From df41436e615cc541a946543b81498a84ff131151 Mon Sep 17 00:00:00 2001
From: Rick Barrette
Date: Tue, 8 Sep 2026 22:56:47 -0400
Subject: [PATCH] Implement global permissions for vehicle actions and update
version to 2026.9.0
---
app/controllers/vehicles_controller.rb | 2 ++
.../customer_appointments/_show_hook.html.erb | 14 ++++++++------
app/views/customers/_show_hook.html.erb | 4 +++-
app/views/vehicles/_details.html.erb | 8 ++++++--
init.rb | 12 ++++++++----
5 files changed, 27 insertions(+), 13 deletions(-)
diff --git a/app/controllers/vehicles_controller.rb b/app/controllers/vehicles_controller.rb
index a5b4f33..1c3aa10 100644
--- a/app/controllers/vehicles_controller.rb
+++ b/app/controllers/vehicles_controller.rb
@@ -13,6 +13,8 @@ class VehiclesController < ApplicationController
include AuthHelper
+ # This tells Redmine to check global permissions for the current controller/action
+ before_action :authorize_global
before_action :require_user
def allowed_params
diff --git a/app/views/customer_appointments/_show_hook.html.erb b/app/views/customer_appointments/_show_hook.html.erb
index ce967d1..cb13867 100644
--- a/app/views/customer_appointments/_show_hook.html.erb
+++ b/app/views/customer_appointments/_show_hook.html.erb
@@ -1,9 +1,11 @@
-<% if appointment.customer.present? %>
- <% unless appointment.vehicle.present? &&%>
-
- <%= link_to new_vehicle_path(customer_id: appointment.customer_id), class: 'icon icon-add' do %>
- <%= l(:label_add_vehicle) %>
+<% if <% if User.current.allowed_to?(:add_vehicles, nil, global: true) %> %>
+ <% if appointment.customer.present? %>
+ <% unless appointment.vehicle.present? &&%>
+
+ <%= link_to new_vehicle_path(customer_id: appointment.customer_id), class: 'icon icon-add' do %>
+ <%= l(:label_add_vehicle) %>
+ <% end %>
+
<% end %>
-
<% end %>
<% end %>
\ No newline at end of file
diff --git a/app/views/customers/_show_hook.html.erb b/app/views/customers/_show_hook.html.erb
index 57a55eb..15763cf 100644
--- a/app/views/customers/_show_hook.html.erb
+++ b/app/views/customers/_show_hook.html.erb
@@ -1,5 +1,7 @@
<%=t(:field_vehicles)%>:
<%= render partial: 'vehicles/list', locals: { vehicles: customer.vehicles.paginate(page: params[:page]), show_customer: false, show_checkbox: true } %>
- <%= button_to t(:button_new_vehicle), new_customer_vehicle_path(customer), method: :get %>
+ <% if User.current.allowed_to?(:add_vehicles, nil, global: true) %>
+ <%= button_to t(:button_new_vehicle), new_customer_vehicle_path(customer), method: :get %>
+ <% end %>
\ No newline at end of file
diff --git a/app/views/vehicles/_details.html.erb b/app/views/vehicles/_details.html.erb
index 4a0d24b..b89817a 100644
--- a/app/views/vehicles/_details.html.erb
+++ b/app/views/vehicles/_details.html.erb
@@ -54,6 +54,10 @@
<% end %>
- <%= button_to t(:label_edit), edit_vehicle_path(vehicle), method: :get %>
- <%= button_to t(:label_delete), vehicle, method: :delete, data: { confirm: t(:warn_ru_sure) } %>
+ <% if User.current.allowed_to?(:edit_vehicles, nil, global: true) %>
+ <%= button_to t(:label_edit), edit_vehicle_path(vehicle), method: :get %>
+ <% end %>
+ <% if User.current.allowed_to?(:delete_vehicles, nil, global: true) %>
+ <%= button_to t(:label_delete), vehicle, method: :delete, data: { confirm: t(:warn_ru_sure) } %>
+ <% end %>
\ No newline at end of file
diff --git a/init.rb b/init.rb
index 7cfb220..275c737 100644
--- a/init.rb
+++ b/init.rb
@@ -14,7 +14,7 @@ Redmine::Plugin.register :redmine_qbo_vehicles do
name 'Redmine QBO Vehicles plugin'
author 'Rick Barrette'
description 'This is a plugin for Redmine to intergrate with the redmine_qbo plugin to provide vehicle data tracking'
- version '2026.8.2'
+ version '2026.9.0'
url 'https://github.com/rickbarrette/redmine_qbo_vehicles'
author_url 'https://barrettefabrication.com'
requires_redmine version_or_higher: '6.1.0'
@@ -29,11 +29,15 @@ Redmine::Plugin.register :redmine_qbo_vehicles do
# Add safe attributes for core models
Issue.safe_attributes :vehicle_id
- # Permissions for security
- permission :view_vehicles, vehicles: :new, public: false
+ # Global Permissions
+ permission :view_vehicles, { vehicles: [:index, :show] }, global: true
+ permission :add_vehicles, { vehicles: [:new, :create] }, global: true
+ permission :edit_vehicles, { vehicles: [:edit, :update] }, global: true
+ permission :delete_vehicles, { vehicles: [:destroy] }, global: true
+
# Register top menu items
- menu :top_menu, :vehicles, { controller: :vehicles, action: :index }, caption: :field_vehicles, if: Proc.new { User.current.logged? }
+ menu :top_menu, :vehicles, { controller: :vehicles, action: :index }, caption: :field_vehicles, if: Proc.new { User.current.allowed_to?(:view_vehicles, nil, global: true) }
Redmine::Search.map do |search|
search.register :vehicles