flex justify-content-between align-items-center">
{{ $tour->start }} - {{ $tour->name }} [{{$participantCount[$tour->id]}}/{{$tour->max_participants}}]
<a href="#">(Bilder)</a>
<a href="/tour/gallery/{{$tour->id}}">(Galerie)</a>
@if(App\Tour::has_participant($tour->id, Auth::user()->id)==true)
<i class="fas fa-biking"></i>
@endif

View file

@ -63,6 +63,8 @@
Route::get('/img_storage/{category}/{imageName}', 'ImageController@getImage'); // no middleware auth needed, its checked in Controller
Route::get('/tour/gallery/{gallery_id}', 'GalleryController@show'); // no middleware auth needed, its checked in Controller
Auth::routes();
/* Cache clearing on remote server */