. */ declare(strict_types=1); namespace App\Security\Voter; use App\Entity\LogSystem\AbstractLogEntry; use App\Entity\UserSystem\User; class LogEntryVoter extends ExtendedVoter { public const ALLOWED_OPS = ['read', 'delete']; protected function voteOnUser(string $attribute, $subject, User $user): bool { if ('delete' === $attribute) { return $this->resolver->inherit($user, 'system', 'delete_logs') ?? false; } if ('read' === $attribute) { //Allow read of the users own log entries if ( $subject->getUser() === $user && $this->resolver->inherit($user, 'self', 'show_logs') ) { return true; } return $this->resolver->inherit($user, 'system', 'show_logs') ?? false; } return false; } protected function supports($attribute, $subject): bool { if ($subject instanceof AbstractLogEntry) { return in_array($subject, static::ALLOWED_OPS, true); } return false; } }