ability.rb 3.1 KB
Newer Older
G
gitlabhq 已提交
1
class Ability
A
Andrey Kumanyaev 已提交
2 3 4 5 6 7 8 9
  class << self
    def allowed(object, subject)
      case subject.class.name
      when "Project" then project_abilities(object, subject)
      when "Issue" then issue_abilities(object, subject)
      when "Note" then note_abilities(object, subject)
      when "Snippet" then snippet_abilities(object, subject)
      when "MergeRequest" then merge_request_abilities(object, subject)
10
      when "Group", "Namespace" then group_abilities(object, subject)
A
Andrey Kumanyaev 已提交
11 12
      else []
      end
G
gitlabhq 已提交
13 14
    end

A
Andrey Kumanyaev 已提交
15 16
    def project_abilities(user, project)
      rules = []
G
gitlabhq 已提交
17

D
Dmitriy Zaporozhets 已提交
18 19
      team = project.team

20
      # Rules based on role in project
D
Dmitriy Zaporozhets 已提交
21
      if team.masters.include?(user)
22
        rules << project_master_rules
23

D
Dmitriy Zaporozhets 已提交
24
      elsif team.developers.include?(user)
25 26
        rules << project_dev_rules

D
Dmitriy Zaporozhets 已提交
27
      elsif team.reporters.include?(user)
28 29
        rules << project_report_rules

D
Dmitriy Zaporozhets 已提交
30
      elsif team.guests.include?(user)
31 32 33
        rules << project_guest_rules
      end

34 35
      if project.owner == user
        rules << project_admin_rules
36 37 38 39 40 41 42
      end

      rules.flatten
    end

    def project_guest_rules
      [
A
Andrey Kumanyaev 已提交
43 44 45 46 47 48 49 50 51 52 53
        :read_project,
        :read_wiki,
        :read_issue,
        :read_milestone,
        :read_snippet,
        :read_team_member,
        :read_merge_request,
        :read_note,
        :write_project,
        :write_issue,
        :write_note
54 55
      ]
    end
D
Dmitriy Zaporozhets 已提交
56

57 58
    def project_report_rules
      project_guest_rules + [
A
Andrey Kumanyaev 已提交
59 60
        :download_code,
        :write_snippet
61 62
      ]
    end
D
Dmitriy Zaporozhets 已提交
63

64 65
    def project_dev_rules
      project_report_rules + [
66
        :write_merge_request,
67 68
        :write_wiki,
        :push_code
69 70
      ]
    end
71

72 73 74
    def project_master_rules
      project_dev_rules + [
        :push_code_to_protected_branches,
A
Andrey Kumanyaev 已提交
75 76 77 78 79 80 81 82 83 84
        :modify_issue,
        :modify_snippet,
        :modify_merge_request,
        :admin_issue,
        :admin_milestone,
        :admin_snippet,
        :admin_team_member,
        :admin_merge_request,
        :admin_note,
        :accept_mr,
85 86
        :admin_wiki,
        :admin_project
87 88
      ]
    end
G
gitlabhq 已提交
89

90 91
    def project_admin_rules
      project_master_rules + [
92
        :change_namespace,
93
        :change_public_mode,
94 95
        :rename_project,
        :remove_project
96
      ]
A
Andrey Kumanyaev 已提交
97
    end
G
gitlabhq 已提交
98

99 100 101
    def group_abilities user, group
      rules = []

102 103 104
      # Only group owner and administrators can manage group
      if group.owner == user || user.admin?
        rules << [
105 106
          :manage_group,
          :manage_namespace
107 108
        ]
      end
109 110 111 112

      rules.flatten
    end

D
Dmitriy Zaporozhets 已提交
113
    [:issue, :note, :snippet, :merge_request].each do |name|
G
gitlabhq 已提交
114 115 116 117 118
      define_method "#{name}_abilities" do |user, subject|
        if subject.author == user
          [
            :"read_#{name}",
            :"write_#{name}",
D
Dmitriy Zaporozhets 已提交
119
            :"modify_#{name}",
G
gitlabhq 已提交
120 121
            :"admin_#{name}"
          ]
122 123 124 125 126 127
        elsif subject.respond_to?(:assignee) && subject.assignee == user
          [
            :"read_#{name}",
            :"write_#{name}",
            :"modify_#{name}",
          ]
G
gitlabhq 已提交
128
        else
A
Andrey Kumanyaev 已提交
129
          subject.respond_to?(:project) ? project_abilities(user, subject.project) : []
G
gitlabhq 已提交
130 131 132 133
        end
      end
    end
  end
G
gitlabhq 已提交
134
end