Files
ladill-meet/app/Services/Meet/SecurityPolicyService.php
T
isaaccladandCursor 965fb992e9
Deploy Ladill Meet / deploy (push) Failing after 7s
Initial Ladill Meet release.
Phases 0–18: core meetings, webinar, breakouts, team chat, live streaming, town hall, billing, and Ladill Mail calendar wiring.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-30 23:35:29 +00:00

79 lines
2.3 KiB
PHP

<?php
namespace App\Services\Meet;
use App\Models\Organization;
use App\Models\Room;
use App\Models\User;
use Illuminate\Support\Str;
class SecurityPolicyService
{
public function canJoin(Room $room, ?User $user, ?string $email, ?string $ip = null): array
{
$org = $room->organization;
$policy = $this->mergedPolicy($org, $room);
if ($policy['org_only'] && ! $user) {
return [false, 'This meeting requires a Ladill account.'];
}
if ($policy['authenticated_only'] && ! $user) {
return [false, 'Please sign in to join this meeting.'];
}
if (! empty($policy['allowed_domains']) && $email) {
$domain = Str($email)->after('@')->lower()->toString();
$allowed = collect($policy['allowed_domains'])->map(fn ($d) => strtolower(trim($d)))->filter();
if ($allowed->isNotEmpty() && ! $allowed->contains($domain)) {
return [false, 'Your email domain is not allowed to join this meeting.'];
}
}
if ($room->passcode && ! session()->get("meet.passcode.{$room->uuid}")) {
return [false, 'passcode_required'];
}
if ($room->activeSession()?->is_locked && ! $this->isHost($room, $user)) {
return [false, 'This meeting is locked.'];
}
if ($policy['recording_host_only'] && ! $this->isHost($room, $user)) {
// enforced at recording start
}
return [true, null];
}
public function isHost(Room $room, ?User $user): bool
{
return $user && $user->ownerRef() === $room->host_user_ref;
}
/**
* @param array<string, mixed> $policy
*/
public function updateOrganizationPolicy(Organization $org, array $policy): Organization
{
$org->update([
'security_policy' => array_merge($org->security_policy ?? [], $policy),
]);
AuditLogger::record($org->owner_ref, 'organization.security_updated', $org->id, auth()->user()?->ownerRef());
return $org->fresh();
}
/**
* @return array<string, mixed>
*/
protected function mergedPolicy(Organization $org, Room $room): array
{
return array_merge(
config('meet.security_defaults'),
$org->security_policy ?? [],
$room->settings['security'] ?? [],
);
}
}