From bab019a152d3b15c3a0e80a5c9cd9b7223272593 Mon Sep 17 00:00:00 2001 From: Rick Barrette Date: Tue, 8 Sep 2026 22:35:52 -0400 Subject: [PATCH] Implement global permissions for customer actions and update views to check permissions before rendering buttons --- app/controllers/customers_controller.rb | 2 ++ app/views/customers/_actions.html.erb | 4 +++- app/views/customers/_search.html.erb | 4 +++- app/views/qbo/_sidebar.html.erb | 5 ++++- init.rb | 9 +++++---- 5 files changed, 17 insertions(+), 7 deletions(-) diff --git a/app/controllers/customers_controller.rb b/app/controllers/customers_controller.rb index 8553000..7cf78e8 100644 --- a/app/controllers/customers_controller.rb +++ b/app/controllers/customers_controller.rb @@ -25,6 +25,8 @@ class CustomersController < ApplicationController include SortHelper helper :timelog + # This tells Redmine to check global permissions for the current controller/action + before_action :authorize_global before_action :add_customer, only: [:new, :create] before_action :view_customer, except: [:new, :create, :view] skip_before_action :verify_authenticity_token, :check_if_login_required, only: [:view] diff --git a/app/views/customers/_actions.html.erb b/app/views/customers/_actions.html.erb index 57f86a9..8da3454 100644 --- a/app/views/customers/_actions.html.erb +++ b/app/views/customers/_actions.html.erb @@ -14,7 +14,9 @@ <%= call_hook :customer_actions_bottom, { customer: @customer } %> -<%= button_to t(:label_edit_customer), edit_customer_path(@customer), method: :get%> +<% if User.current.allowed_to?(:edit_customers, nil, global: true) %> + <%= button_to t(:label_edit_customer), edit_customer_path(@customer), method: :get%> +<% end %>