ability.rb 7.7 KB
Newer Older
G
gitlabhq 已提交
1
class Ability
A
Andrey Kumanyaev 已提交
2
  class << self
3
    def allowed(user, subject)
4
      return not_auth_abilities(user, subject) if user.nil?
5
      return [] unless user.kind_of?(User)
6
      return [] if user.blocked?
7

A
Andrey Kumanyaev 已提交
8
      case subject.class.name
9 10 11
      when "Project" then project_abilities(user, subject)
      when "Issue" then issue_abilities(user, subject)
      when "Note" then note_abilities(user, subject)
12
      when "ProjectSnippet" then project_snippet_abilities(user, subject)
13
      when "PersonalSnippet" then personal_snippet_abilities(user, subject)
14
      when "MergeRequest" then merge_request_abilities(user, subject)
15 16
      when "Group" then group_abilities(user, subject)
      when "Namespace" then namespace_abilities(user, subject)
17
      when "GroupMember" then group_member_abilities(user, subject)
A
Andrey Kumanyaev 已提交
18
      else []
19 20 21
      end.concat(global_abilities(user))
    end

22 23 24 25 26 27 28 29 30 31 32
    # List of possible abilities
    # for non-authenticated user
    def not_auth_abilities(user, subject)
      project = if subject.kind_of?(Project)
                  subject
                elsif subject.respond_to?(:project)
                  subject.project
                else
                  nil
                end

33
      if project && project.public?
34 35 36 37 38 39
        [
          :read_project,
          :read_wiki,
          :read_issue,
          :read_milestone,
          :read_project_snippet,
40
          :read_project_member,
41 42 43 44
          :read_merge_request,
          :read_note,
          :download_code
        ]
45
      else
46 47 48 49 50 51 52
        group = if subject.kind_of?(Group)
                  subject
                elsif subject.respond_to?(:group)
                  subject.group
                else
                  nil
                end
53

54
        if group && group.public_profile?
55 56 57 58
          [:read_group]
        else
          []
        end
59 60 61
      end
    end

62 63 64 65
    def global_abilities(user)
      rules = []
      rules << :create_group if user.can_create_group
      rules
G
gitlabhq 已提交
66 67
    end

A
Andrey Kumanyaev 已提交
68 69
    def project_abilities(user, project)
      rules = []
S
skv-headless 已提交
70
      key = "/user/#{user.id}/project/#{project.id}"
71

S
skv-headless 已提交
72 73
      RequestStore.store[key] ||= begin
        team = project.team
G
gitlabhq 已提交
74

S
skv-headless 已提交
75 76
        # Rules based on role in project
        if team.master?(user)
77
          rules.push(*project_master_rules)
D
Dmitriy Zaporozhets 已提交
78

S
skv-headless 已提交
79
        elsif team.developer?(user)
80
          rules.push(*project_dev_rules)
81

S
skv-headless 已提交
82
        elsif team.reporter?(user)
83
          rules.push(*project_report_rules)
84

S
skv-headless 已提交
85
        elsif team.guest?(user)
86
          rules.push(*project_guest_rules)
S
skv-headless 已提交
87
        end
88

S
skv-headless 已提交
89
        if project.public? || project.internal?
90
          rules.push(*public_project_rules)
S
skv-headless 已提交
91
        end
92

S
skv-headless 已提交
93
        if project.owner == user || user.admin?
94
          rules.push(*project_admin_rules)
S
skv-headless 已提交
95
        end
96

S
skv-headless 已提交
97
        if project.group && project.group.has_owner?(user)
98
          rules.push(*project_admin_rules)
S
skv-headless 已提交
99
        end
100

S
skv-headless 已提交
101 102 103
        if project.archived?
          rules -= project_archived_rules
        end
104

105 106 107 108 109 110 111 112
        unless project.issues_enabled
          rules -= named_abilities('issue')
        end

        unless project.merge_requests_enabled
          rules -= named_abilities('merge_request')
        end

113 114 115 116 117
        unless project.issues_enabled or project.merge_requests_enabled
          rules -= named_abilities('label')
          rules -= named_abilities('milestone')
        end

118
        unless project.snippets_enabled
119
          rules -= named_abilities('project_snippet')
120 121 122 123 124 125
        end

        unless project.wiki_enabled
          rules -= named_abilities('wiki')
        end

S
skv-headless 已提交
126
        rules
127
      end
128 129
    end

130
    def public_project_rules
131
      project_guest_rules + [
132
        :download_code,
133
        :fork_project
134 135 136
      ]
    end

137 138
    def project_guest_rules
      [
A
Andrey Kumanyaev 已提交
139 140 141
        :read_project,
        :read_wiki,
        :read_issue,
142
        :read_label,
A
Andrey Kumanyaev 已提交
143
        :read_milestone,
A
Andrew8xx8 已提交
144
        :read_project_snippet,
145
        :read_project_member,
A
Andrey Kumanyaev 已提交
146 147
        :read_merge_request,
        :read_note,
148 149 150
        :create_project,
        :create_issue,
        :create_note
151 152
      ]
    end
D
Dmitriy Zaporozhets 已提交
153

154 155
    def project_report_rules
      project_guest_rules + [
A
Andrey Kumanyaev 已提交
156
        :download_code,
157
        :fork_project,
158
        :create_project_snippet
159 160
      ]
    end
D
Dmitriy Zaporozhets 已提交
161

162 163
    def project_dev_rules
      project_report_rules + [
164 165 166
        :create_merge_request,
        :create_wiki,
        :update_issue,
D
Dmitriy Zaporozhets 已提交
167
        :admin_issue,
D
Dmitriy Zaporozhets 已提交
168
        :admin_label,
169
        :push_code
170 171
      ]
    end
172

173 174
    def project_archived_rules
      [
175
        :create_merge_request,
176 177
        :push_code,
        :push_code_to_protected_branches,
178
        :update_merge_request,
179 180 181 182
        :admin_merge_request
      ]
    end

183 184 185
    def project_master_rules
      project_dev_rules + [
        :push_code_to_protected_branches,
186 187
        :update_project_snippet,
        :update_merge_request,
A
Andrey Kumanyaev 已提交
188
        :admin_milestone,
A
Andrew8xx8 已提交
189
        :admin_project_snippet,
190
        :admin_project_member,
A
Andrey Kumanyaev 已提交
191 192
        :admin_merge_request,
        :admin_note,
193 194
        :admin_wiki,
        :admin_project
195 196
      ]
    end
G
gitlabhq 已提交
197

198 199
    def project_admin_rules
      project_master_rules + [
200
        :change_namespace,
201
        :change_visibility_level,
202
        :rename_project,
203 204
        :remove_project,
        :archive_project
205
      ]
A
Andrey Kumanyaev 已提交
206
    end
G
gitlabhq 已提交
207

208
    def group_abilities(user, group)
209 210
      rules = []

211
      if user.admin? || group.users.include?(user) || ProjectsFinder.new.execute(user, group: group).any?
212 213 214
        rules << :read_group
      end

215 216
      # Only group masters and group owners can create new projects in group
      if group.has_master?(user) || group.has_owner?(user) || user.admin?
217
        rules.push(*[
218
          :create_projects,
219
        ])
220 221
      end

222
      # Only group owner and administrators can admin group
223
      if group.has_owner?(user) || user.admin?
224
        rules.push(*[
225 226
          :admin_group,
          :admin_namespace
227
        ])
228
      end
229 230 231 232

      rules.flatten
    end

233
    def namespace_abilities(user, namespace)
234 235
      rules = []

236
      # Only namespace owner and administrators can admin it
237
      if namespace.owner == user || user.admin?
238
        rules.push(*[
239
          :create_projects,
240
          :admin_namespace
241
        ])
242 243 244 245 246
      end

      rules.flatten
    end

247 248

    [:issue, :merge_request].each do |name|
G
gitlabhq 已提交
249
      define_method "#{name}_abilities" do |user, subject|
250 251 252 253
        rules = []

        if subject.author == user || (subject.respond_to?(:assignee) && subject.assignee == user)
          rules += [
G
gitlabhq 已提交
254
            :"read_#{name}",
255
            :"update_#{name}",
G
gitlabhq 已提交
256
          ]
257 258 259 260 261 262 263 264 265 266 267 268 269
        end

        rules += project_abilities(user, subject.project)
        rules
      end
    end

    [:note, :project_snippet, :personal_snippet].each do |name|
      define_method "#{name}_abilities" do |user, subject|
        rules = []

        if subject.author == user
          rules += [
270
            :"read_#{name}",
271
            :"update_#{name}",
272
            :"admin_#{name}"
273
          ]
G
gitlabhq 已提交
274
        end
275 276 277 278 279 280

        if subject.respond_to?(:project) && subject.project
          rules += project_abilities(user, subject.project)
        end

        rules
G
gitlabhq 已提交
281 282
      end
    end
283

284
    def group_member_abilities(user, subject)
285 286 287
      rules = []
      target_user = subject.user
      group = subject.group
288
      can_manage = group_abilities(user, group).include?(:admin_group)
289

290
      if can_manage && (user != target_user)
291
        rules << :update_group_member
292
        rules << :destroy_group_member
293
      end
294

295
      if !group.last_owner?(user) && (can_manage || (user == target_user))
296
        rules << :destroy_group_member
297
      end
298

299 300
      rules
    end
C
Ciro Santilli 已提交
301 302 303 304 305 306 307 308

    def abilities
      @abilities ||= begin
                       abilities = Six.new
                       abilities << self
                       abilities
                     end
    end
309 310 311 312 313 314

    private

    def named_abilities(name)
      [
        :"read_#{name}",
315 316
        :"create_#{name}",
        :"update_#{name}",
317 318 319
        :"admin_#{name}"
      ]
    end
G
gitlabhq 已提交
320
  end
G
gitlabhq 已提交
321
end