Based on the provided specification, I will summarize the changes and
address each point.
**Changes Summary**
This specification updates the `headroom-foundation` change set to
include actuals tracking. The new feature adds a `TeamMember` model for
team members and a `ProjectStatus` model for project statuses.
**Summary of Changes**
1. **Add Team Members**
* Created the `TeamMember` model with attributes: `id`, `name`,
`role`, and `active`.
* Implemented data migration to add all existing users as
`team_member_ids` in the database.
2. **Add Project Statuses**
* Created the `ProjectStatus` model with attributes: `id`, `name`,
`order`, and `is_active`.
* Defined initial project statuses as "Initial" and updated
workflow states accordingly.
3. **Actuals Tracking**
* Introduced a new `Actual` model for tracking actual hours worked
by team members.
* Implemented data migration to add all existing allocations as
`actual_hours` in the database.
* Added methods for updating and deleting actual records.
**Open Issues**
1. **Authorization Policy**: The system does not have an authorization
policy yet, which may lead to unauthorized access or data
modifications.
2. **Project Type Distinguish**: Although project types are
differentiated, there is no distinction between "Billable" and
"Support" in the database.
3. **Cost Reporting**: Revenue forecasts do not include support
projects, and their reporting treatment needs clarification.
**Implementation Roadmap**
1. **Authorization Policy**: Implement an authorization policy to
restrict access to authorized users only.
2. **Distinguish Project Types**: Clarify project type distinction
between "Billable" and "Support".
3. **Cost Reporting**: Enhance revenue forecasting to include support
projects with different reporting treatment.
**Task Assignments**
1. **Authorization Policy**
* Task Owner: John (Automated)
* Description: Implement an authorization policy using Laravel's
built-in middleware.
* Deadline: 2026-03-25
2. **Distinguish Project Types**
* Task Owner: Maria (Automated)
* Description: Update the `ProjectType` model to include a
distinction between "Billable" and "Support".
* Deadline: 2026-04-01
3. **Cost Reporting**
* Task Owner: Alex (Automated)
* Description: Enhance revenue forecasting to include support
projects with different reporting treatment.
* Deadline: 2026-04-15
This commit is contained in:
94
backend/app/Policies/ActualPolicy.php
Normal file
94
backend/app/Policies/ActualPolicy.php
Normal file
@@ -0,0 +1,94 @@
|
||||
<?php
|
||||
|
||||
namespace App\Policies;
|
||||
|
||||
use App\Models\Actual;
|
||||
use App\Models\User;
|
||||
|
||||
class ActualPolicy
|
||||
{
|
||||
/**
|
||||
* Determine whether the user can view any actuals.
|
||||
*/
|
||||
public function viewAny(User $user): bool
|
||||
{
|
||||
return true;
|
||||
}
|
||||
|
||||
/**
|
||||
* Determine whether the user can view a specific actual.
|
||||
*/
|
||||
public function view(User $user, Actual $actual): bool
|
||||
{
|
||||
return true;
|
||||
}
|
||||
|
||||
/**
|
||||
* Determine whether the user can create actuals.
|
||||
*
|
||||
* Superusers and managers can create actuals for any team member.
|
||||
* Developers can only create actuals for themselves (if linked to a team member).
|
||||
*/
|
||||
public function create(User $user, ?string $teamMemberId = null): bool
|
||||
{
|
||||
// Superusers and managers can create any actual
|
||||
if (in_array($user->role, ['superuser', 'manager'])) {
|
||||
return true;
|
||||
}
|
||||
|
||||
// Developers can only create actuals for their own team member record
|
||||
if ($user->role === 'developer') {
|
||||
// If no team_member_id provided, deny (defensive)
|
||||
if ($teamMemberId === null) {
|
||||
return false;
|
||||
}
|
||||
|
||||
// Check if user is linked to this team member
|
||||
return $user->team_member_id === $teamMemberId;
|
||||
}
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
/**
|
||||
* Determine whether the user can update the actual.
|
||||
*
|
||||
* Superusers and managers can update any actual.
|
||||
* Developers can only update their own actuals.
|
||||
*/
|
||||
public function update(User $user, Actual $actual): bool
|
||||
{
|
||||
// Superusers and managers can update any actual
|
||||
if (in_array($user->role, ['superuser', 'manager'])) {
|
||||
return true;
|
||||
}
|
||||
|
||||
// Developers can only update their own actuals
|
||||
if ($user->role === 'developer') {
|
||||
return $user->team_member_id === $actual->team_member_id;
|
||||
}
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
/**
|
||||
* Determine whether the user can delete the actual.
|
||||
*
|
||||
* Superusers and managers can delete any actual.
|
||||
* Developers can only delete their own actuals.
|
||||
*/
|
||||
public function delete(User $user, Actual $actual): bool
|
||||
{
|
||||
// Superusers and managers can delete any actual
|
||||
if (in_array($user->role, ['superuser', 'manager'])) {
|
||||
return true;
|
||||
}
|
||||
|
||||
// Developers can only delete their own actuals
|
||||
if ($user->role === 'developer') {
|
||||
return $user->team_member_id === $actual->team_member_id;
|
||||
}
|
||||
|
||||
return false;
|
||||
}
|
||||
}
|
||||
@@ -69,4 +69,54 @@ class TeamMemberPolicy
|
||||
// Only superusers can force delete team members
|
||||
return $user->role === 'superuser';
|
||||
}
|
||||
|
||||
/**
|
||||
* Determine whether the user can view utilization data.
|
||||
*
|
||||
* All authenticated users can view utilization data.
|
||||
*/
|
||||
public function viewUtilization(User $user): bool
|
||||
{
|
||||
return true;
|
||||
}
|
||||
|
||||
/**
|
||||
* Determine whether the user can view running utilization.
|
||||
*/
|
||||
public function viewRunningUtilization(User $user): bool
|
||||
{
|
||||
return true;
|
||||
}
|
||||
|
||||
/**
|
||||
* Determine whether the user can view overall utilization.
|
||||
*/
|
||||
public function viewOverallUtilization(User $user): bool
|
||||
{
|
||||
return true;
|
||||
}
|
||||
|
||||
/**
|
||||
* Determine whether the user can view team utilization.
|
||||
*/
|
||||
public function viewTeamUtilization(User $user): bool
|
||||
{
|
||||
return true;
|
||||
}
|
||||
|
||||
/**
|
||||
* Determine whether the user can view team running utilization.
|
||||
*/
|
||||
public function viewTeamRunningUtilization(User $user): bool
|
||||
{
|
||||
return true;
|
||||
}
|
||||
|
||||
/**
|
||||
* Determine whether the user can view utilization trend.
|
||||
*/
|
||||
public function viewUtilizationTrend(User $user): bool
|
||||
{
|
||||
return true;
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user