Deploy Ladill Meet / deploy (push) Failing after 7s
Phases 0–18: core meetings, webinar, breakouts, team chat, live streaming, town hall, billing, and Ladill Mail calendar wiring. Co-authored-by: Cursor <cursoragent@cursor.com>
79 lines
2.3 KiB
PHP
79 lines
2.3 KiB
PHP
<?php
|
|
|
|
namespace App\Services\Meet;
|
|
|
|
use App\Models\Organization;
|
|
use App\Models\Room;
|
|
use App\Models\User;
|
|
use Illuminate\Support\Str;
|
|
|
|
class SecurityPolicyService
|
|
{
|
|
public function canJoin(Room $room, ?User $user, ?string $email, ?string $ip = null): array
|
|
{
|
|
$org = $room->organization;
|
|
$policy = $this->mergedPolicy($org, $room);
|
|
|
|
if ($policy['org_only'] && ! $user) {
|
|
return [false, 'This meeting requires a Ladill account.'];
|
|
}
|
|
|
|
if ($policy['authenticated_only'] && ! $user) {
|
|
return [false, 'Please sign in to join this meeting.'];
|
|
}
|
|
|
|
if (! empty($policy['allowed_domains']) && $email) {
|
|
$domain = Str($email)->after('@')->lower()->toString();
|
|
$allowed = collect($policy['allowed_domains'])->map(fn ($d) => strtolower(trim($d)))->filter();
|
|
if ($allowed->isNotEmpty() && ! $allowed->contains($domain)) {
|
|
return [false, 'Your email domain is not allowed to join this meeting.'];
|
|
}
|
|
}
|
|
|
|
if ($room->passcode && ! session()->get("meet.passcode.{$room->uuid}")) {
|
|
return [false, 'passcode_required'];
|
|
}
|
|
|
|
if ($room->activeSession()?->is_locked && ! $this->isHost($room, $user)) {
|
|
return [false, 'This meeting is locked.'];
|
|
}
|
|
|
|
if ($policy['recording_host_only'] && ! $this->isHost($room, $user)) {
|
|
// enforced at recording start
|
|
}
|
|
|
|
return [true, null];
|
|
}
|
|
|
|
public function isHost(Room $room, ?User $user): bool
|
|
{
|
|
return $user && $user->ownerRef() === $room->host_user_ref;
|
|
}
|
|
|
|
/**
|
|
* @param array<string, mixed> $policy
|
|
*/
|
|
public function updateOrganizationPolicy(Organization $org, array $policy): Organization
|
|
{
|
|
$org->update([
|
|
'security_policy' => array_merge($org->security_policy ?? [], $policy),
|
|
]);
|
|
|
|
AuditLogger::record($org->owner_ref, 'organization.security_updated', $org->id, auth()->user()?->ownerRef());
|
|
|
|
return $org->fresh();
|
|
}
|
|
|
|
/**
|
|
* @return array<string, mixed>
|
|
*/
|
|
protected function mergedPolicy(Organization $org, Room $room): array
|
|
{
|
|
return array_merge(
|
|
config('meet.security_defaults'),
|
|
$org->security_policy ?? [],
|
|
$room->settings['security'] ?? [],
|
|
);
|
|
}
|
|
}
|