ability.rb 4.6 KB
Newer Older
G
gitlabhq 已提交
1
class Ability
A
Andrey Kumanyaev 已提交
2
  class << self
3
    def allowed(user, subject)
4
      return not_auth_abilities(user, subject) if user.nil?
5
      return [] unless user.kind_of?(User)
6
      return [] if user.blocked?
7

A
Andrey Kumanyaev 已提交
8
      case subject.class.name
9 10 11
      when "Project" then project_abilities(user, subject)
      when "Issue" then issue_abilities(user, subject)
      when "Note" then note_abilities(user, subject)
12
      when "ProjectSnippet" then project_snippet_abilities(user, subject)
13
      when "PersonalSnippet" then personal_snippet_abilities(user, subject)
14
      when "MergeRequest" then merge_request_abilities(user, subject)
15 16
      when "Group" then group_abilities(user, subject)
      when "Namespace" then namespace_abilities(user, subject)
A
Andrey Kumanyaev 已提交
17
      else []
18 19 20
      end.concat(global_abilities(user))
    end

21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38
    # List of possible abilities
    # for non-authenticated user
    def not_auth_abilities(user, subject)
      project = if subject.kind_of?(Project)
                  subject
                elsif subject.respond_to?(:project)
                  subject.project
                else
                  nil
                end

      if project && project.public
        public_project_rules
      else
        []
      end
    end

39 40 41 42
    def global_abilities(user)
      rules = []
      rules << :create_group if user.can_create_group
      rules
G
gitlabhq 已提交
43 44
    end

A
Andrey Kumanyaev 已提交
45 46
    def project_abilities(user, project)
      rules = []
G
gitlabhq 已提交
47

D
Dmitriy Zaporozhets 已提交
48 49
      team = project.team

50
      # Rules based on role in project
D
Dmitriy Zaporozhets 已提交
51
      if team.masters.include?(user)
52
        rules << project_master_rules
53

D
Dmitriy Zaporozhets 已提交
54
      elsif team.developers.include?(user)
55 56
        rules << project_dev_rules

D
Dmitriy Zaporozhets 已提交
57
      elsif team.reporters.include?(user)
58 59
        rules << project_report_rules

60
      elsif team.guests.include?(user)
61 62 63
        rules << project_guest_rules
      end

64 65 66 67
      if project.public?
        rules << public_project_rules
      end

68
      if project.owner == user || user.admin?
69
        rules << project_admin_rules
70 71
      end

72 73 74 75
      if project.group && project.group.owners.include?(user)
        rules << project_admin_rules
      end

76 77 78
      rules.flatten
    end

79
    def public_project_rules
80
      project_guest_rules + [
81 82 83 84 85
        :download_code,
        :fork_project,
      ]
    end

86 87
    def project_guest_rules
      [
A
Andrey Kumanyaev 已提交
88 89 90 91
        :read_project,
        :read_wiki,
        :read_issue,
        :read_milestone,
A
Andrew8xx8 已提交
92
        :read_project_snippet,
A
Andrey Kumanyaev 已提交
93 94 95 96 97
        :read_team_member,
        :read_merge_request,
        :read_note,
        :write_project,
        :write_issue,
98
        :write_note
99 100
      ]
    end
D
Dmitriy Zaporozhets 已提交
101

102 103
    def project_report_rules
      project_guest_rules + [
A
Andrey Kumanyaev 已提交
104
        :download_code,
105
        :fork_project,
A
Andrew8xx8 已提交
106
        :write_project_snippet
107 108
      ]
    end
D
Dmitriy Zaporozhets 已提交
109

110 111
    def project_dev_rules
      project_report_rules + [
112
        :write_merge_request,
113 114
        :write_wiki,
        :push_code
115 116
      ]
    end
117

118 119 120
    def project_master_rules
      project_dev_rules + [
        :push_code_to_protected_branches,
A
Andrey Kumanyaev 已提交
121
        :modify_issue,
A
Andrew8xx8 已提交
122
        :modify_project_snippet,
A
Andrey Kumanyaev 已提交
123 124 125
        :modify_merge_request,
        :admin_issue,
        :admin_milestone,
A
Andrew8xx8 已提交
126
        :admin_project_snippet,
A
Andrey Kumanyaev 已提交
127 128 129
        :admin_team_member,
        :admin_merge_request,
        :admin_note,
130 131
        :admin_wiki,
        :admin_project
132 133
      ]
    end
G
gitlabhq 已提交
134

135 136
    def project_admin_rules
      project_master_rules + [
137
        :change_namespace,
138
        :change_public_mode,
139 140
        :rename_project,
        :remove_project
141
      ]
A
Andrey Kumanyaev 已提交
142
    end
G
gitlabhq 已提交
143

144 145 146
    def group_abilities user, group
      rules = []

147 148 149 150
      if group.users.include?(user)
        rules << :read_group
      end

151
      # Only group owner and administrators can manage group
152
      if group.owners.include?(user) || user.admin?
153
        rules << [
154 155
          :manage_group,
          :manage_namespace
156 157
        ]
      end
158 159 160 161

      rules.flatten
    end

162 163 164 165 166 167 168 169 170 171 172 173 174
    def namespace_abilities user, namespace
      rules = []

      # Only namespace owner and administrators can manage it
      if namespace.owner == user || user.admin?
        rules << [
          :manage_namespace
        ]
      end

      rules.flatten
    end

175
    [:issue, :note, :project_snippet, :personal_snippet, :merge_request].each do |name|
G
gitlabhq 已提交
176 177 178 179 180
      define_method "#{name}_abilities" do |user, subject|
        if subject.author == user
          [
            :"read_#{name}",
            :"write_#{name}",
D
Dmitriy Zaporozhets 已提交
181
            :"modify_#{name}",
G
gitlabhq 已提交
182 183
            :"admin_#{name}"
          ]
184 185 186 187 188 189
        elsif subject.respond_to?(:assignee) && subject.assignee == user
          [
            :"read_#{name}",
            :"write_#{name}",
            :"modify_#{name}",
          ]
G
gitlabhq 已提交
190
        else
A
Andrey Kumanyaev 已提交
191
          subject.respond_to?(:project) ? project_abilities(user, subject.project) : []
G
gitlabhq 已提交
192 193 194 195
        end
      end
    end
  end
G
gitlabhq 已提交
196
end