2018-07-24 06:00:56 -04:00
|
|
|
# frozen_string_literal: true
|
|
|
|
|
2016-08-16 19:29:19 -04:00
|
|
|
class GlobalPolicy < BasePolicy
|
2017-04-06 17:06:42 -04:00
|
|
|
desc "User is an internal user"
|
|
|
|
with_options scope: :user, score: 0
|
2018-05-09 06:55:31 -04:00
|
|
|
condition(:internal) { @user&.internal? }
|
2016-08-30 14:14:07 -04:00
|
|
|
|
2017-04-06 17:06:42 -04:00
|
|
|
desc "User's access has been locked"
|
|
|
|
with_options scope: :user, score: 0
|
2018-05-09 06:55:31 -04:00
|
|
|
condition(:access_locked) { @user&.access_locked? }
|
2017-02-28 16:09:23 -05:00
|
|
|
|
2018-05-09 06:55:31 -04:00
|
|
|
condition(:can_create_fork, scope: :user) { @user && @user.manageable_namespaces.any? { |namespace| @user.can?(:create_projects, namespace) } }
|
2017-09-29 07:14:39 -04:00
|
|
|
|
2018-05-08 09:07:55 -04:00
|
|
|
condition(:required_terms_not_accepted, scope: :user, score: 0) do
|
|
|
|
@user&.required_terms_not_accepted?
|
|
|
|
end
|
|
|
|
|
2021-06-01 17:10:06 -04:00
|
|
|
condition(:password_expired, scope: :user) do
|
2021-06-16 14:10:35 -04:00
|
|
|
@user&.password_expired_if_applicable?
|
2021-06-01 17:10:06 -04:00
|
|
|
end
|
|
|
|
|
2020-04-21 11:21:10 -04:00
|
|
|
condition(:project_bot, scope: :user) { @user&.project_bot? }
|
2020-05-04 17:09:41 -04:00
|
|
|
condition(:migration_bot, scope: :user) { @user&.migration_bot? }
|
2020-04-21 11:21:10 -04:00
|
|
|
|
2017-06-30 09:29:34 -04:00
|
|
|
rule { anonymous }.policy do
|
|
|
|
prevent :log_in
|
|
|
|
prevent :receive_notifications
|
|
|
|
prevent :use_quick_actions
|
|
|
|
prevent :create_group
|
2021-04-28 11:09:35 -04:00
|
|
|
prevent :execute_graphql_mutation
|
2017-06-30 09:29:34 -04:00
|
|
|
end
|
2017-04-06 17:06:42 -04:00
|
|
|
|
|
|
|
rule { default }.policy do
|
|
|
|
enable :log_in
|
|
|
|
enable :access_api
|
|
|
|
enable :access_git
|
|
|
|
enable :receive_notifications
|
|
|
|
enable :use_quick_actions
|
2019-07-04 06:31:44 -04:00
|
|
|
enable :use_slash_commands
|
2021-04-28 11:09:35 -04:00
|
|
|
enable :execute_graphql_mutation
|
2017-04-06 17:06:42 -04:00
|
|
|
end
|
|
|
|
|
2020-01-30 16:08:47 -05:00
|
|
|
rule { inactive }.policy do
|
|
|
|
prevent :log_in
|
|
|
|
prevent :access_api
|
|
|
|
prevent :access_git
|
|
|
|
prevent :use_slash_commands
|
|
|
|
end
|
|
|
|
|
2017-04-06 17:06:42 -04:00
|
|
|
rule { blocked | internal }.policy do
|
|
|
|
prevent :log_in
|
|
|
|
prevent :access_api
|
|
|
|
prevent :receive_notifications
|
2019-07-04 06:31:44 -04:00
|
|
|
prevent :use_slash_commands
|
2017-04-06 17:06:42 -04:00
|
|
|
end
|
|
|
|
|
2021-04-28 11:09:35 -04:00
|
|
|
rule { ~can?(:access_api) }.prevent :execute_graphql_mutation
|
|
|
|
|
2020-12-11 13:09:57 -05:00
|
|
|
rule { blocked | (internal & ~migration_bot & ~security_bot) }.policy do
|
2020-05-04 17:09:41 -04:00
|
|
|
prevent :access_git
|
|
|
|
end
|
|
|
|
|
2020-04-21 11:21:10 -04:00
|
|
|
rule { project_bot }.policy do
|
|
|
|
prevent :log_in
|
|
|
|
prevent :receive_notifications
|
|
|
|
end
|
|
|
|
|
2019-10-09 20:06:44 -04:00
|
|
|
rule { deactivated }.policy do
|
|
|
|
prevent :access_git
|
|
|
|
prevent :access_api
|
|
|
|
prevent :receive_notifications
|
2019-10-10 20:06:24 -04:00
|
|
|
prevent :use_slash_commands
|
2019-10-09 20:06:44 -04:00
|
|
|
end
|
|
|
|
|
2018-05-08 09:07:55 -04:00
|
|
|
rule { required_terms_not_accepted }.policy do
|
|
|
|
prevent :access_api
|
|
|
|
prevent :access_git
|
|
|
|
end
|
|
|
|
|
2021-06-01 17:10:06 -04:00
|
|
|
rule { password_expired }.policy do
|
|
|
|
prevent :access_api
|
|
|
|
prevent :access_git
|
|
|
|
prevent :use_slash_commands
|
|
|
|
end
|
|
|
|
|
2017-04-06 17:06:42 -04:00
|
|
|
rule { can_create_group }.policy do
|
|
|
|
enable :create_group
|
|
|
|
end
|
|
|
|
|
2020-04-24 05:09:44 -04:00
|
|
|
rule { can?(:create_group) }.policy do
|
|
|
|
enable :create_group_with_default_branch_protection
|
|
|
|
end
|
|
|
|
|
2017-09-29 07:14:39 -04:00
|
|
|
rule { can_create_fork }.policy do
|
|
|
|
enable :create_fork
|
|
|
|
end
|
|
|
|
|
2017-04-06 17:06:42 -04:00
|
|
|
rule { access_locked }.policy do
|
|
|
|
prevent :log_in
|
2019-07-04 06:31:44 -04:00
|
|
|
prevent :use_slash_commands
|
2016-08-16 19:29:19 -04:00
|
|
|
end
|
2017-06-30 09:29:34 -04:00
|
|
|
|
2017-08-01 03:46:13 -04:00
|
|
|
rule { ~(anonymous & restricted_public_level) }.policy do
|
2017-06-30 09:29:34 -04:00
|
|
|
enable :read_users_list
|
2016-08-16 19:29:19 -04:00
|
|
|
end
|
2017-09-28 12:49:42 -04:00
|
|
|
|
2019-01-24 11:23:57 -05:00
|
|
|
rule { ~anonymous }.policy do
|
|
|
|
enable :read_instance_metadata
|
2020-01-23 07:08:38 -05:00
|
|
|
enable :create_snippet
|
2019-01-24 11:23:57 -05:00
|
|
|
end
|
|
|
|
|
2017-09-28 12:49:42 -04:00
|
|
|
rule { admin }.policy do
|
|
|
|
enable :read_custom_attribute
|
|
|
|
enable :update_custom_attribute
|
2020-10-15 08:09:06 -04:00
|
|
|
enable :approve_user
|
2020-12-02 19:09:53 -05:00
|
|
|
enable :reject_user
|
2021-02-18 10:09:43 -05:00
|
|
|
enable :read_usage_trends_measurement
|
2021-06-14 11:09:48 -04:00
|
|
|
enable :update_runners_registration_token
|
2017-09-28 12:49:42 -04:00
|
|
|
end
|
2019-11-29 16:06:13 -05:00
|
|
|
|
2020-06-19 17:08:32 -04:00
|
|
|
# We can't use `read_statistics` because the user may have different permissions for different projects
|
|
|
|
rule { admin }.enable :use_project_statistics_filters
|
|
|
|
|
2020-01-23 07:08:38 -05:00
|
|
|
rule { external_user }.prevent :create_snippet
|
2016-08-16 19:29:19 -04:00
|
|
|
end
|
2019-09-13 09:26:31 -04:00
|
|
|
|
2021-05-11 17:10:21 -04:00
|
|
|
GlobalPolicy.prepend_mod_with('GlobalPolicy')
|