mirror of
https://github.com/rickbarrette/redmine_qbo_calendar.git
synced 2026-10-03 20:40:43 -04:00
Implement global permissions for customer appointments and update views to check permissions before displaying actions
This commit is contained in:
1 parent
167e956457
commit
97ed852068
8 files changed
+70
-40
No files matched your search
@@ -12,7 +12,8 @@ class CustomerAppointmentsController < ApplicationController
|
|||||||
before_action :require_login
|
before_action :require_login
|
||||||
before_action :find_project, except: [:index]
|
before_action :find_project, except: [:index]
|
||||||
before_action :find_appointment, only: [ :show, :edit, :update, :destroy ]
|
before_action :find_appointment, only: [ :show, :edit, :update, :destroy ]
|
||||||
#before_action :authorize
|
# This tells Redmine to check global permissions for the current controller/action
|
||||||
|
before_action :authorize_global
|
||||||
|
|
||||||
helper :projects
|
helper :projects
|
||||||
|
|
||||||
|
|||||||
@@ -197,15 +197,17 @@
|
|||||||
</span>
|
</span>
|
||||||
|
|
||||||
<!-- Center: New Appointment Action -->
|
<!-- Center: New Appointment Action -->
|
||||||
<span class="day-num-center" style="display: inline-flex; align-items: center; justify-self: center;">
|
<% if User.current.allowed_to?(:add_customer_appointments, nil, global: true) %>
|
||||||
<%# Only show ADD button if it's in the future, NOT a weekend, and NOT a custom holiday %>
|
<span class="day-num-center" style="display: inline-flex; align-items: center; justify-self: center;">
|
||||||
<% if day >= User.current.today && !is_standard_weekend && !is_custom_holiday %>
|
<%# Only show ADD button if it's in the future, NOT a weekend, NOT a holiday, AND user has permission %>
|
||||||
<%= link_to sprite_icon('add'),
|
<% if day >= User.current.today && !is_standard_weekend && !is_custom_holiday && User.current.allowed_to?(:add_customer_appointments, nil, global: true) %>
|
||||||
new_customer_appointment_path(start_date: day),
|
<%= link_to sprite_icon('add'),
|
||||||
class: 'icon-only icon-add',
|
new_customer_appointment_path(start_date: day),
|
||||||
title: l(:label_appointment_new, default: 'New Appointment') %>
|
class: 'icon-only icon-add',
|
||||||
<% end %>
|
title: l(:label_appointment_new, default: 'New Appointment') %>
|
||||||
</span>
|
<% end %>
|
||||||
|
</span>
|
||||||
|
<% end %>
|
||||||
|
|
||||||
<!-- Right: Total Hours -->
|
<!-- Right: Total Hours -->
|
||||||
<span class="day-num-right" style="display: inline-flex; align-items: center; justify-self: end;">
|
<span class="day-num-right" style="display: inline-flex; align-items: center; justify-self: end;">
|
||||||
|
|||||||
@@ -1,4 +1,6 @@
|
|||||||
<p>
|
<% if User.current.allowed_to?(:add_customer_appointments, nil, global: true) %>
|
||||||
<% customer = context[:customer] %>
|
<p>
|
||||||
<%= link_to l(:label_add_appointment), new_customer_appointment_path(customer_id: customer.id), target: :_blank, id: :appointment_link %>
|
<% customer = context[:customer] %>
|
||||||
</p>
|
<%= link_to l(:label_add_appointment), new_customer_appointment_path(customer_id: customer.id), target: :_blank, id: :appointment_link %>
|
||||||
|
</p>\
|
||||||
|
<% end %>
|
||||||
@@ -92,6 +92,8 @@
|
|||||||
|
|
||||||
<hr>
|
<hr>
|
||||||
|
|
||||||
<p class="buttons">
|
<% if User.current.allowed_to?(:edit_customer_appointments, nil, global: true) %>
|
||||||
<%= link_to l(:label_open_appointment), customer_appointment_path(appointment), class: "icon icon-edit" %>
|
<p class="buttons">
|
||||||
</p>
|
<%= link_to l(:label_open_appointment), customer_appointment_path(appointment), class: "icon icon-edit" %>
|
||||||
|
</p>
|
||||||
|
<% end %>
|
||||||
@@ -5,8 +5,10 @@
|
|||||||
<i class="fa-regular fa-calendar-days"></i> <%= l(:button_calendar) %>
|
<i class="fa-regular fa-calendar-days"></i> <%= l(:button_calendar) %>
|
||||||
<% end %>
|
<% end %>
|
||||||
|
|
||||||
<%= link_to new_customer_appointment_path do %>
|
<% if User.current.allowed_to?(:add_customer_appointments, nil, global: true) %>
|
||||||
<i class="fa-regular fa-pen-to-square"></i> <%= l(:button_add) %>
|
<%= link_to new_customer_appointment_path do %>
|
||||||
|
<i class="fa-regular fa-pen-to-square"></i> <%= l(:button_add) %>
|
||||||
|
<% end %>
|
||||||
<% end %>
|
<% end %>
|
||||||
|
|
||||||
</div>
|
</div>
|
||||||
|
|||||||
@@ -3,16 +3,22 @@
|
|||||||
<i class="fa-regular fa-calendar-days"></i> <%= l(:button_calendar) %>
|
<i class="fa-regular fa-calendar-days"></i> <%= l(:button_calendar) %>
|
||||||
<% end %>
|
<% end %>
|
||||||
|
|
||||||
<%= link_to new_issue_path(issue: { customer_id: @appointment.customer_id, vehicle_id: @appointment.vehicle_id, estimate_id: @appointment.estimate_id }), target: :_blank do %>
|
<% if User.current.allowed_to?(:add_customer_appointments, nil, global: true) %>
|
||||||
<i class="fa-solid fa-plus"></i> <%= l(:label_new_issue) %>
|
<%= link_to new_issue_path(issue: { customer_id: @appointment.customer_id, vehicle_id: @appointment.vehicle_id, estimate_id: @appointment.estimate_id }), target: :_blank do %>
|
||||||
|
<i class="fa-solid fa-plus"></i> <%= l(:label_new_issue) %>
|
||||||
|
<% end %>
|
||||||
<% end %>
|
<% end %>
|
||||||
|
|
||||||
<%= link_to edit_customer_appointment_path(@appointment) do %>
|
<% if User.current.allowed_to?(:edit_customer_appointments, nil, global: true) %>
|
||||||
<i class="fa-solid fa-pen-to-square"></i> <%= l(:button_edit) %>
|
<%= link_to edit_customer_appointment_path(@appointment) do %>
|
||||||
|
<i class="fa-solid fa-pen-to-square"></i> <%= l(:button_edit) %>
|
||||||
|
<% end %>
|
||||||
<% end %>
|
<% end %>
|
||||||
|
|
||||||
<%= link_to customer_appointment_path(@appointment), method: :delete, data: { confirm: l(:text_are_you_sure) } do %>
|
<% if User.current.allowed_to?(:delete_customer_appointments, nil, global: true) %>
|
||||||
<i class="fa-solid fa-trash"></i> <%= l(:button_delete) %>
|
<%= link_to customer_appointment_path(@appointment), method: :delete, data: { confirm: l(:text_are_you_sure) } do %>
|
||||||
|
<i class="fa-solid fa-trash"></i> <%= l(:button_delete) %>
|
||||||
|
<% end %>
|
||||||
<% end %>
|
<% end %>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
@@ -36,20 +42,22 @@
|
|||||||
</span>
|
</span>
|
||||||
</h2>
|
</h2>
|
||||||
|
|
||||||
<%# Quick Status Action Buttons %>
|
<% if User.current.allowed_to?(:edit_customer_appointments, nil, global: true) %>
|
||||||
<%
|
<%# Quick Status Action Buttons %>
|
||||||
statuses = CustomerAppointment::STATUSES
|
<%
|
||||||
current_status = @appointment.status.to_s.parameterize.underscore
|
statuses = CustomerAppointment::STATUSES
|
||||||
%>
|
current_status = @appointment.status.to_s.parameterize.underscore
|
||||||
<div class="appointment-quick-actions">
|
%>
|
||||||
<span class="quick-action-label"><%= l(:label_change_status, default: 'Change Status:') %></span>
|
<div class="appointment-quick-actions">
|
||||||
<% statuses.reject { |s| s == current_status }.each do |status_key| %>
|
<span class="quick-action-label"><%= l(:label_change_status, default: 'Change Status:') %></span>
|
||||||
<%= link_to status_key.humanize,
|
<% statuses.reject { |s| s == current_status }.each do |status_key| %>
|
||||||
customer_appointment_path(@appointment, customer_appointment: { status: status_key }),
|
<%= link_to status_key.humanize,
|
||||||
method: :patch,
|
customer_appointment_path(@appointment, customer_appointment: { status: status_key }),
|
||||||
class: "quick-status-btn status-#{status_key.parameterize}" %>
|
method: :patch,
|
||||||
<% end %>
|
class: "quick-status-btn status-#{status_key.parameterize}" %>
|
||||||
</div>
|
<% end %>
|
||||||
|
</div>
|
||||||
|
<% end %>
|
||||||
|
|
||||||
<div class="issue details">
|
<div class="issue details">
|
||||||
<div class="attributes">
|
<div class="attributes">
|
||||||
|
|||||||
@@ -34,6 +34,7 @@ en:
|
|||||||
field_vehicle: Vehicle
|
field_vehicle: Vehicle
|
||||||
label_add_appointment: Add Appointment
|
label_add_appointment: Add Appointment
|
||||||
label_appointment: Appointment
|
label_appointment: Appointment
|
||||||
|
label_appointment_new: "New Appointment"
|
||||||
label_appointments: Appointments
|
label_appointments: Appointments
|
||||||
label_customer_appointment: Customer Appointment
|
label_customer_appointment: Customer Appointment
|
||||||
label_customer_calendar: Customer Calendar
|
label_customer_calendar: Customer Calendar
|
||||||
@@ -43,9 +44,11 @@ en:
|
|||||||
label_end_date: End Date
|
label_end_date: End Date
|
||||||
label_estimated_hours: Estimated Time
|
label_estimated_hours: Estimated Time
|
||||||
label_event: Event
|
label_event: Event
|
||||||
|
label_hide_past_weeks: "Hide Past Weeks"
|
||||||
label_holiday_edit: Edit Holiday
|
label_holiday_edit: Edit Holiday
|
||||||
label_holiday_new: New Holiday
|
label_holiday_new: New Holiday
|
||||||
label_holiday_plural: Holidays
|
label_holiday_plural: Holidays
|
||||||
|
label_legend: "Legend"
|
||||||
label_new_appointment: New Appointment
|
label_new_appointment: New Appointment
|
||||||
label_of: "of"
|
label_of: "of"
|
||||||
label_only_customer_appointments: Show Customer Appointments Only
|
label_only_customer_appointments: Show Customer Appointments Only
|
||||||
@@ -65,6 +68,9 @@ en:
|
|||||||
label_week_4th: "4th"
|
label_week_4th: "4th"
|
||||||
label_week_last: "Last"
|
label_week_last: "Last"
|
||||||
notice_unable_delete_holiday: "Unable to delete holiday"
|
notice_unable_delete_holiday: "Unable to delete holiday"
|
||||||
|
permission_add_customer_appointments: "Add customer appointments"
|
||||||
|
permission_delete_customer_appointments: "Delete customer appointments"
|
||||||
|
permission_edit_customer_appointments: "Edit customer appointments"
|
||||||
permission_manage_customer_appointments: Manage Customer Appointments
|
permission_manage_customer_appointments: Manage Customer Appointments
|
||||||
permission_view_customer_appointments: View Customer Appointments
|
permission_view_customer_appointments: "View customer appointments"
|
||||||
title_customer_appointments: Customer Appointments
|
title_customer_appointments: Customer Appointments
|
||||||
@@ -53,6 +53,13 @@ end
|
|||||||
caption: 'Customer Calendar',
|
caption: 'Customer Calendar',
|
||||||
after: :calendar,
|
after: :calendar,
|
||||||
param: :project_id
|
param: :project_id
|
||||||
|
|
||||||
|
# Global Permissions
|
||||||
|
permission :view_customer_appointments, { customer_appointments: [:index, :show] }, global: true
|
||||||
|
permission :add_customer_appointments, { customer_appointments: [:new, :create] }, global: true
|
||||||
|
permission :edit_customer_appointments, { customer_appointments: [:edit, :update] }, global: true
|
||||||
|
permission :delete_customer_appointments, { customer_appointments: [:destroy] }, global: true
|
||||||
|
|
||||||
end
|
end
|
||||||
|
|
||||||
Rails.configuration.to_prepare do
|
Rails.configuration.to_prepare do
|
||||||
|
|||||||
Reference in new issue
Block a user