Skip to content

Use policy for viewing form entries when app registers one - #63

Merged
scottgrayson merged 1 commit into
4.xfrom
form-submission-file-downloads
Mar 3, 2026
Merged

scottgrayson merged 1 commit into
4.xfrom
form-submission-file-downloads

Conversation

@scottgrayson

Copy link
Copy Markdown
Contributor

Summary

When the consuming app registers a policy for FilamentFormUser with a view() method, ShowEntry uses $user->can('view', $entry) instead of only allowing the submitter. Falls back to submitter-only when no policy is present.

Behavior

  • Guest entries (user_id null): still require valid signed URL.
  • Authenticated entries: If policy($entry) has view method → use that; else only allow owner.

Allows apps to grant e.g. admins permission to view any form entry via FilamentFormUserPolicy::view().

Made with Cursor

When the app registers a policy for FilamentFormUser with a view() method,
use $user->can('view', $entry) instead of only allowing the submitter.
Falls back to submitter-only when no policy is present.

Made-with: Cursor
@scottgrayson
scottgrayson merged commit 284f985 into 4.x Mar 3, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant