Implement global permissions for customer actions and update views to check permissions before rendering buttons

This commit is contained in:
ricky committed 2026-09-08 22:35:52 -04:00
1 parent fd91bd6fa2
commit bab019a152
5 files changed
+14 -4

No files matched your search

+2
View File
@@ -25,6 +25,8 @@ class CustomersController < ApplicationController
include SortHelper include SortHelper
helper :timelog helper :timelog
# This tells Redmine to check global permissions for the current controller/action
before_action :authorize_global
before_action :add_customer, only: [:new, :create] before_action :add_customer, only: [:new, :create]
before_action :view_customer, except: [:new, :create, :view] before_action :view_customer, except: [:new, :create, :view]
skip_before_action :verify_authenticity_token, :check_if_login_required, only: [:view] skip_before_action :verify_authenticity_token, :check_if_login_required, only: [:view]
+2
View File
@@ -14,7 +14,9 @@
<%= call_hook :customer_actions_bottom, { customer: @customer } %> <%= call_hook :customer_actions_bottom, { customer: @customer } %>
<% if User.current.allowed_to?(:edit_customers, nil, global: true) %>
<%= button_to t(:label_edit_customer), edit_customer_path(@customer), method: :get%> <%= button_to t(:label_edit_customer), edit_customer_path(@customer), method: :get%>
<% end %>
<script> <script>
function handleSingleSelect(event, className) { function handleSingleSelect(event, className) {
+2
View File
@@ -2,5 +2,7 @@
<%= text_field_tag :search, params[:search], class: "customer-name", placeholder: t(:label_search_customers), autocomplete: "off", data: { autocomplete_url: "/customers/autocomplete" } %> <%= text_field_tag :search, params[:search], class: "customer-name", placeholder: t(:label_search_customers), autocomplete: "off", data: { autocomplete_url: "/customers/autocomplete" } %>
<%= submit_tag t(:label_search) %> <%= submit_tag t(:label_search) %>
<% end %> <% end %>
<% if User.current.allowed_to?(:add_customers, nil, global: true) %>
<%= button_to t(:label_new_customer), new_customer_path, method: :get%> <%= button_to t(:label_new_customer), new_customer_path, method: :get%>
<% end %>
<%= button_to(t(:label_sync), qbo_sync_path, method: :get) if User.current.admin?%> <%= button_to(t(:label_sync), qbo_sync_path, method: :get) if User.current.admin?%>
+3
View File
@@ -1,6 +1,9 @@
<% if User.current.logged? %> <% if User.current.logged? %>
<% if User.current.allowed_to?(:view_customers, nil, global: true) %>
<%= render partial: 'customers/sidebar' %> <%= render partial: 'customers/sidebar' %>
<% end %>
<%= render partial: 'estimates/sidebar' %> <%= render partial: 'estimates/sidebar' %>
<% end %> <% end %>
+5 -4
View File
@@ -30,12 +30,13 @@ Redmine::Plugin.register :redmine_qbo do
# set per_page globally # set per_page globally
WillPaginate.per_page = 20 WillPaginate.per_page = 20
# Permissions for security # Global Permissions
permission :view_customers, customers: :index, public: false permission :view_customers, { customers: [:index, :show] }, global: true
permission :add_customers, customers: :new, public: false permission :add_customers, { customers: [:new, :create] }, global: true
permission :edit_customers, { customers: [:edit, :update] }, global: true
# Register top menu items # Register top menu items
menu :top_menu, :customers, { controller: :customers, action: :index }, caption: :label_customers, if: Proc.new {User.current.logged?} menu :top_menu, :customers, { controller: :customers, action: :index }, caption: :label_customers, if: Proc.new {User.current.allowed_to?(:view_customers, nil, global: true)}
Redmine::Search.map do |search| Redmine::Search.map do |search|
search.register :customers search.register :customers