diff --git a/app/controllers/customers_controller.rb b/app/controllers/customers_controller.rb index 8553000..7cf78e8 100644 --- a/app/controllers/customers_controller.rb +++ b/app/controllers/customers_controller.rb @@ -25,6 +25,8 @@ class CustomersController < ApplicationController include SortHelper helper :timelog + # This tells Redmine to check global permissions for the current controller/action + before_action :authorize_global before_action :add_customer, only: [:new, :create] before_action :view_customer, except: [:new, :create, :view] skip_before_action :verify_authenticity_token, :check_if_login_required, only: [:view] diff --git a/app/views/customers/_actions.html.erb b/app/views/customers/_actions.html.erb index 57f86a9..8da3454 100644 --- a/app/views/customers/_actions.html.erb +++ b/app/views/customers/_actions.html.erb @@ -14,7 +14,9 @@ <%= call_hook :customer_actions_bottom, { customer: @customer } %> -<%= button_to t(:label_edit_customer), edit_customer_path(@customer), method: :get%> +<% if User.current.allowed_to?(:edit_customers, nil, global: true) %> + <%= button_to t(:label_edit_customer), edit_customer_path(@customer), method: :get%> +<% end %>