@php $policy = $accessPolicyConfig ?? []; $baseRoles = $policy['base_roles'] ?? ['admin', 'manager', 'accountant', 'officer', 'applicant', 'user']; $dayLabels = $policy['day_labels'] ?? [1 => 'Mon', 2 => 'Tue', 3 => 'Wed', 4 => 'Thu', 5 => 'Fri', 6 => 'Sat', 7 => 'Sun']; $globalIps = $policy['global_ips'] ?? []; if ($globalIps === []) { $globalIps = ['']; } $roleIps = $policy['role_ips'] ?? []; foreach ($baseRoles as $roleKey) { if (! isset($roleIps[$roleKey])) { $roleIps[$roleKey] = []; } } $roleWindows = $policy['role_login_windows'] ?? []; $sensitiveRoutes = $policy['sensitive_routes'] ?? []; if ($sensitiveRoutes === []) { $sensitiveRoutes = ['']; } $policyTurboAttr = \App\Support\Navigation\WorkspaceEmbed::isEmbedded() ? ['data-turbo-frame' => $accessRolesTurboFrame ?? '_top'] : []; @endphp
Control login windows, trusted devices, and IP restrictions for sensitive loan modules. These rules apply on top of role permissions.
Session timeout
10 min inactivity · auto logout
High-risk pages
Setup, accounting, financial
IP restriction
Sensitive routes when enabled
Login windows
Per base role below
Unique credentials
No shared staff logins