ability.rb 6.9 KB
Newer Older
G
gitlabhq 已提交
1
class Ability
A
Andrey Kumanyaev 已提交
2
  class << self
3
    def allowed(user, subject)
4
      return not_auth_abilities(user, subject) if user.nil?
5
      return [] unless user.kind_of?(User)
6
      return [] if user.blocked?
7

A
Andrey Kumanyaev 已提交
8
      case subject.class.name
9 10 11
      when "Project" then project_abilities(user, subject)
      when "Issue" then issue_abilities(user, subject)
      when "Note" then note_abilities(user, subject)
12
      when "ProjectSnippet" then project_snippet_abilities(user, subject)
13
      when "PersonalSnippet" then personal_snippet_abilities(user, subject)
14
      when "MergeRequest" then merge_request_abilities(user, subject)
15 16
      when "Group" then group_abilities(user, subject)
      when "Namespace" then namespace_abilities(user, subject)
17
      when "GroupMember" then group_member_abilities(user, subject)
A
Andrey Kumanyaev 已提交
18
      else []
19 20 21
      end.concat(global_abilities(user))
    end

22 23 24 25 26 27 28 29 30 31 32
    # List of possible abilities
    # for non-authenticated user
    def not_auth_abilities(user, subject)
      project = if subject.kind_of?(Project)
                  subject
                elsif subject.respond_to?(:project)
                  subject.project
                else
                  nil
                end

33
      if project && project.public?
34 35 36 37 38 39
        [
          :read_project,
          :read_wiki,
          :read_issue,
          :read_milestone,
          :read_project_snippet,
40
          :read_project_member,
41 42 43 44
          :read_merge_request,
          :read_note,
          :download_code
        ]
45
      else
46 47 48 49 50 51 52
        group = if subject.kind_of?(Group)
                  subject
                elsif subject.respond_to?(:group)
                  subject.group
                else
                  nil
                end
53

54
        if group && group.public_profile?
55 56 57 58
          [:read_group]
        else
          []
        end
59 60 61
      end
    end

62 63 64 65
    def global_abilities(user)
      rules = []
      rules << :create_group if user.can_create_group
      rules
G
gitlabhq 已提交
66 67
    end

A
Andrey Kumanyaev 已提交
68 69
    def project_abilities(user, project)
      rules = []
S
skv-headless 已提交
70 71 72
      key = "/user/#{user.id}/project/#{project.id}"
      RequestStore.store[key] ||= begin
        team = project.team
G
gitlabhq 已提交
73

S
skv-headless 已提交
74 75
        # Rules based on role in project
        if team.master?(user)
76
          rules.push(*project_master_rules)
D
Dmitriy Zaporozhets 已提交
77

S
skv-headless 已提交
78
        elsif team.developer?(user)
79
          rules.push(*project_dev_rules)
80

S
skv-headless 已提交
81
        elsif team.reporter?(user)
82
          rules.push(*project_report_rules)
83

S
skv-headless 已提交
84
        elsif team.guest?(user)
85
          rules.push(*project_guest_rules)
S
skv-headless 已提交
86
        end
87

S
skv-headless 已提交
88
        if project.public? || project.internal?
89
          rules.push(*public_project_rules)
S
skv-headless 已提交
90
        end
91

S
skv-headless 已提交
92
        if project.owner == user || user.admin?
93
          rules.push(*project_admin_rules)
S
skv-headless 已提交
94
        end
95

S
skv-headless 已提交
96
        if project.group && project.group.has_owner?(user)
97
          rules.push(*project_admin_rules)
S
skv-headless 已提交
98
        end
99

S
skv-headless 已提交
100 101 102
        if project.archived?
          rules -= project_archived_rules
        end
103

S
skv-headless 已提交
104
        rules
105
      end
106 107
    end

108
    def public_project_rules
109
      project_guest_rules + [
110
        :download_code,
111
        :fork_project
112 113 114
      ]
    end

115 116
    def project_guest_rules
      [
A
Andrey Kumanyaev 已提交
117 118 119 120
        :read_project,
        :read_wiki,
        :read_issue,
        :read_milestone,
A
Andrew8xx8 已提交
121
        :read_project_snippet,
122
        :read_project_member,
A
Andrey Kumanyaev 已提交
123 124 125 126
        :read_merge_request,
        :read_note,
        :write_project,
        :write_issue,
127
        :write_note
128 129
      ]
    end
D
Dmitriy Zaporozhets 已提交
130

131 132
    def project_report_rules
      project_guest_rules + [
A
Andrey Kumanyaev 已提交
133
        :download_code,
134
        :fork_project,
A
Andrew8xx8 已提交
135
        :write_project_snippet
136 137
      ]
    end
D
Dmitriy Zaporozhets 已提交
138

139 140
    def project_dev_rules
      project_report_rules + [
141
        :write_merge_request,
142
        :write_wiki,
143
        :modify_issue,
D
Dmitriy Zaporozhets 已提交
144
        :admin_issue,
D
Dmitriy Zaporozhets 已提交
145
        :admin_label,
146
        :push_code
147 148
      ]
    end
149

150 151 152 153 154 155 156 157 158 159
    def project_archived_rules
      [
        :write_merge_request,
        :push_code,
        :push_code_to_protected_branches,
        :modify_merge_request,
        :admin_merge_request
      ]
    end

160 161 162
    def project_master_rules
      project_dev_rules + [
        :push_code_to_protected_branches,
A
Andrey Kumanyaev 已提交
163
        :modify_issue,
A
Andrew8xx8 已提交
164
        :modify_project_snippet,
A
Andrey Kumanyaev 已提交
165 166 167
        :modify_merge_request,
        :admin_issue,
        :admin_milestone,
A
Andrew8xx8 已提交
168
        :admin_project_snippet,
169
        :admin_project_member,
A
Andrey Kumanyaev 已提交
170 171
        :admin_merge_request,
        :admin_note,
172 173
        :admin_wiki,
        :admin_project
174 175
      ]
    end
G
gitlabhq 已提交
176

177 178
    def project_admin_rules
      project_master_rules + [
179
        :change_namespace,
180
        :change_visibility_level,
181
        :rename_project,
182 183
        :remove_project,
        :archive_project
184
      ]
A
Andrey Kumanyaev 已提交
185
    end
G
gitlabhq 已提交
186

187
    def group_abilities(user, group)
188 189
      rules = []

190
      if user.admin? || group.users.include?(user) || ProjectsFinder.new.execute(user, group: group).any?
191 192 193
        rules << :read_group
      end

194 195
      # Only group masters and group owners can create new projects in group
      if group.has_master?(user) || group.has_owner?(user) || user.admin?
196
        rules.push(*[
197
          :create_projects,
198
        ])
199 200
      end

201
      # Only group owner and administrators can manage group
202
      if group.has_owner?(user) || user.admin?
203
        rules.push(*[
204 205
          :manage_group,
          :manage_namespace
206
        ])
207
      end
208 209 210 211

      rules.flatten
    end

212
    def namespace_abilities(user, namespace)
213 214 215 216
      rules = []

      # Only namespace owner and administrators can manage it
      if namespace.owner == user || user.admin?
217
        rules.push(*[
218
          :create_projects,
219
          :manage_namespace
220
        ])
221 222 223 224 225
      end

      rules.flatten
    end

226
    [:issue, :note, :project_snippet, :personal_snippet, :merge_request].each do |name|
G
gitlabhq 已提交
227
      define_method "#{name}_abilities" do |user, subject|
V
Vinnie Okada 已提交
228 229
        if subject.author == user || user.is_admin?
          rules = [
G
gitlabhq 已提交
230 231
            :"read_#{name}",
            :"write_#{name}",
D
Dmitriy Zaporozhets 已提交
232
            :"modify_#{name}",
G
gitlabhq 已提交
233 234
            :"admin_#{name}"
          ]
V
Vinnie Okada 已提交
235 236
          rules.push(:change_visibility_level) if subject.is_a?(Snippet)
          rules
237 238 239 240 241 242
        elsif subject.respond_to?(:assignee) && subject.assignee == user
          [
            :"read_#{name}",
            :"write_#{name}",
            :"modify_#{name}",
          ]
G
gitlabhq 已提交
243
        else
244 245 246 247 248
          if subject.respond_to?(:project)
            project_abilities(user, subject.project)
          else
            []
          end
G
gitlabhq 已提交
249 250 251
        end
      end
    end
252

253
    def group_member_abilities(user, subject)
254 255 256 257 258
      rules = []
      target_user = subject.user
      group = subject.group
      can_manage = group_abilities(user, group).include?(:manage_group)
      if can_manage && (user != target_user)
259 260
        rules << :modify_group_member
        rules << :destroy_group_member
261 262
      end
      if !group.last_owner?(user) && (can_manage || (user == target_user))
263
        rules << :destroy_group_member
264 265 266
      end
      rules
    end
C
Ciro Santilli 已提交
267 268 269 270 271 272 273 274

    def abilities
      @abilities ||= begin
                       abilities = Six.new
                       abilities << self
                       abilities
                     end
    end
G
gitlabhq 已提交
275
  end
G
gitlabhq 已提交
276
end