Implement global permissions for customer actions and update views to check permissions before rendering buttons

This commit is contained in:
ricky committed 2026-09-08 22:35:52 -04:00
1 parent fd91bd6fa2
commit bab019a152
5 files changed
+17 -7

No files matched your search

+2
View File
@@ -25,6 +25,8 @@ class CustomersController < ApplicationController
include SortHelper
helper :timelog
# This tells Redmine to check global permissions for the current controller/action
before_action :authorize_global
before_action :add_customer, only: [:new, :create]
before_action :view_customer, except: [:new, :create, :view]
skip_before_action :verify_authenticity_token, :check_if_login_required, only: [:view]