ability.rb 3.2 KB
Newer Older
G
gitlabhq 已提交
1
class Ability
A
Andrey Kumanyaev 已提交
2 3 4 5 6 7 8 9
  class << self
    def allowed(object, subject)
      case subject.class.name
      when "Project" then project_abilities(object, subject)
      when "Issue" then issue_abilities(object, subject)
      when "Note" then note_abilities(object, subject)
      when "Snippet" then snippet_abilities(object, subject)
      when "MergeRequest" then merge_request_abilities(object, subject)
10
      when "Group" then group_abilities(object, subject)
A
Andrey Kumanyaev 已提交
11 12
      else []
      end
G
gitlabhq 已提交
13 14
    end

A
Andrey Kumanyaev 已提交
15 16
    def project_abilities(user, project)
      rules = []
G
gitlabhq 已提交
17

18 19 20
      # Rules based on role in project
      if project.master_access_for?(user)
        # TODO: replace with master rules.
21
        # Only allow project administration for namespace owners
22 23 24 25 26 27 28 29 30 31 32 33
        rules << project_admin_rules

      elsif project.dev_access_for?(user)
        rules << project_dev_rules

      elsif project.report_access_for?(user)
        rules << project_report_rules

      elsif project.guest_access_for?(user)
        rules << project_guest_rules
      end

34 35 36 37 38 39 40 41 42 43 44 45
      if project.namespace
        # If user own project namespace
        # (Ex. group owner or account owner)
        if project.namespace.owner == user
          rules << project_admin_rules
        end
      else
        # For compatibility with global projects
        # use projects.owner_id
        if project.owner == user
          rules << project_admin_rules
        end
46 47 48 49 50 51 52 53
      end


      rules.flatten
    end

    def project_guest_rules
      [
A
Andrey Kumanyaev 已提交
54 55 56 57 58 59 60 61 62 63 64
        :read_project,
        :read_wiki,
        :read_issue,
        :read_milestone,
        :read_snippet,
        :read_team_member,
        :read_merge_request,
        :read_note,
        :write_project,
        :write_issue,
        :write_note
65 66
      ]
    end
D
Dmitriy Zaporozhets 已提交
67

68 69
    def project_report_rules
      project_guest_rules + [
A
Andrey Kumanyaev 已提交
70 71 72
        :download_code,
        :write_merge_request,
        :write_snippet
73 74
      ]
    end
D
Dmitriy Zaporozhets 已提交
75

76 77
    def project_dev_rules
      project_report_rules + [
78 79
        :write_wiki,
        :push_code
80 81
      ]
    end
82

83 84 85
    def project_master_rules
      project_dev_rules + [
        :push_code_to_protected_branches,
A
Andrey Kumanyaev 已提交
86 87 88 89 90 91 92 93 94 95 96
        :modify_issue,
        :modify_snippet,
        :modify_merge_request,
        :admin_issue,
        :admin_milestone,
        :admin_snippet,
        :admin_team_member,
        :admin_merge_request,
        :admin_note,
        :accept_mr,
        :admin_wiki
97 98
      ]
    end
G
gitlabhq 已提交
99

100 101 102 103
    def project_admin_rules
      project_master_rules + [
        :admin_project
      ]
A
Andrey Kumanyaev 已提交
104
    end
G
gitlabhq 已提交
105

106 107 108 109 110 111 112 113 114 115
    def group_abilities user, group
      rules = []

      rules << [
        :manage_group
      ] if group.owner == user

      rules.flatten
    end

D
Dmitriy Zaporozhets 已提交
116
    [:issue, :note, :snippet, :merge_request].each do |name|
G
gitlabhq 已提交
117 118 119 120 121
      define_method "#{name}_abilities" do |user, subject|
        if subject.author == user
          [
            :"read_#{name}",
            :"write_#{name}",
D
Dmitriy Zaporozhets 已提交
122
            :"modify_#{name}",
G
gitlabhq 已提交
123 124
            :"admin_#{name}"
          ]
125 126 127 128 129 130
        elsif subject.respond_to?(:assignee) && subject.assignee == user
          [
            :"read_#{name}",
            :"write_#{name}",
            :"modify_#{name}",
          ]
G
gitlabhq 已提交
131
        else
A
Andrey Kumanyaev 已提交
132
          subject.respond_to?(:project) ? project_abilities(user, subject.project) : []
G
gitlabhq 已提交
133 134 135 136
        end
      end
    end
  end
G
gitlabhq 已提交
137
end