Implement global permissions for vehicle actions and update version to 2026.9.0

This commit is contained in:
ricky committed 2026-09-08 22:56:47 -04:00
1 parent 849dcabff7
commit df41436e61
5 files changed
+18 -4

No files matched your search

+2
View File
@@ -13,6 +13,8 @@ class VehiclesController < ApplicationController
include AuthHelper
# This tells Redmine to check global permissions for the current controller/action
before_action :authorize_global
before_action :require_user
def allowed_params
@@ -1,3 +1,4 @@
<% if <% if User.current.allowed_to?(:add_vehicles, nil, global: true) %> %>
<% if appointment.customer.present? %>
<% unless appointment.vehicle.present? &&%>
<p>
@@ -7,3 +8,4 @@
</p>
<% end %>
<% end %>
<% end %>
+2
View File
@@ -1,5 +1,7 @@
<h4><%=t(:field_vehicles)%>:</h4>
<%= render partial: 'vehicles/list', locals: { vehicles: customer.vehicles.paginate(page: params[:page]), show_customer: false, show_checkbox: true } %>
<div style="float: right;">
<% if User.current.allowed_to?(:add_vehicles, nil, global: true) %>
<%= button_to t(:button_new_vehicle), new_customer_vehicle_path(customer), method: :get %>
<% end %>
</div>
+4
View File
@@ -54,6 +54,10 @@
<% end %>
<div style="float: right;">
<% if User.current.allowed_to?(:edit_vehicles, nil, global: true) %>
<%= button_to t(:label_edit), edit_vehicle_path(vehicle), method: :get %>
<% end %>
<% if User.current.allowed_to?(:delete_vehicles, nil, global: true) %>
<%= button_to t(:label_delete), vehicle, method: :delete, data: { confirm: t(:warn_ru_sure) } %>
<% end %>
</div>
+8 -4
View File
@@ -14,7 +14,7 @@ Redmine::Plugin.register :redmine_qbo_vehicles do
name 'Redmine QBO Vehicles plugin'
author 'Rick Barrette'
description 'This is a plugin for Redmine to intergrate with the redmine_qbo plugin to provide vehicle data tracking'
version '2026.8.2'
version '2026.9.0'
url 'https://github.com/rickbarrette/redmine_qbo_vehicles'
author_url 'https://barrettefabrication.com'
requires_redmine version_or_higher: '6.1.0'
@@ -29,11 +29,15 @@ Redmine::Plugin.register :redmine_qbo_vehicles do
# Add safe attributes for core models
Issue.safe_attributes :vehicle_id
# Permissions for security
permission :view_vehicles, vehicles: :new, public: false
# Global Permissions
permission :view_vehicles, { vehicles: [:index, :show] }, global: true
permission :add_vehicles, { vehicles: [:new, :create] }, global: true
permission :edit_vehicles, { vehicles: [:edit, :update] }, global: true
permission :delete_vehicles, { vehicles: [:destroy] }, global: true
# Register top menu items
menu :top_menu, :vehicles, { controller: :vehicles, action: :index }, caption: :field_vehicles, if: Proc.new { User.current.logged? }
menu :top_menu, :vehicles, { controller: :vehicles, action: :index }, caption: :field_vehicles, if: Proc.new { User.current.allowed_to?(:view_vehicles, nil, global: true) }
Redmine::Search.map do |search|
search.register :vehicles