security: expand and complete permissions matrix with granular, enterprise-ready permissions
This commit is contained in:
@@ -33,11 +33,11 @@ class UserPolicy
|
||||
|
||||
public function restore(User $authUser, User $user): bool
|
||||
{
|
||||
return $authUser->hasPermissionTo('user.delete');
|
||||
return $authUser->hasPermissionTo('user.restore');
|
||||
}
|
||||
|
||||
public function forceDelete(User $authUser, User $user): bool
|
||||
{
|
||||
return $authUser->hasPermissionTo('user.delete') && $authUser->id !== $user->id;
|
||||
return $authUser->hasPermissionTo('user.force-delete') && $authUser->id !== $user->id;
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user