From d4361121d892d03066742c458c26876a1a1af324 Mon Sep 17 00:00:00 2001 From: FernandoJVideira <03.pleaser-minster@icloud.com> Date: Sat, 27 Dec 2025 15:07:48 +0000 Subject: [PATCH] feat: api admin policies --- api/app/Http/Controllers/UserController.php | 16 +++ api/app/Policies/GamePolicy.php | 105 ++++++++++++++++++++ 2 files changed, 121 insertions(+) create mode 100644 api/app/Policies/GamePolicy.php diff --git a/api/app/Http/Controllers/UserController.php b/api/app/Http/Controllers/UserController.php index 32bc653..5583071 100644 --- a/api/app/Http/Controllers/UserController.php +++ b/api/app/Http/Controllers/UserController.php @@ -184,4 +184,20 @@ class UserController extends Controller return response()->json($matches); } + + public function block(User $user) + { + $user->blocked = true; + $user->save(); + + return response()->json(['message' => 'User blocked successfully']); + } + + public function unblock(User $user) + { + $user->blocked = false; + $user->save(); + + return response()->json(['message' => 'User unblocked successfully']); + } } diff --git a/api/app/Policies/GamePolicy.php b/api/app/Policies/GamePolicy.php new file mode 100644 index 0000000..a352662 --- /dev/null +++ b/api/app/Policies/GamePolicy.php @@ -0,0 +1,105 @@ +type === 'A' || $user->blocked === 1 ) { + return true; + } + + return false; + } + + /** + * Determine whether the user can view the model. + */ + public function view(User $user, Game $game): bool + { + return false; + } + + /** + * Determine whether the user can create models. + */ + public function create(User $user): bool + { + if ($user->type === 'A' || $user->blocked === 1) { + return false; + } + + return true; + } + + public function join(User $user, Game $game): bool + { + if ($user->type === 'A' || $user->blocked === 1) { + return false; + } + + if ($game->status !== 'waiting' || $game->player1_user_id === $user->id) { + return false; + } + + return true; + } + + public function resign(User $user, Game $game): bool + { + if ($user->type === 'A' || $user->blocked === 1) { + return false; + } + + if ( + $game->status !== 'ongoing' || + ($game->player1_user_id !== $user->id && + $game->player2_user_id !== $user->id) + ) { + return false; + } + + return true; + } + + /** + * Determine whether the user can update the model. + */ + public function update(User $user, Game $game): bool + { + if ($user->type === 'A' || $user->blocked === 1) { + return false; + } + } + + /** + * Determine whether the user can delete the model. + */ + public function delete(User $user, Game $game): bool + { + return false; + } + + /** + * Determine whether the user can restore the model. + */ + public function restore(User $user, Game $game): bool + { + return false; + } + + /** + * Determine whether the user can permanently delete the model. + */ + public function forceDelete(User $user, Game $game): bool + { + return false; + } +}