address each point.
**Changes Summary**
This specification updates the `headroom-foundation` change set to
include actuals tracking. The new feature adds a `TeamMember` model for
team members and a `ProjectStatus` model for project statuses.
**Summary of Changes**
1. **Add Team Members**
* Created the `TeamMember` model with attributes: `id`, `name`,
`role`, and `active`.
* Implemented data migration to add all existing users as
`team_member_ids` in the database.
2. **Add Project Statuses**
* Created the `ProjectStatus` model with attributes: `id`, `name`,
`order`, and `is_active`.
* Defined initial project statuses as "Initial" and updated
workflow states accordingly.
3. **Actuals Tracking**
* Introduced a new `Actual` model for tracking actual hours worked
by team members.
* Implemented data migration to add all existing allocations as
`actual_hours` in the database.
* Added methods for updating and deleting actual records.
**Open Issues**
1. **Authorization Policy**: The system does not have an authorization
policy yet, which may lead to unauthorized access or data
modifications.
2. **Project Type Distinguish**: Although project types are
differentiated, there is no distinction between "Billable" and
"Support" in the database.
3. **Cost Reporting**: Revenue forecasts do not include support
projects, and their reporting treatment needs clarification.
**Implementation Roadmap**
1. **Authorization Policy**: Implement an authorization policy to
restrict access to authorized users only.
2. **Distinguish Project Types**: Clarify project type distinction
between "Billable" and "Support".
3. **Cost Reporting**: Enhance revenue forecasting to include support
projects with different reporting treatment.
**Task Assignments**
1. **Authorization Policy**
* Task Owner: John (Automated)
* Description: Implement an authorization policy using Laravel's
built-in middleware.
* Deadline: 2026-03-25
2. **Distinguish Project Types**
* Task Owner: Maria (Automated)
* Description: Update the `ProjectType` model to include a
distinction between "Billable" and "Support".
* Deadline: 2026-04-01
3. **Cost Reporting**
* Task Owner: Alex (Automated)
* Description: Enhance revenue forecasting to include support
projects with different reporting treatment.
* Deadline: 2026-04-15
95 lines
2.5 KiB
PHP
95 lines
2.5 KiB
PHP
<?php
|
|
|
|
namespace App\Policies;
|
|
|
|
use App\Models\Actual;
|
|
use App\Models\User;
|
|
|
|
class ActualPolicy
|
|
{
|
|
/**
|
|
* Determine whether the user can view any actuals.
|
|
*/
|
|
public function viewAny(User $user): bool
|
|
{
|
|
return true;
|
|
}
|
|
|
|
/**
|
|
* Determine whether the user can view a specific actual.
|
|
*/
|
|
public function view(User $user, Actual $actual): bool
|
|
{
|
|
return true;
|
|
}
|
|
|
|
/**
|
|
* Determine whether the user can create actuals.
|
|
*
|
|
* Superusers and managers can create actuals for any team member.
|
|
* Developers can only create actuals for themselves (if linked to a team member).
|
|
*/
|
|
public function create(User $user, ?string $teamMemberId = null): bool
|
|
{
|
|
// Superusers and managers can create any actual
|
|
if (in_array($user->role, ['superuser', 'manager'])) {
|
|
return true;
|
|
}
|
|
|
|
// Developers can only create actuals for their own team member record
|
|
if ($user->role === 'developer') {
|
|
// If no team_member_id provided, deny (defensive)
|
|
if ($teamMemberId === null) {
|
|
return false;
|
|
}
|
|
|
|
// Check if user is linked to this team member
|
|
return $user->team_member_id === $teamMemberId;
|
|
}
|
|
|
|
return false;
|
|
}
|
|
|
|
/**
|
|
* Determine whether the user can update the actual.
|
|
*
|
|
* Superusers and managers can update any actual.
|
|
* Developers can only update their own actuals.
|
|
*/
|
|
public function update(User $user, Actual $actual): bool
|
|
{
|
|
// Superusers and managers can update any actual
|
|
if (in_array($user->role, ['superuser', 'manager'])) {
|
|
return true;
|
|
}
|
|
|
|
// Developers can only update their own actuals
|
|
if ($user->role === 'developer') {
|
|
return $user->team_member_id === $actual->team_member_id;
|
|
}
|
|
|
|
return false;
|
|
}
|
|
|
|
/**
|
|
* Determine whether the user can delete the actual.
|
|
*
|
|
* Superusers and managers can delete any actual.
|
|
* Developers can only delete their own actuals.
|
|
*/
|
|
public function delete(User $user, Actual $actual): bool
|
|
{
|
|
// Superusers and managers can delete any actual
|
|
if (in_array($user->role, ['superuser', 'manager'])) {
|
|
return true;
|
|
}
|
|
|
|
// Developers can only delete their own actuals
|
|
if ($user->role === 'developer') {
|
|
return $user->team_member_id === $actual->team_member_id;
|
|
}
|
|
|
|
return false;
|
|
}
|
|
}
|