From 97ed852068fd9556dc17e27c6ff8d1d022d96a1c Mon Sep 17 00:00:00 2001 From: Rick Barrette Date: Sun, 6 Sep 2026 21:11:18 -0400 Subject: [PATCH] Implement global permissions for customer appointments and update views to check permissions before displaying actions --- .../customer_appointments_controller.rb | 3 +- app/views/common/_calendar.html.erb | 20 ++++---- .../_customer_actions.html.erb | 10 ++-- .../customer_appointments/_tooltip.html.erb | 8 ++-- .../customer_appointments/index.html.erb | 6 ++- app/views/customer_appointments/show.html.erb | 48 +++++++++++-------- config/locales/en.yml | 8 +++- init.rb | 7 +++ 8 files changed, 70 insertions(+), 40 deletions(-) diff --git a/app/controllers/customer_appointments_controller.rb b/app/controllers/customer_appointments_controller.rb index c513d91..8c8aa88 100644 --- a/app/controllers/customer_appointments_controller.rb +++ b/app/controllers/customer_appointments_controller.rb @@ -12,7 +12,8 @@ class CustomerAppointmentsController < ApplicationController before_action :require_login before_action :find_project, except: [:index] before_action :find_appointment, only: [ :show, :edit, :update, :destroy ] - #before_action :authorize + # This tells Redmine to check global permissions for the current controller/action + before_action :authorize_global helper :projects diff --git a/app/views/common/_calendar.html.erb b/app/views/common/_calendar.html.erb index 3fa900c..453b01f 100644 --- a/app/views/common/_calendar.html.erb +++ b/app/views/common/_calendar.html.erb @@ -197,15 +197,17 @@ - - <%# Only show ADD button if it's in the future, NOT a weekend, and NOT a custom holiday %> - <% if day >= User.current.today && !is_standard_weekend && !is_custom_holiday %> - <%= link_to sprite_icon('add'), - new_customer_appointment_path(start_date: day), - class: 'icon-only icon-add', - title: l(:label_appointment_new, default: 'New Appointment') %> - <% end %> - + <% if User.current.allowed_to?(:add_customer_appointments, nil, global: true) %> + + <%# Only show ADD button if it's in the future, NOT a weekend, NOT a holiday, AND user has permission %> + <% if day >= User.current.today && !is_standard_weekend && !is_custom_holiday && User.current.allowed_to?(:add_customer_appointments, nil, global: true) %> + <%= link_to sprite_icon('add'), + new_customer_appointment_path(start_date: day), + class: 'icon-only icon-add', + title: l(:label_appointment_new, default: 'New Appointment') %> + <% end %> + + <% end %> diff --git a/app/views/customer_appointments/_customer_actions.html.erb b/app/views/customer_appointments/_customer_actions.html.erb index a7d8b26..d0f5305 100644 --- a/app/views/customer_appointments/_customer_actions.html.erb +++ b/app/views/customer_appointments/_customer_actions.html.erb @@ -1,4 +1,6 @@ -

-<% customer = context[:customer] %> -<%= link_to l(:label_add_appointment), new_customer_appointment_path(customer_id: customer.id), target: :_blank, id: :appointment_link %> -

\ No newline at end of file +<% if User.current.allowed_to?(:add_customer_appointments, nil, global: true) %> +

+ <% customer = context[:customer] %> + <%= link_to l(:label_add_appointment), new_customer_appointment_path(customer_id: customer.id), target: :_blank, id: :appointment_link %> +

\ +<% end %> \ No newline at end of file diff --git a/app/views/customer_appointments/_tooltip.html.erb b/app/views/customer_appointments/_tooltip.html.erb index 6b61e8a..2f8307a 100644 --- a/app/views/customer_appointments/_tooltip.html.erb +++ b/app/views/customer_appointments/_tooltip.html.erb @@ -92,6 +92,8 @@
-

- <%= link_to l(:label_open_appointment), customer_appointment_path(appointment), class: "icon icon-edit" %> -

\ No newline at end of file +<% if User.current.allowed_to?(:edit_customer_appointments, nil, global: true) %> +

+ <%= link_to l(:label_open_appointment), customer_appointment_path(appointment), class: "icon icon-edit" %> +

+<% end %> \ No newline at end of file diff --git a/app/views/customer_appointments/index.html.erb b/app/views/customer_appointments/index.html.erb index 733dffd..a6eebde 100644 --- a/app/views/customer_appointments/index.html.erb +++ b/app/views/customer_appointments/index.html.erb @@ -5,8 +5,10 @@ <%= l(:button_calendar) %> <% end %> - <%= link_to new_customer_appointment_path do %> - <%= l(:button_add) %> + <% if User.current.allowed_to?(:add_customer_appointments, nil, global: true) %> + <%= link_to new_customer_appointment_path do %> + <%= l(:button_add) %> + <% end %> <% end %> diff --git a/app/views/customer_appointments/show.html.erb b/app/views/customer_appointments/show.html.erb index 6ad3250..258a388 100644 --- a/app/views/customer_appointments/show.html.erb +++ b/app/views/customer_appointments/show.html.erb @@ -3,16 +3,22 @@ <%= l(:button_calendar) %> <% end %> - <%= link_to new_issue_path(issue: { customer_id: @appointment.customer_id, vehicle_id: @appointment.vehicle_id, estimate_id: @appointment.estimate_id }), target: :_blank do %> - <%= l(:label_new_issue) %> + <% if User.current.allowed_to?(:add_customer_appointments, nil, global: true) %> + <%= link_to new_issue_path(issue: { customer_id: @appointment.customer_id, vehicle_id: @appointment.vehicle_id, estimate_id: @appointment.estimate_id }), target: :_blank do %> + <%= l(:label_new_issue) %> + <% end %> <% end %> - <%= link_to edit_customer_appointment_path(@appointment) do %> - <%= l(:button_edit) %> + <% if User.current.allowed_to?(:edit_customer_appointments, nil, global: true) %> + <%= link_to edit_customer_appointment_path(@appointment) do %> + <%= l(:button_edit) %> + <% end %> <% end %> - <%= link_to customer_appointment_path(@appointment), method: :delete, data: { confirm: l(:text_are_you_sure) } do %> - <%= l(:button_delete) %> + <% if User.current.allowed_to?(:delete_customer_appointments, nil, global: true) %> + <%= link_to customer_appointment_path(@appointment), method: :delete, data: { confirm: l(:text_are_you_sure) } do %> + <%= l(:button_delete) %> + <% end %> <% end %> @@ -36,20 +42,22 @@
-<%# Quick Status Action Buttons %> -<% - statuses = CustomerAppointment::STATUSES - current_status = @appointment.status.to_s.parameterize.underscore -%> -
- <%= l(:label_change_status, default: 'Change Status:') %> - <% statuses.reject { |s| s == current_status }.each do |status_key| %> - <%= link_to status_key.humanize, - customer_appointment_path(@appointment, customer_appointment: { status: status_key }), - method: :patch, - class: "quick-status-btn status-#{status_key.parameterize}" %> - <% end %> -
+<% if User.current.allowed_to?(:edit_customer_appointments, nil, global: true) %> + <%# Quick Status Action Buttons %> + <% + statuses = CustomerAppointment::STATUSES + current_status = @appointment.status.to_s.parameterize.underscore + %> +
+ <%= l(:label_change_status, default: 'Change Status:') %> + <% statuses.reject { |s| s == current_status }.each do |status_key| %> + <%= link_to status_key.humanize, + customer_appointment_path(@appointment, customer_appointment: { status: status_key }), + method: :patch, + class: "quick-status-btn status-#{status_key.parameterize}" %> + <% end %> +
+<% end %>
diff --git a/config/locales/en.yml b/config/locales/en.yml index ee48c96..d7153ed 100644 --- a/config/locales/en.yml +++ b/config/locales/en.yml @@ -34,6 +34,7 @@ en: field_vehicle: Vehicle label_add_appointment: Add Appointment label_appointment: Appointment + label_appointment_new: "New Appointment" label_appointments: Appointments label_customer_appointment: Customer Appointment label_customer_calendar: Customer Calendar @@ -43,9 +44,11 @@ en: label_end_date: End Date label_estimated_hours: Estimated Time label_event: Event + label_hide_past_weeks: "Hide Past Weeks" label_holiday_edit: Edit Holiday label_holiday_new: New Holiday label_holiday_plural: Holidays + label_legend: "Legend" label_new_appointment: New Appointment label_of: "of" label_only_customer_appointments: Show Customer Appointments Only @@ -65,6 +68,9 @@ en: label_week_4th: "4th" label_week_last: "Last" notice_unable_delete_holiday: "Unable to delete holiday" + permission_add_customer_appointments: "Add customer appointments" + permission_delete_customer_appointments: "Delete customer appointments" + permission_edit_customer_appointments: "Edit customer appointments" permission_manage_customer_appointments: Manage Customer Appointments - permission_view_customer_appointments: View Customer Appointments + permission_view_customer_appointments: "View customer appointments" title_customer_appointments: Customer Appointments \ No newline at end of file diff --git a/init.rb b/init.rb index 07a4696..8b14406 100644 --- a/init.rb +++ b/init.rb @@ -53,6 +53,13 @@ end caption: 'Customer Calendar', after: :calendar, param: :project_id + + # Global Permissions + permission :view_customer_appointments, { customer_appointments: [:index, :show] }, global: true + permission :add_customer_appointments, { customer_appointments: [:new, :create] }, global: true + permission :edit_customer_appointments, { customer_appointments: [:edit, :update] }, global: true + permission :delete_customer_appointments, { customer_appointments: [:destroy] }, global: true + end Rails.configuration.to_prepare do