Implement global permissions for customer appointments and update views to check permissions before displaying actions

This commit is contained in:
ricky committed 2026-09-06 21:11:18 -04:00
1 parent 167e956457
commit 97ed852068
8 files changed
+70 -40

No files matched your search

@@ -12,7 +12,8 @@ class CustomerAppointmentsController < ApplicationController
before_action :require_login before_action :require_login
before_action :find_project, except: [:index] before_action :find_project, except: [:index]
before_action :find_appointment, only: [ :show, :edit, :update, :destroy ] before_action :find_appointment, only: [ :show, :edit, :update, :destroy ]
#before_action :authorize # This tells Redmine to check global permissions for the current controller/action
before_action :authorize_global
helper :projects helper :projects
+11 -9
View File
@@ -197,15 +197,17 @@
</span> </span>
<!-- Center: New Appointment Action --> <!-- Center: New Appointment Action -->
<span class="day-num-center" style="display: inline-flex; align-items: center; justify-self: center;"> <% if User.current.allowed_to?(:add_customer_appointments, nil, global: true) %>
<%# Only show ADD button if it's in the future, NOT a weekend, and NOT a custom holiday %> <span class="day-num-center" style="display: inline-flex; align-items: center; justify-self: center;">
<% if day >= User.current.today && !is_standard_weekend && !is_custom_holiday %> <%# Only show ADD button if it's in the future, NOT a weekend, NOT a holiday, AND user has permission %>
<%= link_to sprite_icon('add'), <% if day >= User.current.today && !is_standard_weekend && !is_custom_holiday && User.current.allowed_to?(:add_customer_appointments, nil, global: true) %>
new_customer_appointment_path(start_date: day), <%= link_to sprite_icon('add'),
class: 'icon-only icon-add', new_customer_appointment_path(start_date: day),
title: l(:label_appointment_new, default: 'New Appointment') %> class: 'icon-only icon-add',
<% end %> title: l(:label_appointment_new, default: 'New Appointment') %>
</span> <% end %>
</span>
<% end %>
<!-- Right: Total Hours --> <!-- Right: Total Hours -->
<span class="day-num-right" style="display: inline-flex; align-items: center; justify-self: end;"> <span class="day-num-right" style="display: inline-flex; align-items: center; justify-self: end;">
@@ -1,4 +1,6 @@
<p> <% if User.current.allowed_to?(:add_customer_appointments, nil, global: true) %>
<% customer = context[:customer] %> <p>
<%= link_to l(:label_add_appointment), new_customer_appointment_path(customer_id: customer.id), target: :_blank, id: :appointment_link %> <% customer = context[:customer] %>
</p> <%= link_to l(:label_add_appointment), new_customer_appointment_path(customer_id: customer.id), target: :_blank, id: :appointment_link %>
</p>\
<% end %>
@@ -92,6 +92,8 @@
<hr> <hr>
<p class="buttons"> <% if User.current.allowed_to?(:edit_customer_appointments, nil, global: true) %>
<%= link_to l(:label_open_appointment), customer_appointment_path(appointment), class: "icon icon-edit" %> <p class="buttons">
</p> <%= link_to l(:label_open_appointment), customer_appointment_path(appointment), class: "icon icon-edit" %>
</p>
<% end %>
@@ -5,8 +5,10 @@
<i class="fa-regular fa-calendar-days"></i> <%= l(:button_calendar) %> <i class="fa-regular fa-calendar-days"></i> <%= l(:button_calendar) %>
<% end %> <% end %>
<%= link_to new_customer_appointment_path do %> <% if User.current.allowed_to?(:add_customer_appointments, nil, global: true) %>
<i class="fa-regular fa-pen-to-square"></i> <%= l(:button_add) %> <%= link_to new_customer_appointment_path do %>
<i class="fa-regular fa-pen-to-square"></i> <%= l(:button_add) %>
<% end %>
<% end %> <% end %>
</div> </div>
+28 -20
View File
@@ -3,16 +3,22 @@
<i class="fa-regular fa-calendar-days"></i> <%= l(:button_calendar) %> <i class="fa-regular fa-calendar-days"></i> <%= l(:button_calendar) %>
<% end %> <% end %>
<%= link_to new_issue_path(issue: { customer_id: @appointment.customer_id, vehicle_id: @appointment.vehicle_id, estimate_id: @appointment.estimate_id }), target: :_blank do %> <% if User.current.allowed_to?(:add_customer_appointments, nil, global: true) %>
<i class="fa-solid fa-plus"></i> <%= l(:label_new_issue) %> <%= link_to new_issue_path(issue: { customer_id: @appointment.customer_id, vehicle_id: @appointment.vehicle_id, estimate_id: @appointment.estimate_id }), target: :_blank do %>
<i class="fa-solid fa-plus"></i> <%= l(:label_new_issue) %>
<% end %>
<% end %> <% end %>
<%= link_to edit_customer_appointment_path(@appointment) do %> <% if User.current.allowed_to?(:edit_customer_appointments, nil, global: true) %>
<i class="fa-solid fa-pen-to-square"></i> <%= l(:button_edit) %> <%= link_to edit_customer_appointment_path(@appointment) do %>
<i class="fa-solid fa-pen-to-square"></i> <%= l(:button_edit) %>
<% end %>
<% end %> <% end %>
<%= link_to customer_appointment_path(@appointment), method: :delete, data: { confirm: l(:text_are_you_sure) } do %> <% if User.current.allowed_to?(:delete_customer_appointments, nil, global: true) %>
<i class="fa-solid fa-trash"></i> <%= l(:button_delete) %> <%= link_to customer_appointment_path(@appointment), method: :delete, data: { confirm: l(:text_are_you_sure) } do %>
<i class="fa-solid fa-trash"></i> <%= l(:button_delete) %>
<% end %>
<% end %> <% end %>
</div> </div>
@@ -36,20 +42,22 @@
</span> </span>
</h2> </h2>
<%# Quick Status Action Buttons %> <% if User.current.allowed_to?(:edit_customer_appointments, nil, global: true) %>
<% <%# Quick Status Action Buttons %>
statuses = CustomerAppointment::STATUSES <%
current_status = @appointment.status.to_s.parameterize.underscore statuses = CustomerAppointment::STATUSES
%> current_status = @appointment.status.to_s.parameterize.underscore
<div class="appointment-quick-actions"> %>
<span class="quick-action-label"><%= l(:label_change_status, default: 'Change Status:') %></span> <div class="appointment-quick-actions">
<% statuses.reject { |s| s == current_status }.each do |status_key| %> <span class="quick-action-label"><%= l(:label_change_status, default: 'Change Status:') %></span>
<%= link_to status_key.humanize, <% statuses.reject { |s| s == current_status }.each do |status_key| %>
customer_appointment_path(@appointment, customer_appointment: { status: status_key }), <%= link_to status_key.humanize,
method: :patch, customer_appointment_path(@appointment, customer_appointment: { status: status_key }),
class: "quick-status-btn status-#{status_key.parameterize}" %> method: :patch,
<% end %> class: "quick-status-btn status-#{status_key.parameterize}" %>
</div> <% end %>
</div>
<% end %>
<div class="issue details"> <div class="issue details">
<div class="attributes"> <div class="attributes">
+7 -1
View File
@@ -34,6 +34,7 @@ en:
field_vehicle: Vehicle field_vehicle: Vehicle
label_add_appointment: Add Appointment label_add_appointment: Add Appointment
label_appointment: Appointment label_appointment: Appointment
label_appointment_new: "New Appointment"
label_appointments: Appointments label_appointments: Appointments
label_customer_appointment: Customer Appointment label_customer_appointment: Customer Appointment
label_customer_calendar: Customer Calendar label_customer_calendar: Customer Calendar
@@ -43,9 +44,11 @@ en:
label_end_date: End Date label_end_date: End Date
label_estimated_hours: Estimated Time label_estimated_hours: Estimated Time
label_event: Event label_event: Event
label_hide_past_weeks: "Hide Past Weeks"
label_holiday_edit: Edit Holiday label_holiday_edit: Edit Holiday
label_holiday_new: New Holiday label_holiday_new: New Holiday
label_holiday_plural: Holidays label_holiday_plural: Holidays
label_legend: "Legend"
label_new_appointment: New Appointment label_new_appointment: New Appointment
label_of: "of" label_of: "of"
label_only_customer_appointments: Show Customer Appointments Only label_only_customer_appointments: Show Customer Appointments Only
@@ -65,6 +68,9 @@ en:
label_week_4th: "4th" label_week_4th: "4th"
label_week_last: "Last" label_week_last: "Last"
notice_unable_delete_holiday: "Unable to delete holiday" notice_unable_delete_holiday: "Unable to delete holiday"
permission_add_customer_appointments: "Add customer appointments"
permission_delete_customer_appointments: "Delete customer appointments"
permission_edit_customer_appointments: "Edit customer appointments"
permission_manage_customer_appointments: Manage Customer Appointments permission_manage_customer_appointments: Manage Customer Appointments
permission_view_customer_appointments: View Customer Appointments permission_view_customer_appointments: "View customer appointments"
title_customer_appointments: Customer Appointments title_customer_appointments: Customer Appointments
+7
View File
@@ -53,6 +53,13 @@ end
caption: 'Customer Calendar', caption: 'Customer Calendar',
after: :calendar, after: :calendar,
param: :project_id param: :project_id
# Global Permissions
permission :view_customer_appointments, { customer_appointments: [:index, :show] }, global: true
permission :add_customer_appointments, { customer_appointments: [:new, :create] }, global: true
permission :edit_customer_appointments, { customer_appointments: [:edit, :update] }, global: true
permission :delete_customer_appointments, { customer_appointments: [:destroy] }, global: true
end end
Rails.configuration.to_prepare do Rails.configuration.to_prepare do