ability.rb 5.7 KB
Newer Older
G
gitlabhq 已提交
1
class Ability
A
Andrey Kumanyaev 已提交
2
  class << self
3
    def allowed(user, subject)
4
      return not_auth_abilities(user, subject) if user.nil?
5
      return [] unless user.kind_of?(User)
6
      return [] if user.blocked?
7

A
Andrey Kumanyaev 已提交
8
      case subject.class.name
9 10 11
      when "Project" then project_abilities(user, subject)
      when "Issue" then issue_abilities(user, subject)
      when "Note" then note_abilities(user, subject)
12
      when "ProjectSnippet" then project_snippet_abilities(user, subject)
13
      when "PersonalSnippet" then personal_snippet_abilities(user, subject)
14
      when "MergeRequest" then merge_request_abilities(user, subject)
15 16
      when "Group" then group_abilities(user, subject)
      when "Namespace" then namespace_abilities(user, subject)
17
      when "UsersGroup" then users_group_abilities(user, subject)
A
Andrey Kumanyaev 已提交
18
      else []
19 20 21
      end.concat(global_abilities(user))
    end

22 23 24 25 26 27 28 29 30 31 32
    # List of possible abilities
    # for non-authenticated user
    def not_auth_abilities(user, subject)
      project = if subject.kind_of?(Project)
                  subject
                elsif subject.respond_to?(:project)
                  subject.project
                else
                  nil
                end

33
      if project && project.public?
34 35 36 37 38 39 40 41 42 43 44
        [
          :read_project,
          :read_wiki,
          :read_issue,
          :read_milestone,
          :read_project_snippet,
          :read_team_member,
          :read_merge_request,
          :read_note,
          :download_code
        ]
45 46 47 48 49
      else
        []
      end
    end

50 51 52 53
    def global_abilities(user)
      rules = []
      rules << :create_group if user.can_create_group
      rules
G
gitlabhq 已提交
54 55
    end

A
Andrey Kumanyaev 已提交
56 57
    def project_abilities(user, project)
      rules = []
G
gitlabhq 已提交
58

D
Dmitriy Zaporozhets 已提交
59 60
      team = project.team

61
      # Rules based on role in project
D
Dmitriy Zaporozhets 已提交
62
      if team.masters.include?(user)
63
        rules += project_master_rules
64

D
Dmitriy Zaporozhets 已提交
65
      elsif team.developers.include?(user)
66
        rules += project_dev_rules
67

D
Dmitriy Zaporozhets 已提交
68
      elsif team.reporters.include?(user)
69
        rules += project_report_rules
70

71
      elsif team.guests.include?(user)
72
        rules += project_guest_rules
73 74
      end

75
      if project.public? || project.internal?
76
        rules += public_project_rules
77 78
      end

79
      if project.owner == user || user.admin?
80
        rules += project_admin_rules
81 82
      end

83
      if project.group && project.group.has_owner?(user)
84
        rules += project_admin_rules
85 86
      end

87 88 89 90 91
      if project.archived?
        rules -= project_archived_rules
      end

      rules
92 93
    end

94
    def public_project_rules
95
      project_guest_rules + [
96
        :download_code,
97
        :fork_project
98 99 100
      ]
    end

101 102
    def project_guest_rules
      [
A
Andrey Kumanyaev 已提交
103 104 105 106
        :read_project,
        :read_wiki,
        :read_issue,
        :read_milestone,
A
Andrew8xx8 已提交
107
        :read_project_snippet,
A
Andrey Kumanyaev 已提交
108 109 110 111 112
        :read_team_member,
        :read_merge_request,
        :read_note,
        :write_project,
        :write_issue,
113
        :write_note
114 115
      ]
    end
D
Dmitriy Zaporozhets 已提交
116

117 118
    def project_report_rules
      project_guest_rules + [
A
Andrey Kumanyaev 已提交
119
        :download_code,
120
        :fork_project,
A
Andrew8xx8 已提交
121
        :write_project_snippet
122 123
      ]
    end
D
Dmitriy Zaporozhets 已提交
124

125 126
    def project_dev_rules
      project_report_rules + [
127
        :write_merge_request,
128
        :write_wiki,
129
        :modify_issue,
D
Dmitriy Zaporozhets 已提交
130
        :admin_issue,
131
        :push_code
132 133
      ]
    end
134

135 136 137 138 139 140 141 142 143 144
    def project_archived_rules
      [
        :write_merge_request,
        :push_code,
        :push_code_to_protected_branches,
        :modify_merge_request,
        :admin_merge_request
      ]
    end

145 146 147
    def project_master_rules
      project_dev_rules + [
        :push_code_to_protected_branches,
A
Andrey Kumanyaev 已提交
148
        :modify_issue,
A
Andrew8xx8 已提交
149
        :modify_project_snippet,
A
Andrey Kumanyaev 已提交
150 151 152
        :modify_merge_request,
        :admin_issue,
        :admin_milestone,
A
Andrew8xx8 已提交
153
        :admin_project_snippet,
A
Andrey Kumanyaev 已提交
154 155 156
        :admin_team_member,
        :admin_merge_request,
        :admin_note,
157 158
        :admin_wiki,
        :admin_project
159 160
      ]
    end
G
gitlabhq 已提交
161

162 163
    def project_admin_rules
      project_master_rules + [
164
        :change_namespace,
165
        :change_visibility_level,
166
        :rename_project,
167 168
        :remove_project,
        :archive_project
169
      ]
A
Andrey Kumanyaev 已提交
170
    end
G
gitlabhq 已提交
171

172 173 174
    def group_abilities user, group
      rules = []

175
      if group.users.include?(user) || user.admin?
176 177 178
        rules << :read_group
      end

179
      # Only group owner and administrators can manage group
180
      if group.has_owner?(user) || user.admin?
181
        rules += [
182 183
          :manage_group,
          :manage_namespace
184 185
        ]
      end
186 187 188 189

      rules.flatten
    end

190 191 192 193 194
    def namespace_abilities user, namespace
      rules = []

      # Only namespace owner and administrators can manage it
      if namespace.owner == user || user.admin?
195
        rules += [
196 197 198 199 200 201 202
          :manage_namespace
        ]
      end

      rules.flatten
    end

203
    [:issue, :note, :project_snippet, :personal_snippet, :merge_request].each do |name|
G
gitlabhq 已提交
204 205 206 207 208
      define_method "#{name}_abilities" do |user, subject|
        if subject.author == user
          [
            :"read_#{name}",
            :"write_#{name}",
D
Dmitriy Zaporozhets 已提交
209
            :"modify_#{name}",
G
gitlabhq 已提交
210 211
            :"admin_#{name}"
          ]
212 213 214 215 216 217
        elsif subject.respond_to?(:assignee) && subject.assignee == user
          [
            :"read_#{name}",
            :"write_#{name}",
            :"modify_#{name}",
          ]
G
gitlabhq 已提交
218
        else
A
Andrey Kumanyaev 已提交
219
          subject.respond_to?(:project) ? project_abilities(user, subject.project) : []
G
gitlabhq 已提交
220 221 222
        end
      end
    end
223 224 225 226 227 228 229 230 231 232 233 234 235 236

    def users_group_abilities(user, subject)
      rules = []
      target_user = subject.user
      group = subject.group
      can_manage = group_abilities(user, group).include?(:manage_group)
      if can_manage && (user != target_user)
        rules << :modify
      end
      if !group.last_owner?(user) && (can_manage || (user == target_user))
        rules << :destroy
      end
      rules
    end
G
gitlabhq 已提交
237
  end
G
gitlabhq 已提交
238
end