2018-07-24 10:00:56 +00:00
|
|
|
# frozen_string_literal: true
|
|
|
|
|
2016-08-16 20:08:14 +00:00
|
|
|
class NotePolicy < BasePolicy
|
2020-02-24 03:09:05 +00:00
|
|
|
delegate { @subject.resource_parent }
|
2018-04-06 18:19:37 +00:00
|
|
|
delegate { @subject.noteable if DeclarativePolicy.has_policy?(@subject.noteable) }
|
2016-08-16 20:08:14 +00:00
|
|
|
|
2017-04-06 21:06:42 +00:00
|
|
|
condition(:is_author) { @user && @subject.author == @user }
|
|
|
|
condition(:is_noteable_author) { @user && @subject.noteable.author_id == @user.id }
|
2016-08-16 20:08:14 +00:00
|
|
|
|
2017-04-06 21:06:42 +00:00
|
|
|
condition(:editable, scope: :subject) { @subject.editable? }
|
2016-08-16 20:08:14 +00:00
|
|
|
|
2019-10-17 03:55:04 +00:00
|
|
|
condition(:can_read_noteable) { can?(:"read_#{@subject.noteable_ability_name}") }
|
2018-11-28 19:04:15 +00:00
|
|
|
|
2020-02-24 03:09:05 +00:00
|
|
|
condition(:is_visible) { @subject.system_note_with_references_visible_for?(@user) }
|
2019-09-18 08:26:20 +00:00
|
|
|
|
2018-04-02 17:05:47 +00:00
|
|
|
rule { ~editable }.prevent :admin_note
|
2017-04-06 21:06:42 +00:00
|
|
|
|
2018-11-28 19:04:15 +00:00
|
|
|
# If user can't read the issue/MR/etc then they should not be allowed to do anything to their own notes
|
|
|
|
rule { ~can_read_noteable }.policy do
|
|
|
|
prevent :read_note
|
|
|
|
prevent :admin_note
|
|
|
|
prevent :resolve_note
|
2019-01-15 08:21:28 +00:00
|
|
|
prevent :award_emoji
|
2018-11-28 19:04:15 +00:00
|
|
|
end
|
|
|
|
|
2017-04-06 21:06:42 +00:00
|
|
|
rule { is_author }.policy do
|
|
|
|
enable :read_note
|
|
|
|
enable :admin_note
|
|
|
|
enable :resolve_note
|
|
|
|
end
|
|
|
|
|
2019-09-18 08:26:20 +00:00
|
|
|
rule { ~is_visible }.policy do
|
|
|
|
prevent :read_note
|
|
|
|
prevent :admin_note
|
|
|
|
prevent :resolve_note
|
|
|
|
prevent :award_emoji
|
|
|
|
end
|
|
|
|
|
2018-04-02 18:38:47 +00:00
|
|
|
rule { is_noteable_author }.policy do
|
2017-04-06 21:06:42 +00:00
|
|
|
enable :resolve_note
|
2016-08-16 20:08:14 +00:00
|
|
|
end
|
|
|
|
end
|