Files
ladill-meet/app/Services/Meet/SecurityPolicyService.php
T
isaaccladandCursor d19c131428
Deploy Ladill Meet / deploy (push) Successful in 1m35s
Fix join 500, wallet dropdown balance, and launcher Meet entry.
Handle billing API failures gracefully on session start, add wallet.balance JSON endpoint, and sync Meet into the app launcher.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-01 16:50:02 +00:00

79 lines
2.3 KiB
PHP

<?php
namespace App\Services\Meet;
use App\Models\Organization;
use App\Models\Room;
use App\Models\User;
use Illuminate\Support\Str;
class SecurityPolicyService
{
public function canJoin(Room $room, ?User $user, ?string $email, ?string $ip = null): array
{
$org = $room->organization;
$policy = $this->mergedPolicy($org, $room);
if ($policy['org_only'] && ! $user) {
return [false, 'This meeting requires a Ladill account.'];
}
if ($policy['authenticated_only'] && ! $user) {
return [false, 'Please sign in to join this meeting.'];
}
if (! empty($policy['allowed_domains']) && $email) {
$domain = Str($email)->after('@')->lower()->toString();
$allowed = collect($policy['allowed_domains'])->map(fn ($d) => strtolower(trim($d)))->filter();
if ($allowed->isNotEmpty() && ! $allowed->contains($domain)) {
return [false, 'Your email domain is not allowed to join this meeting.'];
}
}
if ($room->passcode && ! session()->get("meet.passcode.{$room->uuid}")) {
return [false, 'passcode_required'];
}
if ($room->activeSession()?->is_locked && ! $this->isHost($room, $user)) {
return [false, 'This meeting is locked.'];
}
if ($policy['recording_host_only'] && ! $this->isHost($room, $user)) {
// enforced at recording start
}
return [true, null];
}
public function isHost(Room $room, ?User $user): bool
{
return $user && $user->ownerRef() === $room->host_user_ref;
}
/**
* @param array<string, mixed> $policy
*/
public function updateOrganizationPolicy(Organization $org, array $policy): Organization
{
$org->update([
'security_policy' => array_merge($org->security_policy ?? [], $policy),
]);
AuditLogger::record($org->owner_ref, 'organization.security_updated', $org->id, auth()->user()?->ownerRef());
return $org->fresh();
}
/**
* @return array<string, mixed>
*/
protected function mergedPolicy(?Organization $org, Room $room): array
{
return array_merge(
config('meet.security_defaults'),
$org?->security_policy ?? [],
$room->settings['security'] ?? [],
);
}
}