Implement global permissions for customer actions and update views to check permissions before rendering buttons

This commit is contained in:
ricky committed 2026-09-08 22:35:52 -04:00
1 parent fd91bd6fa2
commit bab019a152
5 files changed
+17 -7

No files matched your search

+3 -1
View File
@@ -14,7 +14,9 @@
<%= call_hook :customer_actions_bottom, { customer: @customer } %>
<%= button_to t(:label_edit_customer), edit_customer_path(@customer), method: :get%>
<% if User.current.allowed_to?(:edit_customers, nil, global: true) %>
<%= button_to t(:label_edit_customer), edit_customer_path(@customer), method: :get%>
<% end %>
<script>
function handleSingleSelect(event, className) {
+3 -1
View File
@@ -2,5 +2,7 @@
<%= text_field_tag :search, params[:search], class: "customer-name", placeholder: t(:label_search_customers), autocomplete: "off", data: { autocomplete_url: "/customers/autocomplete" } %>
<%= submit_tag t(:label_search) %>
<% end %>
<%= button_to t(:label_new_customer), new_customer_path, method: :get%>
<% if User.current.allowed_to?(:add_customers, nil, global: true) %>
<%= button_to t(:label_new_customer), new_customer_path, method: :get%>
<% end %>
<%= button_to(t(:label_sync), qbo_sync_path, method: :get) if User.current.admin?%>