organization; $policy = $this->mergedPolicy($org, $room); if ($policy['org_only'] && ! $user) { return [false, 'This meeting requires a Ladill account.']; } if ($policy['authenticated_only'] && ! $user) { return [false, 'Please sign in to join this meeting.']; } if (! empty($policy['allowed_domains']) && $email) { $domain = Str($email)->after('@')->lower()->toString(); $allowed = collect($policy['allowed_domains'])->map(fn ($d) => strtolower(trim($d)))->filter(); if ($allowed->isNotEmpty() && ! $allowed->contains($domain)) { return [false, 'Your email domain is not allowed to join this meeting.']; } } if ($room->passcode && ! session()->get("meet.passcode.{$room->uuid}")) { return [false, 'passcode_required']; } if ($room->activeSession()?->is_locked && ! $this->isHost($room, $user)) { return [false, 'This meeting is locked.']; } if ($policy['recording_host_only'] && ! $this->isHost($room, $user)) { // enforced at recording start } return [true, null]; } public function isHost(Room $room, ?User $user): bool { return $user && $user->ownerRef() === $room->host_user_ref; } /** * @param array $policy */ public function updateOrganizationPolicy(Organization $org, array $policy): Organization { $org->update([ 'security_policy' => array_merge($org->security_policy ?? [], $policy), ]); AuditLogger::record($org->owner_ref, 'organization.security_updated', $org->id, auth()->user()?->ownerRef()); return $org->fresh(); } /** * @return array */ protected function mergedPolicy(?Organization $org, Room $room): array { return array_merge( config('meet.security_defaults'), $org?->security_policy ?? [], $room->settings['security'] ?? [], ); } }