Implement global permissions for customer appointments and update views to check permissions before displaying actions

This commit is contained in:
ricky committed 2026-09-06 21:11:18 -04:00
1 parent 167e956457
commit 97ed852068
8 files changed
+70 -40

No files matched your search

@@ -12,7 +12,8 @@ class CustomerAppointmentsController < ApplicationController
before_action :require_login
before_action :find_project, except: [:index]
before_action :find_appointment, only: [ :show, :edit, :update, :destroy ]
#before_action :authorize
# This tells Redmine to check global permissions for the current controller/action
before_action :authorize_global
helper :projects
+11 -9
View File
@@ -197,15 +197,17 @@
</span>
<!-- Center: New Appointment Action -->
<span class="day-num-center" style="display: inline-flex; align-items: center; justify-self: center;">
<%# Only show ADD button if it's in the future, NOT a weekend, and NOT a custom holiday %>
<% if day >= User.current.today && !is_standard_weekend && !is_custom_holiday %>
<%= link_to sprite_icon('add'),
new_customer_appointment_path(start_date: day),
class: 'icon-only icon-add',
title: l(:label_appointment_new, default: 'New Appointment') %>
<% end %>
</span>
<% if User.current.allowed_to?(:add_customer_appointments, nil, global: true) %>
<span class="day-num-center" style="display: inline-flex; align-items: center; justify-self: center;">
<%# Only show ADD button if it's in the future, NOT a weekend, NOT a holiday, AND user has permission %>
<% if day >= User.current.today && !is_standard_weekend && !is_custom_holiday && User.current.allowed_to?(:add_customer_appointments, nil, global: true) %>
<%= link_to sprite_icon('add'),
new_customer_appointment_path(start_date: day),
class: 'icon-only icon-add',
title: l(:label_appointment_new, default: 'New Appointment') %>
<% end %>
</span>
<% end %>
<!-- Right: Total Hours -->
<span class="day-num-right" style="display: inline-flex; align-items: center; justify-self: end;">
@@ -1,4 +1,6 @@
<p>
<% customer = context[:customer] %>
<%= link_to l(:label_add_appointment), new_customer_appointment_path(customer_id: customer.id), target: :_blank, id: :appointment_link %>
</p>
<% if User.current.allowed_to?(:add_customer_appointments, nil, global: true) %>
<p>
<% customer = context[:customer] %>
<%= link_to l(:label_add_appointment), new_customer_appointment_path(customer_id: customer.id), target: :_blank, id: :appointment_link %>
</p>\
<% end %>
@@ -92,6 +92,8 @@
<hr>
<p class="buttons">
<%= link_to l(:label_open_appointment), customer_appointment_path(appointment), class: "icon icon-edit" %>
</p>
<% if User.current.allowed_to?(:edit_customer_appointments, nil, global: true) %>
<p class="buttons">
<%= link_to l(:label_open_appointment), customer_appointment_path(appointment), class: "icon icon-edit" %>
</p>
<% end %>
@@ -5,8 +5,10 @@
<i class="fa-regular fa-calendar-days"></i> <%= l(:button_calendar) %>
<% end %>
<%= link_to new_customer_appointment_path do %>
<i class="fa-regular fa-pen-to-square"></i> <%= l(:button_add) %>
<% if User.current.allowed_to?(:add_customer_appointments, nil, global: true) %>
<%= link_to new_customer_appointment_path do %>
<i class="fa-regular fa-pen-to-square"></i> <%= l(:button_add) %>
<% end %>
<% end %>
</div>
+28 -20
View File
@@ -3,16 +3,22 @@
<i class="fa-regular fa-calendar-days"></i> <%= l(:button_calendar) %>
<% end %>
<%= link_to new_issue_path(issue: { customer_id: @appointment.customer_id, vehicle_id: @appointment.vehicle_id, estimate_id: @appointment.estimate_id }), target: :_blank do %>
<i class="fa-solid fa-plus"></i> <%= l(:label_new_issue) %>
<% if User.current.allowed_to?(:add_customer_appointments, nil, global: true) %>
<%= link_to new_issue_path(issue: { customer_id: @appointment.customer_id, vehicle_id: @appointment.vehicle_id, estimate_id: @appointment.estimate_id }), target: :_blank do %>
<i class="fa-solid fa-plus"></i> <%= l(:label_new_issue) %>
<% end %>
<% end %>
<%= link_to edit_customer_appointment_path(@appointment) do %>
<i class="fa-solid fa-pen-to-square"></i> <%= l(:button_edit) %>
<% if User.current.allowed_to?(:edit_customer_appointments, nil, global: true) %>
<%= link_to edit_customer_appointment_path(@appointment) do %>
<i class="fa-solid fa-pen-to-square"></i> <%= l(:button_edit) %>
<% end %>
<% end %>
<%= link_to customer_appointment_path(@appointment), method: :delete, data: { confirm: l(:text_are_you_sure) } do %>
<i class="fa-solid fa-trash"></i> <%= l(:button_delete) %>
<% if User.current.allowed_to?(:delete_customer_appointments, nil, global: true) %>
<%= link_to customer_appointment_path(@appointment), method: :delete, data: { confirm: l(:text_are_you_sure) } do %>
<i class="fa-solid fa-trash"></i> <%= l(:button_delete) %>
<% end %>
<% end %>
</div>
@@ -36,20 +42,22 @@
</span>
</h2>
<%# Quick Status Action Buttons %>
<%
statuses = CustomerAppointment::STATUSES
current_status = @appointment.status.to_s.parameterize.underscore
%>
<div class="appointment-quick-actions">
<span class="quick-action-label"><%= l(:label_change_status, default: 'Change Status:') %></span>
<% statuses.reject { |s| s == current_status }.each do |status_key| %>
<%= link_to status_key.humanize,
customer_appointment_path(@appointment, customer_appointment: { status: status_key }),
method: :patch,
class: "quick-status-btn status-#{status_key.parameterize}" %>
<% end %>
</div>
<% if User.current.allowed_to?(:edit_customer_appointments, nil, global: true) %>
<%# Quick Status Action Buttons %>
<%
statuses = CustomerAppointment::STATUSES
current_status = @appointment.status.to_s.parameterize.underscore
%>
<div class="appointment-quick-actions">
<span class="quick-action-label"><%= l(:label_change_status, default: 'Change Status:') %></span>
<% statuses.reject { |s| s == current_status }.each do |status_key| %>
<%= link_to status_key.humanize,
customer_appointment_path(@appointment, customer_appointment: { status: status_key }),
method: :patch,
class: "quick-status-btn status-#{status_key.parameterize}" %>
<% end %>
</div>
<% end %>
<div class="issue details">
<div class="attributes">
+7 -1
View File
@@ -34,6 +34,7 @@ en:
field_vehicle: Vehicle
label_add_appointment: Add Appointment
label_appointment: Appointment
label_appointment_new: "New Appointment"
label_appointments: Appointments
label_customer_appointment: Customer Appointment
label_customer_calendar: Customer Calendar
@@ -43,9 +44,11 @@ en:
label_end_date: End Date
label_estimated_hours: Estimated Time
label_event: Event
label_hide_past_weeks: "Hide Past Weeks"
label_holiday_edit: Edit Holiday
label_holiday_new: New Holiday
label_holiday_plural: Holidays
label_legend: "Legend"
label_new_appointment: New Appointment
label_of: "of"
label_only_customer_appointments: Show Customer Appointments Only
@@ -65,6 +68,9 @@ en:
label_week_4th: "4th"
label_week_last: "Last"
notice_unable_delete_holiday: "Unable to delete holiday"
permission_add_customer_appointments: "Add customer appointments"
permission_delete_customer_appointments: "Delete customer appointments"
permission_edit_customer_appointments: "Edit customer appointments"
permission_manage_customer_appointments: Manage Customer Appointments
permission_view_customer_appointments: View Customer Appointments
permission_view_customer_appointments: "View customer appointments"
title_customer_appointments: Customer Appointments
+7
View File
@@ -53,6 +53,13 @@ end
caption: 'Customer Calendar',
after: :calendar,
param: :project_id
# Global Permissions
permission :view_customer_appointments, { customer_appointments: [:index, :show] }, global: true
permission :add_customer_appointments, { customer_appointments: [:new, :create] }, global: true
permission :edit_customer_appointments, { customer_appointments: [:edit, :update] }, global: true
permission :delete_customer_appointments, { customer_appointments: [:destroy] }, global: true
end
Rails.configuration.to_prepare do