Implement permission checks for adding and deleting line items in issue forms

This commit is contained in:
ricky committed 2026-09-07 21:32:44 -04:00
1 parent 0acf5ffca4
commit 9a9efcbaf9
5 files changed
+40 -29

No files matched your search

+8 -5
View File
@@ -45,11 +45,14 @@
</template> </template>
<p> <p>
<button type="button"
class="icon icon-add" <% if User.current.allowed_to?(:add_line_items, nil, global: true) %>
data-nested-form-add> <button type="button"
<%= l(:button_add) %> class="icon icon-add"
</button> data-nested-form-add>
<%= l(:button_add) %>
</button>
<% end %>
</p> </p>
<% end %> <% end %>
@@ -35,13 +35,15 @@
0.00 0.00
</td> </td>
<% unless readonly %> <% if User.current.allowed_to?(:delete_line_items, nil, global: true) %>
<td class="actions"> <% unless readonly %>
<button type="button" <td class="actions">
class="icon-only icon-del" <button type="button"
title="<%= l(:label_remove) %>" class="icon-only icon-del"
data-nested-form-remove> title="<%= l(:label_remove) %>"
</button> data-nested-form-remove>
</td> </button>
</td>
<% end %>
<% end %> <% end %>
</tr> </tr>
+5 -7
View File
@@ -29,14 +29,12 @@ Redmine::Plugin.register :redmine_qbo_lineitems do
# Add safe attributes for core models # Add safe attributes for core models
Issue.safe_attributes :line_items_attributes Issue.safe_attributes :line_items_attributes
end
# Administration menu extension # Global Permissions
Redmine::MenuManager.map :admin_menu do |menu| permission :view_line_items, { line_items: [:index, :show] }, global: true
menu.push :redmine_qbo_lineitems, { controller: 'items', action: 'index' }, permission :add_line_items, { line_items: [:new, :create] }, global: true
icon: 'list', permission :edit_line_items, { line_items: [:edit, :update] }, global: true
caption: :label_items, permission :delete_line_items, { line_items: [:destroy] }, global: true
html: { class: 'icon icon-list' }
end end
RedmineQboLineItems.setup RedmineQboLineItems.setup
+9 -9
View File
@@ -24,19 +24,19 @@ module LineItems
]) ])
end end
# Add the line items form to the issue edit page
def view_issues_edit_notes_bottom(context = {}) def view_issues_edit_notes_bottom(context = {})
return if context[:issue].closed? return if context[:issue].closed?
context[:controller].send(:render_to_string, { return unless User.current.allowed_to?(:edit_line_items, nil, global: true)
partial: 'line_items/issue_form', context[:controller].send(:render_to_string, { partial: 'line_items/issue_form', locals: { f: context[:form] } })
locals: { end
f: context[:form]
} # Add the line items to the issue view page
} def view_issues_show_description_bottom (context = {})
) return unless User.current.allowed_to?(:view_line_items, nil, global: true)
context[:controller].send(:render_to_string, { partial: 'line_items/issue_line_items', locals: { issue: context[:issue] } })
end end
render_on :view_issues_show_description_bottom , partial: 'line_items/issue_line_items'
end end
end end
end end
+8
View File
@@ -12,10 +12,18 @@ module RedmineQboLineItems
def self.setup def self.setup
unless Issue.ancestors.include?(LineItems::Patches::IssuePatch) unless Issue.ancestors.include?(LineItems::Patches::IssuePatch)
# Patches
Issue.prepend LineItems::Patches::IssuePatch Issue.prepend LineItems::Patches::IssuePatch
# Hooks
LineItems::Hooks::IssuesSaveHookListener LineItems::Hooks::IssuesSaveHookListener
LineItems::Hooks::QboHookListener LineItems::Hooks::QboHookListener
LineItems::Hooks::ViewHookListener LineItems::Hooks::ViewHookListener
# Administration menu extension
Redmine::MenuManager.map :admin_menu do |menu|
menu.push :redmine_qbo_lineitems, { controller: 'items', action: 'index' }, icon: 'list', caption: :label_items, html: { class: 'icon icon-list' }
end
end end
end end
end end