2011-10-08 17:36:38 -04:00
|
|
|
class Ability
|
|
|
|
def self.allowed(object, subject)
|
|
|
|
case subject.class.name
|
|
|
|
when "Project" then project_abilities(object, subject)
|
2011-10-17 06:39:03 -04:00
|
|
|
when "Issue" then issue_abilities(object, subject)
|
|
|
|
when "Note" then note_abilities(object, subject)
|
|
|
|
when "Snippet" then snippet_abilities(object, subject)
|
2012-02-21 17:31:18 -05:00
|
|
|
when "MergeRequest" then merge_request_abilities(object, subject)
|
2011-10-08 17:36:38 -04:00
|
|
|
else []
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
def self.project_abilities(user, project)
|
|
|
|
rules = []
|
|
|
|
|
|
|
|
rules << [
|
|
|
|
:read_project,
|
2012-02-20 13:16:55 -05:00
|
|
|
:read_wiki,
|
2011-10-08 17:36:38 -04:00
|
|
|
:read_issue,
|
2012-04-08 17:28:58 -04:00
|
|
|
:read_milestone,
|
2011-10-16 17:07:10 -04:00
|
|
|
:read_snippet,
|
2011-10-08 17:36:38 -04:00
|
|
|
:read_team_member,
|
2011-11-28 02:39:43 -05:00
|
|
|
:read_merge_request,
|
2012-02-20 13:16:55 -05:00
|
|
|
:read_note,
|
2011-10-08 17:36:38 -04:00
|
|
|
:write_project,
|
|
|
|
:write_issue,
|
2012-02-20 13:16:55 -05:00
|
|
|
:write_note
|
|
|
|
] if project.guest_access_for?(user)
|
|
|
|
|
|
|
|
rules << [
|
|
|
|
:download_code,
|
2012-02-21 17:31:18 -05:00
|
|
|
:write_merge_request,
|
|
|
|
:write_snippet
|
2012-02-20 13:16:55 -05:00
|
|
|
] if project.report_access_for?(user)
|
|
|
|
|
|
|
|
rules << [
|
2012-02-19 12:47:49 -05:00
|
|
|
:write_wiki
|
2012-02-20 13:16:55 -05:00
|
|
|
] if project.dev_access_for?(user)
|
2011-10-08 17:36:38 -04:00
|
|
|
|
|
|
|
rules << [
|
2011-12-15 16:57:46 -05:00
|
|
|
:modify_issue,
|
|
|
|
:modify_snippet,
|
2012-02-21 17:31:18 -05:00
|
|
|
:modify_merge_request,
|
2011-10-08 17:36:38 -04:00
|
|
|
:admin_project,
|
|
|
|
:admin_issue,
|
2012-04-08 17:28:58 -04:00
|
|
|
:admin_milestone,
|
2011-10-16 17:07:10 -04:00
|
|
|
:admin_snippet,
|
2011-10-08 17:36:38 -04:00
|
|
|
:admin_team_member,
|
2011-11-28 02:39:43 -05:00
|
|
|
:admin_merge_request,
|
2012-02-20 13:16:55 -05:00
|
|
|
:admin_note,
|
|
|
|
:admin_wiki
|
2012-02-21 17:31:18 -05:00
|
|
|
] if project.master_access_for?(user) || project.owner == user
|
2011-10-08 17:36:38 -04:00
|
|
|
|
2012-02-07 18:00:49 -05:00
|
|
|
|
2011-10-08 17:36:38 -04:00
|
|
|
rules.flatten
|
|
|
|
end
|
2011-10-17 06:39:03 -04:00
|
|
|
|
2011-10-26 09:46:25 -04:00
|
|
|
class << self
|
2012-02-20 13:16:55 -05:00
|
|
|
[:issue, :note, :snippet, :merge_request].each do |name|
|
2011-10-17 06:39:03 -04:00
|
|
|
define_method "#{name}_abilities" do |user, subject|
|
|
|
|
if subject.author == user
|
|
|
|
[
|
|
|
|
:"read_#{name}",
|
|
|
|
:"write_#{name}",
|
2011-12-15 16:57:46 -05:00
|
|
|
:"modify_#{name}",
|
2011-10-17 06:39:03 -04:00
|
|
|
:"admin_#{name}"
|
|
|
|
]
|
2012-02-21 17:31:18 -05:00
|
|
|
elsif subject.respond_to?(:assignee) && subject.assignee == user
|
|
|
|
[
|
|
|
|
:"read_#{name}",
|
|
|
|
:"write_#{name}",
|
|
|
|
:"modify_#{name}",
|
|
|
|
]
|
2011-10-17 06:39:03 -04:00
|
|
|
else
|
2011-10-26 09:46:25 -04:00
|
|
|
subject.respond_to?(:project) ?
|
2011-10-17 06:39:03 -04:00
|
|
|
project_abilities(user, subject.project) : []
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
2011-10-08 17:36:38 -04:00
|
|
|
end
|