Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
44 changes: 29 additions & 15 deletions routes/api.php
Original file line number Diff line number Diff line change
Expand Up @@ -47,20 +47,30 @@
Route::get('/me', [AuthController::class, 'me']);

// Role Management CRUD API
// Authorization handled by RoleManagementPolicy
Route::get('/roles', [RoleManagementController::class, 'index']);
Route::post('/roles', [RoleManagementController::class, 'store']);
Route::get('/roles/{id}', [RoleManagementController::class, 'show']);
Route::patch('/roles/{id}', [RoleManagementController::class, 'update']);
Route::delete('/roles/{id}', [RoleManagementController::class, 'destroy']);
// Authorization: Route-level permission middleware + Policy (defense-in-depth)
Route::get('/roles', [RoleManagementController::class, 'index'])
->middleware('permission:roles.read');
Route::post('/roles', [RoleManagementController::class, 'store'])
->middleware('permission:roles.create');
Route::get('/roles/{id}', [RoleManagementController::class, 'show'])
->middleware('permission:roles.read');
Route::patch('/roles/{id}', [RoleManagementController::class, 'update'])
->middleware('permission:roles.update');
Route::delete('/roles/{id}', [RoleManagementController::class, 'destroy'])
->middleware('permission:roles.delete');

// Permission Management CRUD API
// Authorization handled by PermissionManagementPolicy
Route::get('/permissions', [PermissionManagementController::class, 'index']);
Route::post('/permissions', [PermissionManagementController::class, 'store']);
Route::get('/permissions/{id}', [PermissionManagementController::class, 'show']);
Route::patch('/permissions/{id}', [PermissionManagementController::class, 'update']);
Route::delete('/permissions/{id}', [PermissionManagementController::class, 'destroy']);
// Authorization: Route-level permission middleware + Policy (defense-in-depth)
Route::get('/permissions', [PermissionManagementController::class, 'index'])
->middleware('permission:permissions.read');
Route::post('/permissions', [PermissionManagementController::class, 'store'])
->middleware('permission:permissions.create');
Route::get('/permissions/{id}', [PermissionManagementController::class, 'show'])
->middleware('permission:permissions.read');
Route::patch('/permissions/{id}', [PermissionManagementController::class, 'update'])
->middleware('permission:permissions.update');
Route::delete('/permissions/{id}', [PermissionManagementController::class, 'destroy'])
->middleware('permission:permissions.delete');

// Role management endpoints
Route::post('/users/{user}/roles', [RoleController::class, 'store'])
Expand All @@ -73,10 +83,14 @@
->middleware('permission:role.assign');

// User Direct Permission Assignment API (RBAC Phase 4)
// Authorization handled by UserPermissionPolicy (viewPermissions, assignPermission, revokePermission)
// Authorization: Policy-based (users can view own, Admin can view all/modify)
Route::get('/users/{user}/permissions', [UserPermissionController::class, 'index']);
Route::post('/users/{user}/permissions', [UserPermissionController::class, 'store']);
Route::delete('/users/{user}/permissions/{permission}', [UserPermissionController::class, 'destroy']);
// Authorization: Route-level permission middleware + Policy (Admin only)
Route::post('/users/{user}/permissions', [UserPermissionController::class, 'store'])
->middleware('permission:permissions.assign_direct');
Route::delete('/users/{user}/permissions/{permission}', [UserPermissionController::class, 'destroy'])
->middleware('permission:permissions.revoke_direct');
// Authorization: Policy-based (users can view own, Admin can view all)
Route::get('/users/{user}/permissions/direct', [UserPermissionController::class, 'direct']);

// Tenant-scoped Person endpoints
Expand Down
8 changes: 8 additions & 0 deletions tests/Feature/UserPermissionAssignmentApiTest.php
Original file line number Diff line number Diff line change
Expand Up @@ -28,12 +28,20 @@
Permission::create(['name' => 'employees.export', 'guard_name' => 'sanctum']);
Permission::create(['name' => 'reports.generate', 'guard_name' => 'sanctum']);
Permission::create(['name' => 'shifts.read', 'guard_name' => 'sanctum']);
Permission::create(['name' => 'permissions.read', 'guard_name' => 'sanctum']);
Permission::create(['name' => 'permissions.assign_direct', 'guard_name' => 'sanctum']);
Permission::create(['name' => 'permissions.revoke_direct', 'guard_name' => 'sanctum']);

// Create roles with permissions
$managerRole = Role::create(['name' => 'Manager', 'guard_name' => 'sanctum']);
$managerRole->givePermissionTo(['employees.read', 'shifts.read']);

$adminRole = Role::create(['name' => 'Admin', 'guard_name' => 'sanctum']);
$adminRole->givePermissionTo([
'permissions.read',
'permissions.assign_direct',
'permissions.revoke_direct',
]);
});

afterEach(function (): void {
Expand Down