Allow specialty doctors to open patient charts and order labs.
Deploy Ladill Care / deploy (push) Successful in 1m18s

Branch-scoped staff could 404 on charts when the patient's home branch differed from the visit site; Orders also linked doctors to a lab index they could not access.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
isaacclad
2026-07-18 16:49:59 +00:00
co-authored by Cursor
parent c3a090112b
commit e227f8705f
7 changed files with 159 additions and 21 deletions
+17 -2
View File
@@ -4,7 +4,9 @@ namespace App\Http\Controllers\Api;
use App\Http\Controllers\Controller;
use App\Http\Controllers\Api\Concerns\ScopesApiToAccount;
use App\Models\Appointment;
use App\Models\Patient;
use App\Models\Visit;
use App\Services\Care\CarePermissions;
use App\Services\Care\OrganizationResolver;
use App\Services\Care\PatientService;
@@ -89,9 +91,22 @@ class PatientController extends Controller
abort_unless($patient->organization_id === $this->organization($request)->id, 404);
$branchScope = app(OrganizationResolver::class)->branchScope($this->member($request));
if ($branchScope !== null && $patient->branch_id !== $branchScope) {
abort(404);
if ($branchScope === null || $patient->branch_id === $branchScope) {
return;
}
$hasLocalActivity = Visit::query()
->where('patient_id', $patient->id)
->where('organization_id', $patient->organization_id)
->where('branch_id', $branchScope)
->exists()
|| Appointment::query()
->where('patient_id', $patient->id)
->where('organization_id', $patient->organization_id)
->where('branch_id', $branchScope)
->exists();
abort_unless($hasLocalActivity, 404);
}
/**
@@ -4,8 +4,10 @@ namespace App\Http\Controllers\Care;
use App\Http\Controllers\Controller;
use App\Http\Controllers\Care\Concerns\ScopesToAccount;
use App\Models\Appointment;
use App\Models\Branch;
use App\Models\Patient;
use App\Models\Visit;
use App\Services\Care\AdminOverviewService;
use App\Services\Care\CareFeatures;
use App\Services\Care\CarePermissions;
@@ -293,9 +295,24 @@ class PatientController extends Controller
abort_unless($patient->organization_id === $this->organization($request)->id, 404);
$branchId = app(OrganizationResolver::class)->branchScope($this->member($request));
if ($branchId !== null && $patient->branch_id !== $branchId) {
abort(404);
if ($branchId === null || $patient->branch_id === $branchId) {
return;
}
// Home branch may differ from the site where care is delivered — allow chart
// access when the patient has a visit or appointment at the member's branch.
$hasLocalActivity = Visit::query()
->where('patient_id', $patient->id)
->where('organization_id', $patient->organization_id)
->where('branch_id', $branchId)
->exists()
|| Appointment::query()
->where('patient_id', $patient->id)
->where('organization_id', $patient->organization_id)
->where('branch_id', $branchId)
->exists();
abort_unless($hasLocalActivity, 404);
}
/**
@@ -4,7 +4,9 @@ namespace App\Http\Controllers\Care;
use App\Http\Controllers\Controller;
use App\Http\Controllers\Care\Concerns\ScopesToAccount;
use App\Models\Appointment;
use App\Models\Patient;
use App\Models\Visit;
use App\Services\Billing\PlatformEmailClient;
use App\Services\Billing\PlatformSmsClient;
use App\Services\Care\AuditLogger;
@@ -176,8 +178,21 @@ class PatientMessageController extends Controller
abort_unless($patient->organization_id === $this->organization($request)->id, 404);
$branchId = app(OrganizationResolver::class)->branchScope($this->member($request));
if ($branchId !== null && $patient->branch_id !== $branchId) {
abort(404);
if ($branchId === null || $patient->branch_id === $branchId) {
return;
}
$hasLocalActivity = Visit::query()
->where('patient_id', $patient->id)
->where('organization_id', $patient->organization_id)
->where('branch_id', $branchId)
->exists()
|| Appointment::query()
->where('patient_id', $patient->id)
->where('organization_id', $patient->organization_id)
->where('branch_id', $branchId)
->exists();
abort_unless($hasLocalActivity, 404);
}
}
@@ -6,6 +6,7 @@ use App\Http\Controllers\Care\Concerns\ScopesToAccount;
use App\Http\Controllers\Controller;
use App\Models\Appointment;
use App\Models\Department;
use App\Models\InvestigationType;
use App\Models\PatientAttachment;
use App\Models\Visit;
use App\Services\Care\AppointmentService;
@@ -507,6 +508,7 @@ class SpecialtyModuleController extends Controller
$clinicalFields = [];
$clinicalAlerts = [];
$visitDocuments = collect();
$investigationTypes = collect();
$dentalChart = null;
$dentalTeethMap = [];
$dentalPlan = null;
@@ -529,9 +531,9 @@ class SpecialtyModuleController extends Controller
'patient.emergencyContacts',
'patient.attachments',
'appointment.practitioner',
'appointment.consultation',
'appointment.consultation.investigationRequests.investigationType',
'bill.lineItems',
'consultations',
'consultations.investigationRequests.investigationType',
]);
$workspaceVisit = $visit;
if ($visit->patient) {
@@ -549,9 +551,9 @@ class SpecialtyModuleController extends Controller
'patient.emergencyContacts',
'patient.attachments',
'appointment.practitioner',
'appointment.consultation',
'appointment.consultation.investigationRequests.investigationType',
'bill.lineItems',
'consultations',
'consultations.investigationRequests.investigationType',
]);
$workspaceVisit = $first;
$patientHeader = array_merge(
@@ -624,6 +626,14 @@ class SpecialtyModuleController extends Controller
->limit(20)
->get()
: collect();
if ($activeTab === 'orders' && $canConsult) {
$investigationTypes = InvestigationType::query()
->where('organization_id', $organization->id)
->where('is_active', true)
->orderBy('name')
->get();
}
}
return view('care.specialty.shell', [
@@ -650,6 +660,7 @@ class SpecialtyModuleController extends Controller
'clinicalFields' => $clinicalFields,
'clinicalAlerts' => $clinicalAlerts,
'visitDocuments' => $visitDocuments,
'investigationTypes' => $investigationTypes,
'dentalChart' => $dentalChart,
'dentalTeethMap' => $dentalTeethMap,
'dentalPlan' => $dentalPlan,