<?php

/*
 * This file is part of the Symfony package.
 *
 * (c) Fabien Potencier <fabien@symfony.com>
 *
 * For the full copyright and license information, please view the LICENSE
 * file that was distributed with this source code.
 */

namespace Symfony\Component\Security\Core\Authorization\Voter;

use Symfony\Component\Security\Core\Authentication\Token\TokenInterface;
use Symfony\Component\Security\Core\Role\RoleHierarchyInterface;

/**
 * RoleHierarchyVoter uses a RoleHierarchy to determine the roles granted to
 * the user before voting.
 *
 * @author Fabien Potencier <fabien@symfony.com>
 */
class RoleHierarchyVoter extends RoleVoter
{
    public function __construct(
        private RoleHierarchyInterface $roleHierarchy,
        string $prefix = 'ROLE_',
    ) {
        parent::__construct($prefix);
    }

    protected function extractRoles(TokenInterface $token): array
    {
        return $this->roleHierarchy->getReachableRoleNames($token->getRoleNames());
    }
}
