Implement global permissions for vehicle actions and update version to 2026.9.0

This commit is contained in:
ricky committed 2026-09-08 22:56:47 -04:00
1 parent 849dcabff7
commit df41436e61
5 files changed
+27 -13

No files matched your search

+2
View File
@@ -13,6 +13,8 @@ class VehiclesController < ApplicationController
include AuthHelper
# This tells Redmine to check global permissions for the current controller/action
before_action :authorize_global
before_action :require_user
def allowed_params
@@ -1,9 +1,11 @@
<% if appointment.customer.present? %>
<% unless appointment.vehicle.present? &&%>
<p>
<%= link_to new_vehicle_path(customer_id: appointment.customer_id), class: 'icon icon-add' do %>
<%= l(:label_add_vehicle) %>
<% if <% if User.current.allowed_to?(:add_vehicles, nil, global: true) %> %>
<% if appointment.customer.present? %>
<% unless appointment.vehicle.present? &&%>
<p>
<%= link_to new_vehicle_path(customer_id: appointment.customer_id), class: 'icon icon-add' do %>
<%= l(:label_add_vehicle) %>
<% end %>
</p>
<% end %>
</p>
<% end %>
<% end %>
+3 -1
View File
@@ -1,5 +1,7 @@
<h4><%=t(:field_vehicles)%>:</h4>
<%= render partial: 'vehicles/list', locals: { vehicles: customer.vehicles.paginate(page: params[:page]), show_customer: false, show_checkbox: true } %>
<div style="float: right;">
<%= button_to t(:button_new_vehicle), new_customer_vehicle_path(customer), method: :get %>
<% if User.current.allowed_to?(:add_vehicles, nil, global: true) %>
<%= button_to t(:button_new_vehicle), new_customer_vehicle_path(customer), method: :get %>
<% end %>
</div>
+6 -2
View File
@@ -54,6 +54,10 @@
<% end %>
<div style="float: right;">
<%= button_to t(:label_edit), edit_vehicle_path(vehicle), method: :get %>
<%= button_to t(:label_delete), vehicle, method: :delete, data: { confirm: t(:warn_ru_sure) } %>
<% if User.current.allowed_to?(:edit_vehicles, nil, global: true) %>
<%= button_to t(:label_edit), edit_vehicle_path(vehicle), method: :get %>
<% end %>
<% if User.current.allowed_to?(:delete_vehicles, nil, global: true) %>
<%= button_to t(:label_delete), vehicle, method: :delete, data: { confirm: t(:warn_ru_sure) } %>
<% end %>
</div>