From 8e5fba6943124bad7c884a11fa30a03a684d0017 Mon Sep 17 00:00:00 2001 From: David Bomba Date: Thu, 10 Aug 2023 19:53:35 +1000 Subject: [PATCH] Updates for low permission users attempting to generate reports --- app/Http/Requests/Report/GenericReportRequest.php | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/app/Http/Requests/Report/GenericReportRequest.php b/app/Http/Requests/Report/GenericReportRequest.php index d18bb516c233..4f941b5802ad 100644 --- a/app/Http/Requests/Report/GenericReportRequest.php +++ b/app/Http/Requests/Report/GenericReportRequest.php @@ -22,7 +22,11 @@ class GenericReportRequest extends Request */ public function authorize() : bool { - return auth()->user()->isAdmin(); + /** @var \App\Models\User $user */ + $user = auth()->user(); + + return $user->isAdmin() || $user->hasPermission('view_reports'); + } public function rules()