gitlabhq/app/models/ability.rb

80 lines
1.9 KiB
Ruby
Raw Normal View History

2011-10-09 00:36:38 +03:00
class Ability
def self.allowed(object, subject)
case subject.class.name
when "Project" then project_abilities(object, subject)
2011-10-17 13:39:03 +03:00
when "Issue" then issue_abilities(object, subject)
when "Note" then note_abilities(object, subject)
when "Snippet" then snippet_abilities(object, subject)
when "MergeRequest" then merge_request_abilities(object, subject)
2011-10-09 00:36:38 +03:00
else []
end
end
def self.project_abilities(user, project)
rules = []
rules << [
:read_project,
2012-02-20 21:16:55 +03:00
:read_wiki,
2011-10-09 00:36:38 +03:00
:read_issue,
2011-10-17 00:07:10 +03:00
:read_snippet,
2011-10-09 00:36:38 +03:00
:read_team_member,
2011-11-28 09:39:43 +02:00
:read_merge_request,
2012-02-20 21:16:55 +03:00
:read_note,
2011-10-09 00:36:38 +03:00
:write_project,
:write_issue,
2012-02-20 21:16:55 +03:00
:write_note
] if project.guest_access_for?(user)
rules << [
:download_code,
:write_merge_request,
:write_snippet
2012-02-20 21:16:55 +03:00
] if project.report_access_for?(user)
rules << [
2012-02-19 19:47:49 +02:00
:write_wiki
2012-02-20 21:16:55 +03:00
] if project.dev_access_for?(user)
2011-10-09 00:36:38 +03:00
rules << [
2011-12-15 23:57:46 +02:00
:modify_issue,
:modify_snippet,
:modify_merge_request,
2011-10-09 00:36:38 +03:00
:admin_project,
:admin_issue,
2011-10-17 00:07:10 +03:00
:admin_snippet,
2011-10-09 00:36:38 +03:00
:admin_team_member,
2011-11-28 09:39:43 +02:00
:admin_merge_request,
2012-02-20 21:16:55 +03:00
:admin_note,
:admin_wiki
] if project.master_access_for?(user) || project.owner == user
2011-10-09 00:36:38 +03:00
2011-10-09 00:36:38 +03:00
rules.flatten
end
2011-10-17 13:39:03 +03:00
class << self
2012-02-20 21:16:55 +03:00
[:issue, :note, :snippet, :merge_request].each do |name|
2011-10-17 13:39:03 +03:00
define_method "#{name}_abilities" do |user, subject|
if subject.author == user
[
:"read_#{name}",
:"write_#{name}",
2011-12-15 23:57:46 +02:00
:"modify_#{name}",
2011-10-17 13:39:03 +03:00
:"admin_#{name}"
]
elsif subject.respond_to?(:assignee) && subject.assignee == user
[
:"read_#{name}",
:"write_#{name}",
:"modify_#{name}",
]
2011-10-17 13:39:03 +03:00
else
subject.respond_to?(:project) ?
2011-10-17 13:39:03 +03:00
project_abilities(user, subject.project) : []
end
end
end
end
2011-10-09 00:36:38 +03:00
end