ability.rb 3.7 KB
Newer Older
G
gitlabhq 已提交
1
class Ability
A
Andrey Kumanyaev 已提交
2
  class << self
3 4 5
    def allowed(user, subject)
      return [] unless user.kind_of?(User)

A
Andrey Kumanyaev 已提交
6
      case subject.class.name
7 8 9 10 11 12 13
      when "Project" then project_abilities(user, subject)
      when "Issue" then issue_abilities(user, subject)
      when "Note" then note_abilities(user, subject)
      when "Snippet" then snippet_abilities(user, subject)
      when "MergeRequest" then merge_request_abilities(user, subject)
      when "Group", "Namespace" then group_abilities(user, subject)
      when "UserTeam" then user_team_abilities(user, subject)
A
Andrey Kumanyaev 已提交
14
      else []
15 16 17 18 19 20 21 22
      end.concat(global_abilities(user))
    end

    def global_abilities(user)
      rules = []
      rules << :create_group if user.can_create_group
      rules << :create_team if user.can_create_team
      rules
G
gitlabhq 已提交
23 24
    end

A
Andrey Kumanyaev 已提交
25 26
    def project_abilities(user, project)
      rules = []
G
gitlabhq 已提交
27

D
Dmitriy Zaporozhets 已提交
28 29
      team = project.team

30
      # Rules based on role in project
D
Dmitriy Zaporozhets 已提交
31
      if team.masters.include?(user)
32
        rules << project_master_rules
33

D
Dmitriy Zaporozhets 已提交
34
      elsif team.developers.include?(user)
35 36
        rules << project_dev_rules

D
Dmitriy Zaporozhets 已提交
37
      elsif team.reporters.include?(user)
38 39
        rules << project_report_rules

D
Dmitriy Zaporozhets 已提交
40
      elsif team.guests.include?(user)
41 42 43
        rules << project_guest_rules
      end

44
      if project.owner == user || user.admin?
45
        rules << project_admin_rules
46 47 48 49 50 51 52
      end

      rules.flatten
    end

    def project_guest_rules
      [
A
Andrey Kumanyaev 已提交
53 54 55 56 57 58 59 60 61 62
        :read_project,
        :read_wiki,
        :read_issue,
        :read_milestone,
        :read_snippet,
        :read_team_member,
        :read_merge_request,
        :read_note,
        :write_project,
        :write_issue,
63 64
        :write_note,
        :fork_project
65 66
      ]
    end
D
Dmitriy Zaporozhets 已提交
67

68 69
    def project_report_rules
      project_guest_rules + [
A
Andrey Kumanyaev 已提交
70 71
        :download_code,
        :write_snippet
72 73
      ]
    end
D
Dmitriy Zaporozhets 已提交
74

75 76
    def project_dev_rules
      project_report_rules + [
77
        :write_merge_request,
78 79
        :write_wiki,
        :push_code
80 81
      ]
    end
82

83 84 85
    def project_master_rules
      project_dev_rules + [
        :push_code_to_protected_branches,
A
Andrey Kumanyaev 已提交
86 87 88 89 90 91 92 93 94
        :modify_issue,
        :modify_snippet,
        :modify_merge_request,
        :admin_issue,
        :admin_milestone,
        :admin_snippet,
        :admin_team_member,
        :admin_merge_request,
        :admin_note,
95 96
        :admin_wiki,
        :admin_project
97 98
      ]
    end
G
gitlabhq 已提交
99

100 101
    def project_admin_rules
      project_master_rules + [
102
        :change_namespace,
103
        :change_public_mode,
104 105
        :rename_project,
        :remove_project
106
      ]
A
Andrey Kumanyaev 已提交
107
    end
G
gitlabhq 已提交
108

109 110 111
    def group_abilities user, group
      rules = []

112 113 114
      # Only group owner and administrators can manage group
      if group.owner == user || user.admin?
        rules << [
115 116
          :manage_group,
          :manage_namespace
117 118
        ]
      end
119 120 121 122

      rules.flatten
    end

A
Andrey Kumanyaev 已提交
123 124 125
    def user_team_abilities user, team
      rules = []

126
      # Only group owner and administrators can manage team
A
Andrey Kumanyaev 已提交
127 128 129 130 131 132 133 134 135 136 137 138
      if team.owner == user || team.admin?(user) || user.admin?
        rules << [ :manage_user_team ]
      end

      if team.owner == user || user.admin?
        rules << [ :admin_user_team ]
      end

      rules.flatten
    end


D
Dmitriy Zaporozhets 已提交
139
    [:issue, :note, :snippet, :merge_request].each do |name|
G
gitlabhq 已提交
140 141 142 143 144
      define_method "#{name}_abilities" do |user, subject|
        if subject.author == user
          [
            :"read_#{name}",
            :"write_#{name}",
D
Dmitriy Zaporozhets 已提交
145
            :"modify_#{name}",
G
gitlabhq 已提交
146 147
            :"admin_#{name}"
          ]
148 149 150 151 152 153
        elsif subject.respond_to?(:assignee) && subject.assignee == user
          [
            :"read_#{name}",
            :"write_#{name}",
            :"modify_#{name}",
          ]
G
gitlabhq 已提交
154
        else
A
Andrey Kumanyaev 已提交
155
          subject.respond_to?(:project) ? project_abilities(user, subject.project) : []
G
gitlabhq 已提交
156 157 158 159
        end
      end
    end
  end
G
gitlabhq 已提交
160
end