Phases 0–18: core meetings, webinar, breakouts, team chat, live streaming, town hall, billing, and Ladill Mail calendar wiring. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -0,0 +1,78 @@
|
||||
<?php
|
||||
|
||||
namespace App\Services\Meet;
|
||||
|
||||
use App\Models\Organization;
|
||||
use App\Models\Room;
|
||||
use App\Models\User;
|
||||
use Illuminate\Support\Str;
|
||||
|
||||
class SecurityPolicyService
|
||||
{
|
||||
public function canJoin(Room $room, ?User $user, ?string $email, ?string $ip = null): array
|
||||
{
|
||||
$org = $room->organization;
|
||||
$policy = $this->mergedPolicy($org, $room);
|
||||
|
||||
if ($policy['org_only'] && ! $user) {
|
||||
return [false, 'This meeting requires a Ladill account.'];
|
||||
}
|
||||
|
||||
if ($policy['authenticated_only'] && ! $user) {
|
||||
return [false, 'Please sign in to join this meeting.'];
|
||||
}
|
||||
|
||||
if (! empty($policy['allowed_domains']) && $email) {
|
||||
$domain = Str($email)->after('@')->lower()->toString();
|
||||
$allowed = collect($policy['allowed_domains'])->map(fn ($d) => strtolower(trim($d)))->filter();
|
||||
if ($allowed->isNotEmpty() && ! $allowed->contains($domain)) {
|
||||
return [false, 'Your email domain is not allowed to join this meeting.'];
|
||||
}
|
||||
}
|
||||
|
||||
if ($room->passcode && ! session()->get("meet.passcode.{$room->uuid}")) {
|
||||
return [false, 'passcode_required'];
|
||||
}
|
||||
|
||||
if ($room->activeSession()?->is_locked && ! $this->isHost($room, $user)) {
|
||||
return [false, 'This meeting is locked.'];
|
||||
}
|
||||
|
||||
if ($policy['recording_host_only'] && ! $this->isHost($room, $user)) {
|
||||
// enforced at recording start
|
||||
}
|
||||
|
||||
return [true, null];
|
||||
}
|
||||
|
||||
public function isHost(Room $room, ?User $user): bool
|
||||
{
|
||||
return $user && $user->ownerRef() === $room->host_user_ref;
|
||||
}
|
||||
|
||||
/**
|
||||
* @param array<string, mixed> $policy
|
||||
*/
|
||||
public function updateOrganizationPolicy(Organization $org, array $policy): Organization
|
||||
{
|
||||
$org->update([
|
||||
'security_policy' => array_merge($org->security_policy ?? [], $policy),
|
||||
]);
|
||||
|
||||
AuditLogger::record($org->owner_ref, 'organization.security_updated', $org->id, auth()->user()?->ownerRef());
|
||||
|
||||
return $org->fresh();
|
||||
}
|
||||
|
||||
/**
|
||||
* @return array<string, mixed>
|
||||
*/
|
||||
protected function mergedPolicy(Organization $org, Room $room): array
|
||||
{
|
||||
return array_merge(
|
||||
config('meet.security_defaults'),
|
||||
$org->security_policy ?? [],
|
||||
$room->settings['security'] ?? [],
|
||||
);
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user