@@ -437,14 +437,14 @@ public function show(int $id)
437437 {
438438 // Not API
439439 abort_if (
440- Auth::User ()->role === 4 ,
440+ Auth::User ()->isAPI () ,
441441 Response::HTTP_FORBIDDEN ,
442442 '403 Forbidden '
443443 );
444444
445445 // for aditee only if he is assigne to that control
446446 abort_if (
447- Auth::User ()->role === 5 &&
447+ Auth::User ()->isAuditee () &&
448448 ! (DB ::table ('control_user ' )
449449 ->where ('control_id ' , $ id )
450450 ->where ('user_id ' , Auth::User ()->id )
@@ -509,7 +509,7 @@ public function edit(int $id)
509509 {
510510 // Only for administrator role
511511 abort_if (
512- Auth::User ()->role !== 1 ,
512+ ! Auth::User ()->isAdmin () ,
513513 Response::HTTP_FORBIDDEN ,
514514 '403 Forbidden '
515515 );
@@ -607,9 +607,9 @@ public function edit(int $id)
607607 */
608608 public function clone (Request $ request )
609609 {
610- // Only for admin and users
610+ // For administrators, users only
611611 abort_if (
612- ( Auth::User ()->role !== 1 ) && ( Auth::User ()->role !== 2 ),
612+ ! Auth::User ()->isAdmin ( ) && ! Auth::User ()->isUser ( ),
613613 Response::HTTP_FORBIDDEN ,
614614 '403 Forbidden '
615615 );
@@ -992,6 +992,13 @@ public function domains(Request $request)
992992
993993 public function measures (Request $ request )
994994 {
995+ // For administrators, users only
996+ abort_if (
997+ !Auth::User ()->isAdmin () && !Auth::User ()->isUser (),
998+ Response::HTTP_FORBIDDEN ,
999+ '403 Forbidden '
1000+ );
1001+
9951002 // get all active domains
9961003 $ domains = DB ::table ('domains ' )
9971004 ->select (
@@ -1067,9 +1074,9 @@ public function measures(Request $request)
10671074
10681075 public function attributes ()
10691076 {
1070- // Not API and auditee
1077+ // For administrators, users only
10711078 abort_if (
1072- Auth::User ()->role === 4 || Auth::User ()->role === 5 ,
1079+ ! Auth::User ()->isAdmin () && ! Auth::User ()->isUser () ,
10731080 Response::HTTP_FORBIDDEN ,
10741081 '403 Forbidden '
10751082 );
@@ -1129,9 +1136,9 @@ public function attributes()
11291136 */
11301137 public function plan (int $ id )
11311138 {
1132- // For administrators and users only
1139+ // For administrators, users only
11331140 abort_if (
1134- Auth::User ()->role !== 1 && Auth::User ()->role !== 2 ,
1141+ ! Auth::User ()->isAdmin () && ! Auth::User ()->isUser () ,
11351142 Response::HTTP_FORBIDDEN ,
11361143 '403 Forbidden '
11371144 );
@@ -1216,7 +1223,7 @@ public function unplan(Request $request)
12161223 {
12171224 // For administrators and users only
12181225 abort_if (
1219- Auth::User ()->role !== 1 && Auth::User ()->role !== 2 ,
1226+ ! Auth::User ()->isAdmin () && ! Auth::User ()->isUser () ,
12201227 Response::HTTP_FORBIDDEN ,
12211228 '403 Forbidden '
12221229 );
0 commit comments