Implement permission checks for adding and deleting line items in issue forms

This commit is contained in:
ricky committed 2026-09-07 21:32:44 -04:00
1 parent 0acf5ffca4
commit 9a9efcbaf9
5 files changed
+40 -29

No files matched your search

+8 -5
View File
@@ -45,11 +45,14 @@
</template>
<p>
<button type="button"
class="icon icon-add"
data-nested-form-add>
<%= l(:button_add) %>
</button>
<% if User.current.allowed_to?(:add_line_items, nil, global: true) %>
<button type="button"
class="icon icon-add"
data-nested-form-add>
<%= l(:button_add) %>
</button>
<% end %>
</p>
<% end %>
@@ -35,13 +35,15 @@
0.00
</td>
<% unless readonly %>
<td class="actions">
<button type="button"
class="icon-only icon-del"
title="<%= l(:label_remove) %>"
data-nested-form-remove>
</button>
</td>
<% if User.current.allowed_to?(:delete_line_items, nil, global: true) %>
<% unless readonly %>
<td class="actions">
<button type="button"
class="icon-only icon-del"
title="<%= l(:label_remove) %>"
data-nested-form-remove>
</button>
</td>
<% end %>
<% end %>
</tr>
+5 -7
View File
@@ -29,14 +29,12 @@ Redmine::Plugin.register :redmine_qbo_lineitems do
# Add safe attributes for core models
Issue.safe_attributes :line_items_attributes
end
# Administration menu extension
Redmine::MenuManager.map :admin_menu do |menu|
menu.push :redmine_qbo_lineitems, { controller: 'items', action: 'index' },
icon: 'list',
caption: :label_items,
html: { class: 'icon icon-list' }
# Global Permissions
permission :view_line_items, { line_items: [:index, :show] }, global: true
permission :add_line_items, { line_items: [:new, :create] }, global: true
permission :edit_line_items, { line_items: [:edit, :update] }, global: true
permission :delete_line_items, { line_items: [:destroy] }, global: true
end
RedmineQboLineItems.setup
+9 -9
View File
@@ -24,19 +24,19 @@ module LineItems
])
end
# Add the line items form to the issue edit page
def view_issues_edit_notes_bottom(context = {})
return if context[:issue].closed?
context[:controller].send(:render_to_string, {
partial: 'line_items/issue_form',
locals: {
f: context[:form]
}
}
)
return unless User.current.allowed_to?(:edit_line_items, nil, global: true)
context[:controller].send(:render_to_string, { partial: 'line_items/issue_form', locals: { f: context[:form] } })
end
# Add the line items to the issue view page
def view_issues_show_description_bottom (context = {})
return unless User.current.allowed_to?(:view_line_items, nil, global: true)
context[:controller].send(:render_to_string, { partial: 'line_items/issue_line_items', locals: { issue: context[:issue] } })
end
render_on :view_issues_show_description_bottom , partial: 'line_items/issue_line_items'
end
end
end
+8
View File
@@ -12,10 +12,18 @@ module RedmineQboLineItems
def self.setup
unless Issue.ancestors.include?(LineItems::Patches::IssuePatch)
# Patches
Issue.prepend LineItems::Patches::IssuePatch
# Hooks
LineItems::Hooks::IssuesSaveHookListener
LineItems::Hooks::QboHookListener
LineItems::Hooks::ViewHookListener
# Administration menu extension
Redmine::MenuManager.map :admin_menu do |menu|
menu.push :redmine_qbo_lineitems, { controller: 'items', action: 'index' }, icon: 'list', caption: :label_items, html: { class: 'icon icon-list' }
end
end
end
end