Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Restricting access to thread participants only. #371

ronlinet started this conversation in Ideas
Discussion options

Thank you for the demo guys.
I am reusing it now in my project and I have noticed that the thread page doesn’t check if the user is a participant or not.

Adding below snippet to MessagesController.php#L60 will redirect "non participants" back to the listing page with an error message.

$participant = Participant::where(['user_id' => Auth::id(), 'thread_id' => $id ]);
if( is_null($participant->first())) {
 \Session::flash('error_message', 'Only For Participants');
 return redirect()->back();
}
You must be logged in to vote

Replies: 1 comment

Comment options

hey @ronlinet, thanks for the discussion thread and using the package!

Correct, we handle the basics in the package. It's up to the application code to determine authorization for gaining access to message/thread features.

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Ideas
Labels
None yet
2 participants

AltStyle によって変換されたページ (->オリジナル) /