diff --git a/app/controllers/customer_appointments_controller.rb b/app/controllers/customer_appointments_controller.rb
index c513d91..8c8aa88 100644
--- a/app/controllers/customer_appointments_controller.rb
+++ b/app/controllers/customer_appointments_controller.rb
@@ -12,7 +12,8 @@ class CustomerAppointmentsController < ApplicationController
before_action :require_login
before_action :find_project, except: [:index]
before_action :find_appointment, only: [ :show, :edit, :update, :destroy ]
- #before_action :authorize
+ # This tells Redmine to check global permissions for the current controller/action
+ before_action :authorize_global
helper :projects
diff --git a/app/views/common/_calendar.html.erb b/app/views/common/_calendar.html.erb
index 3fa900c..453b01f 100644
--- a/app/views/common/_calendar.html.erb
+++ b/app/views/common/_calendar.html.erb
@@ -197,15 +197,17 @@
-
- <%# Only show ADD button if it's in the future, NOT a weekend, and NOT a custom holiday %>
- <% if day >= User.current.today && !is_standard_weekend && !is_custom_holiday %>
- <%= link_to sprite_icon('add'),
- new_customer_appointment_path(start_date: day),
- class: 'icon-only icon-add',
- title: l(:label_appointment_new, default: 'New Appointment') %>
- <% end %>
-
+ <% if User.current.allowed_to?(:add_customer_appointments, nil, global: true) %>
+
+ <%# Only show ADD button if it's in the future, NOT a weekend, NOT a holiday, AND user has permission %>
+ <% if day >= User.current.today && !is_standard_weekend && !is_custom_holiday && User.current.allowed_to?(:add_customer_appointments, nil, global: true) %>
+ <%= link_to sprite_icon('add'),
+ new_customer_appointment_path(start_date: day),
+ class: 'icon-only icon-add',
+ title: l(:label_appointment_new, default: 'New Appointment') %>
+ <% end %>
+
+ <% end %>
diff --git a/app/views/customer_appointments/_customer_actions.html.erb b/app/views/customer_appointments/_customer_actions.html.erb
index a7d8b26..d0f5305 100644
--- a/app/views/customer_appointments/_customer_actions.html.erb
+++ b/app/views/customer_appointments/_customer_actions.html.erb
@@ -1,4 +1,6 @@
-
-<% customer = context[:customer] %>
-<%= link_to l(:label_add_appointment), new_customer_appointment_path(customer_id: customer.id), target: :_blank, id: :appointment_link %>
-
+ <% customer = context[:customer] %>
+ <%= link_to l(:label_add_appointment), new_customer_appointment_path(customer_id: customer.id), target: :_blank, id: :appointment_link %>
+
-
\ No newline at end of file
+<% if User.current.allowed_to?(:edit_customer_appointments, nil, global: true) %>
+
+<% end %>
\ No newline at end of file
diff --git a/app/views/customer_appointments/index.html.erb b/app/views/customer_appointments/index.html.erb
index 733dffd..a6eebde 100644
--- a/app/views/customer_appointments/index.html.erb
+++ b/app/views/customer_appointments/index.html.erb
@@ -5,8 +5,10 @@
<%= l(:button_calendar) %>
<% end %>
- <%= link_to new_customer_appointment_path do %>
- <%= l(:button_add) %>
+ <% if User.current.allowed_to?(:add_customer_appointments, nil, global: true) %>
+ <%= link_to new_customer_appointment_path do %>
+ <%= l(:button_add) %>
+ <% end %>
<% end %>
diff --git a/app/views/customer_appointments/show.html.erb b/app/views/customer_appointments/show.html.erb
index 6ad3250..258a388 100644
--- a/app/views/customer_appointments/show.html.erb
+++ b/app/views/customer_appointments/show.html.erb
@@ -3,16 +3,22 @@
<%= l(:button_calendar) %>
<% end %>
- <%= link_to new_issue_path(issue: { customer_id: @appointment.customer_id, vehicle_id: @appointment.vehicle_id, estimate_id: @appointment.estimate_id }), target: :_blank do %>
- <%= l(:label_new_issue) %>
+ <% if User.current.allowed_to?(:add_customer_appointments, nil, global: true) %>
+ <%= link_to new_issue_path(issue: { customer_id: @appointment.customer_id, vehicle_id: @appointment.vehicle_id, estimate_id: @appointment.estimate_id }), target: :_blank do %>
+ <%= l(:label_new_issue) %>
+ <% end %>
<% end %>
- <%= link_to edit_customer_appointment_path(@appointment) do %>
- <%= l(:button_edit) %>
+ <% if User.current.allowed_to?(:edit_customer_appointments, nil, global: true) %>
+ <%= link_to edit_customer_appointment_path(@appointment) do %>
+ <%= l(:button_edit) %>
+ <% end %>
<% end %>
- <%= link_to customer_appointment_path(@appointment), method: :delete, data: { confirm: l(:text_are_you_sure) } do %>
- <%= l(:button_delete) %>
+ <% if User.current.allowed_to?(:delete_customer_appointments, nil, global: true) %>
+ <%= link_to customer_appointment_path(@appointment), method: :delete, data: { confirm: l(:text_are_you_sure) } do %>
+ <%= l(:button_delete) %>
+ <% end %>
<% end %>
@@ -36,20 +42,22 @@
-<%# Quick Status Action Buttons %>
-<%
- statuses = CustomerAppointment::STATUSES
- current_status = @appointment.status.to_s.parameterize.underscore
-%>
-