ability.rb 4.3 KB
Newer Older
G
gitlabhq 已提交
1
class Ability
A
Andrey Kumanyaev 已提交
2
  class << self
3 4 5
    def allowed(user, subject)
      return [] unless user.kind_of?(User)

A
Andrey Kumanyaev 已提交
6
      case subject.class.name
7 8 9
      when "Project" then project_abilities(user, subject)
      when "Issue" then issue_abilities(user, subject)
      when "Note" then note_abilities(user, subject)
10
      when "ProjectSnippet" then project_snippet_abilities(user, subject)
11
      when "PersonalSnippet" then personal_snippet_abilities(user, subject)
12 13 14
      when "MergeRequest" then merge_request_abilities(user, subject)
      when "Group", "Namespace" then group_abilities(user, subject)
      when "UserTeam" then user_team_abilities(user, subject)
A
Andrey Kumanyaev 已提交
15
      else []
16 17 18 19 20 21 22 23
      end.concat(global_abilities(user))
    end

    def global_abilities(user)
      rules = []
      rules << :create_group if user.can_create_group
      rules << :create_team if user.can_create_team
      rules
G
gitlabhq 已提交
24 25
    end

A
Andrey Kumanyaev 已提交
26 27
    def project_abilities(user, project)
      rules = []
G
gitlabhq 已提交
28

D
Dmitriy Zaporozhets 已提交
29 30
      team = project.team

31
      # Rules based on role in project
D
Dmitriy Zaporozhets 已提交
32
      if team.masters.include?(user)
33
        rules << project_master_rules
34

D
Dmitriy Zaporozhets 已提交
35
      elsif team.developers.include?(user)
36 37
        rules << project_dev_rules

D
Dmitriy Zaporozhets 已提交
38
      elsif team.reporters.include?(user)
39 40
        rules << project_report_rules

41
      elsif team.guests.include?(user)
42 43 44
        rules << project_guest_rules
      end

45 46 47 48
      if project.public?
        rules << public_project_rules
      end

49
      if project.owner == user || user.admin?
50
        rules << project_admin_rules
51 52 53 54 55
      end

      rules.flatten
    end

56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72
    def public_project_rules
      [
        :download_code,
        :fork_project,
        :read_project,
        :read_wiki,
        :read_issue,
        :read_milestone,
        :read_project_snippet,
        :read_team_member,
        :read_merge_request,
        :read_note,
        :write_issue,
        :write_note
      ]
    end

73 74
    def project_guest_rules
      [
A
Andrey Kumanyaev 已提交
75 76 77 78
        :read_project,
        :read_wiki,
        :read_issue,
        :read_milestone,
A
Andrew8xx8 已提交
79
        :read_project_snippet,
A
Andrey Kumanyaev 已提交
80 81 82 83 84
        :read_team_member,
        :read_merge_request,
        :read_note,
        :write_project,
        :write_issue,
85
        :write_note
86 87
      ]
    end
D
Dmitriy Zaporozhets 已提交
88

89 90
    def project_report_rules
      project_guest_rules + [
A
Andrey Kumanyaev 已提交
91
        :download_code,
92
        :fork_project,
A
Andrew8xx8 已提交
93
        :write_project_snippet
94 95
      ]
    end
D
Dmitriy Zaporozhets 已提交
96

97 98
    def project_dev_rules
      project_report_rules + [
99
        :write_merge_request,
100 101
        :write_wiki,
        :push_code
102 103
      ]
    end
104

105 106 107
    def project_master_rules
      project_dev_rules + [
        :push_code_to_protected_branches,
A
Andrey Kumanyaev 已提交
108
        :modify_issue,
A
Andrew8xx8 已提交
109
        :modify_project_snippet,
A
Andrey Kumanyaev 已提交
110 111 112
        :modify_merge_request,
        :admin_issue,
        :admin_milestone,
A
Andrew8xx8 已提交
113
        :admin_project_snippet,
A
Andrey Kumanyaev 已提交
114 115 116
        :admin_team_member,
        :admin_merge_request,
        :admin_note,
117 118
        :admin_wiki,
        :admin_project
119 120
      ]
    end
G
gitlabhq 已提交
121

122 123
    def project_admin_rules
      project_master_rules + [
124
        :change_namespace,
125
        :change_public_mode,
126 127
        :rename_project,
        :remove_project
128
      ]
A
Andrey Kumanyaev 已提交
129
    end
G
gitlabhq 已提交
130

131 132 133
    def group_abilities user, group
      rules = []

134
      # Only group owner and administrators can manage group
135
      if group.owners.include?(user) || user.admin?
136
        rules << [
137 138
          :manage_group,
          :manage_namespace
139 140
        ]
      end
141 142 143 144

      rules.flatten
    end

A
Andrey Kumanyaev 已提交
145 146 147
    def user_team_abilities user, team
      rules = []

148
      # Only group owner and administrators can manage team
149
      if user.admin? || team.owner == user || team.admin?(user)
A
Andrey Kumanyaev 已提交
150 151 152 153 154 155 156 157 158 159
        rules << [ :manage_user_team ]
      end

      if team.owner == user || user.admin?
        rules << [ :admin_user_team ]
      end

      rules.flatten
    end

160
    [:issue, :note, :project_snippet, :personal_snippet, :merge_request].each do |name|
G
gitlabhq 已提交
161 162 163 164 165
      define_method "#{name}_abilities" do |user, subject|
        if subject.author == user
          [
            :"read_#{name}",
            :"write_#{name}",
D
Dmitriy Zaporozhets 已提交
166
            :"modify_#{name}",
G
gitlabhq 已提交
167 168
            :"admin_#{name}"
          ]
169 170 171 172 173 174
        elsif subject.respond_to?(:assignee) && subject.assignee == user
          [
            :"read_#{name}",
            :"write_#{name}",
            :"modify_#{name}",
          ]
G
gitlabhq 已提交
175
        else
A
Andrey Kumanyaev 已提交
176
          subject.respond_to?(:project) ? project_abilities(user, subject.project) : []
G
gitlabhq 已提交
177 178 179 180
        end
      end
    end
  end
G
gitlabhq 已提交
181
end