diff --git a/app/controllers/admin/base_controller.rb b/app/controllers/admin/base_controller.rb index 85dba43d..3b28a230 100644 --- a/app/controllers/admin/base_controller.rb +++ b/app/controllers/admin/base_controller.rb @@ -2,6 +2,12 @@ module Admin class BaseController < ApplicationController before_filter :verify_user_admin + private + + def current_ability + @current_ability ||= AdminAbility.new(current_user) + end + def verify_user_admin if (current_user.nil?) redirect_to sign_in_path diff --git a/app/controllers/admin/registration_periods_controller.rb b/app/controllers/admin/registration_periods_controller.rb index d955ddd0..4e48c013 100644 --- a/app/controllers/admin/registration_periods_controller.rb +++ b/app/controllers/admin/registration_periods_controller.rb @@ -1,5 +1,5 @@ module Admin - class RegistrationPeriodsController < ApplicationController + class RegistrationPeriodsController < Admin::BaseController load_and_authorize_resource :conference, find_by: :short_title load_and_authorize_resource through: :conference, singleton: true diff --git a/app/models/ability.rb b/app/models/ability.rb index 40965719..6581069c 100644 --- a/app/models/ability.rb +++ b/app/models/ability.rb @@ -3,30 +3,52 @@ class Ability # Initializes the ability class def initialize(user) - # Order Abilities - # (Check https://github.com/CanCanCommunity/cancancan/wiki/Ability-Precedence) - # Check roles of user, using rolify. Role name is *case sensitive* - # user.is_organizer? or user.has_role? :organizer - # user.is_cfp_of? Conference or user.has_role? :cfp, Conference - # user.is_info_desk_of? Conference - # user.is_volunteers_coordinator_of? Conference - # user.is_attendee_of? Conference - # The following is wrong because a user will only have 'cfp' role for a specific conference - # user.is_cfp? # This is always false - user ||= User.new - # This is what sets up the different abilities if user.new_record? not_signed_in - # Checks if the user does not have any role and is not an admin elsif user.roles.any? || user.is_admin - signed_in_with_roles(user) + common_abilities_for_admins(user) else signed_in(user) end end + # Abilities for users with roles wandering around in non-admin views. + def common_abilities_for_admins(user) + signed_in(user) + conf_ids_for_organizer = Conference.with_role(:organizer, user).pluck(:id) + conf_ids_for_cfp = Conference.with_role(:cfp, user).pluck(:id) + conf_ids_for_info_desk = Conference.with_role(:info_desk, user).pluck(:id) + + if conf_ids_for_organizer + + # To access splashpage of their conference if it is not public + can :show, Conference, id: conf_ids_for_organizer + + # To access conference/proposals/registrations + can :manage, Registration, conference_id: conf_ids_for_organizer + + # To access conference/proposals + can :manage, Event, program: { conference_id: conf_ids_for_organizer } + + # To access comment link in menu bar + can :index, Comment, commentable_type: 'Event', + commentable_id: Event.where(program_id: Program.where(conference_id: conf_ids_for_organizer).pluck(:id)).pluck(:id) + elsif conf_ids_for_cfp + + can :index, Comment, commentable_type: 'Event', + commentable_id: Event.where(program_id: Program.where(conference_id: conf_ids_for_cfp).pluck(:id)).pluck(:id) + can :manage, Event, program: { conference_id: conf_ids_for_cfp } + + elsif conf_ids_for_info_desk + can :manage, Registration, conference_id: conf_ids_for_info_desk + end + + can :access, Admin + can :manage, :all if user.is_admin + end + # Abilities for not signed in users (guests) def not_signed_in can [:index], Organization @@ -74,7 +96,6 @@ class Ability def signed_in(user) # Abilities from not_signed_in user are also inherited not_signed_in - can :manage, User, id: user.id can :manage, Registration, user_id: user.id @@ -105,199 +126,4 @@ class Ability can [:destroy], Openid end - - # Abilities for signed in users with roles - def signed_in_with_roles(user) - # Abilities from not_signed_in and signed_in are also inherited - signed_in(user) - - signed_in_with_organization_admin_role(user) if user.has_role? :organization_admin, :any - signed_in_with_organizer_role(user) if user.has_role? :organizer, :any - signed_in_with_cfp_role(user) if user.has_role? :cfp, :any - signed_in_with_info_desk_role(user) if user.has_role? :info_desk, :any - signed_in_with_volunteers_coordinator_role(user) if user.has_role? :volunteers_coordinator, :any - - # for users with any role - can :access, Admin - can [:show], Conference - can :index, Commercial, commercialable_type: 'Conference' - cannot [:edit, :update, :destroy], Question, global: true - # for admins - can :manage, :all if user.is_admin - - # even admin cannot create new users with ICHAIN enabled - cannot [:new, :create], User if ENV['OSEM_ICHAIN_ENABLED'] == 'true' - - cannot :revert_object, PaperTrail::Version do |version| - (version.event == 'create' && %w(Conference User Event).include?(version.item_type)) - end - - cannot :revert_attribute, PaperTrail::Version do |version| - version.event != 'update' || version.item.nil? - end - - cannot :destroy, Program - # Do not delete venue, when there are rooms being used - cannot :destroy, Venue do |venue| - venue.conference.program.events.where.not(room_id: nil).any? - end - - # Can't create cfp if there are no available cfp types - cannot [:new, :create], Cfp do |cfp| - cfp.program.remaining_cfp_types.empty? - end - end - - def signed_in_with_organization_admin_role(user) - org_ids_for_organization_admin = Organization.with_role(:organization_admin, user).pluck(:id) - conf_ids_for_organization_admin = Conference.where(organization_id: org_ids_for_organization_admin).pluck(:id) - - can [:read, :update, :destroy], Organization, id: org_ids_for_organization_admin - can :new, Conference - can :manage, Conference, organization_id: org_ids_for_organization_admin - can [:index, :show], Role - can [:edit, :update], Role do |role| - role.resource_type == 'Organization' && (org_ids_for_organization_admin.include? role.resource_id) - end - signed_in_with_organizer_role(user, conf_ids_for_organization_admin) - end - - def signed_in_with_organizer_role(user, conf_ids_for_organization_admin = []) - # ids of all the conferences for which the user has the 'organizer' role and - # conferences that belong to organizations for which user is 'organization_admin' - conf_ids = conf_ids_for_organization_admin.concat(Conference.with_role(:organizer, user).pluck(:id)).uniq - can :manage, Resource, conference_id: conf_ids - can [:read, :update, :destroy], Conference, id: conf_ids - can :manage, Splashpage, conference_id: conf_ids - can :manage, Contact, conference_id: conf_ids - can :manage, EmailSettings, conference_id: conf_ids - can :manage, Campaign, conference_id: conf_ids - can :manage, Target, conference_id: conf_ids - can :manage, Commercial, commercialable_type: 'Conference', - commercialable_id: conf_ids - can :manage, Registration, conference_id: conf_ids - can :manage, RegistrationPeriod, conference_id: conf_ids - can :manage, Question, conference_id: conf_ids - can :manage, Question do |question| - !(question.conferences.pluck(:id) & conf_ids).empty? - end - can :manage, Vposition, conference_id: conf_ids - can :manage, Vday, conference_id: conf_ids - can :manage, Program, conference_id: conf_ids - can :manage, Schedule, program: { conference_id: conf_ids } - can :manage, EventSchedule, schedule: { program: { conference_id: conf_ids } } - can :manage, Cfp, program: { conference_id: conf_ids} - can :manage, Event, program: { conference_id: conf_ids} - can :manage, EventType, program: { conference_id: conf_ids} - can :manage, Track, program: { conference_id: conf_ids} - can :manage, DifficultyLevel, program: { conference_id: conf_ids} - can :manage, Commercial, commercialable_type: 'Event', - commercialable_id: Event.where(program_id: Program.where(conference_id: conf_ids).pluck(:id)).pluck(:id) - can :manage, Venue, conference_id: conf_ids - can :manage, Commercial, commercialable_type: 'Venue', - commercialable_id: Venue.where(conference_id: conf_ids).pluck(:id) - can :manage, Lodging, conference_id: conf_ids - can :manage, Room, venue: { conference_id: conf_ids} - can :manage, Sponsor, conference_id: conf_ids - can :manage, SponsorshipLevel, conference_id: conf_ids - can :manage, Ticket, conference_id: conf_ids - can :index, Comment, commentable_type: 'Event', - commentable_id: Event.where(program_id: Program.where(conference_id: conf_ids).pluck(:id)).pluck(:id) - - # Abilities for Role (Conference resource) - can [:index, :show], Role do |role| - role.resource_type == 'Conference' - end - - can [:edit, :update, :toggle_user], Role do |role| - role.resource_type == 'Conference' && (conf_ids.include? role.resource_id) - end - - can [:index, :revert_object, :revert_attribute], PaperTrail::Version do |version| - version.item_type == 'User' || (conf_ids.include? version.conference_id) - end - end - - def signed_in_with_cfp_role(user) - # ids of all the conferences for which the user has the 'cfp' role - conf_ids_for_cfp = Conference.with_role(:cfp, user).pluck(:id) - - can [:index, :show, :update], Resource, conference_id: conf_ids_for_cfp - can :manage, Event, program: { conference_id: conf_ids_for_cfp } - can :manage, EventType, program: { conference_id: conf_ids_for_cfp } - can :manage, Track, program: { conference_id: conf_ids_for_cfp } - can :manage, DifficultyLevel, program: { conference_id: conf_ids_for_cfp } - can :manage, EmailSettings, conference_id: conf_ids_for_cfp - can :manage, Schedule, program: { conference_id: conf_ids_for_cfp } - can :manage, Room, venue: { conference_id: conf_ids_for_cfp } - can :show, Venue, conference_id: conf_ids_for_cfp - can :show, Commercial, commercialable_type: 'Venue', commercialable_id: Venue.where(conference_id: conf_ids_for_cfp).pluck(:id) - can :manage, Cfp, program: { conference_id: conf_ids_for_cfp } - can :manage, Program, conference_id: conf_ids_for_cfp - can :manage, Commercial, commercialable_type: 'Event', - commercialable_id: Event.where(program_id: Program.where(conference_id: conf_ids_for_cfp).pluck(:id)).pluck(:id) - can :index, Comment, commentable_type: 'Event', - commentable_id: Event.where(program_id: Program.where(conference_id: conf_ids_for_cfp).pluck(:id)).pluck(:id) - - # Abilities for Role (Conference resource) - can [:index, :show], Role do |role| - role.resource_type == 'Conference' - end - # Can add or remove users from role, when user has that same role for the conference - # Eg. If you are member of the CfP team, you can add more CfP team members (add users to the role 'CfP') - can :toggle_user, Role do |role| - role.resource_type == 'Conference' && role.name == 'cfp' && - (Conference.with_role(:cfp, user).pluck(:id).include? role.resource_id) - end - - can [:index, :revert_object, :revert_attribute], PaperTrail::Version, item_type: 'Event', conference_id: conf_ids_for_cfp - can [:index, :revert_object, :revert_attribute], PaperTrail::Version, item_type: 'Vote', conference_id: conf_ids_for_cfp - can [:index, :revert_object, :revert_attribute], PaperTrail::Version do |version| - version.item_type == 'Commercial' && conf_ids_for_cfp.include?(version.conference_id) && - (version.object.to_s.include?('Event') || version.object_changes.to_s.include?('Event')) - end - end - - def signed_in_with_info_desk_role(user) - # ids of all the conferences for which the user has the 'info_desk' role - conf_ids_for_info_desk = Conference.with_role(:info_desk, user).pluck(:id) - - can [:index, :show, :update], Resource, conference_id: conf_ids_for_info_desk - can :manage, Registration, conference_id: conf_ids_for_info_desk - can :manage, Question, conference_id: conf_ids_for_info_desk - can :manage, Question do |question| - !(question.conferences.pluck(:id) & conf_ids_for_info_desk).empty? - end - - # Abilities for Role (Conference resource) - can [:index, :show], Role do |role| - role.resource_type == 'Conference' - end - # Can add or remove users from role, when user has that same role for the conference - # Eg. If you are member of the CfP team, you can add more CfP team members (add users to the role 'CfP') - can :toggle_user, Role do |role| - role.resource_type == 'Conference' && role.name == 'info_desk' && - (Conference.with_role(:info_desk, user).pluck(:id).include? role.resource_id) - end - end - - def signed_in_with_volunteers_coordinator_role(user) - # ids of all the conferences for which the user has the 'volunteers_coordinator' role - conf_ids_for_volunteers_coordinator = Conference.with_role(:volunteers_coordinator, user).pluck(:id) - - can [:index, :show, :update], Resource, conference_id: conf_ids_for_volunteers_coordinator - can :manage, Vposition, conference_id: conf_ids_for_volunteers_coordinator - can :manage, Vday, conference_id: conf_ids_for_volunteers_coordinator - - # Abilities for Role (Conference resource) - can [:index, :show], Role do |role| - role.resource_type == 'Conference' - end - # Can add or remove users from role, when user has that same role for the conference - # Eg. If you are member of the CfP team, you can add more CfP team members (add users to the role 'CfP') - can :toggle_user, Role do |role| - role.resource_type == 'Conference' && role.name == 'volunteers_coordinator' && - (Conference.with_role(:volunteers_coordinator, user).pluck(:id).include? role.resource_id) - end - end end diff --git a/app/models/admin_ability.rb b/app/models/admin_ability.rb new file mode 100644 index 00000000..99c80401 --- /dev/null +++ b/app/models/admin_ability.rb @@ -0,0 +1,237 @@ +class AdminAbility + include CanCan::Ability + + def initialize(user) + # Order Abilities + # (Check https://github.com/CanCanCommunity/cancancan/wiki/Ability-Precedence) + # Check roles of user, using rolify. Role name is *case sensitive* + # user.is_organizer? or user.has_role? :organizer + # user.is_cfp_of? Conference or user.has_role? :cfp, Conference + # user.is_info_desk_of? Conference + # user.is_volunteers_coordinator_of? Conference + # user.is_attendee_of? Conference + # The following is wrong because a user will only have 'cfp' role for a specific conference + # user.is_cfp? # This is always false + + user ||= User.new + signed_in_with_roles(user) + end + + def common_abilities_for_roles(user) + can :manage, User, id: user.id + can :manage, Registration, user_id: user.id + + can :show, Registration, &:new_record? + + can [:new, :create], Registration do |registration| + conference = registration.conference + conference.registration_open? && !conference.registration_limit_exceeded? || conference.program.speakers.confirmed.include?(user) + end + + can :index, Organization + can :index, Ticket + can :manage, TicketPurchase, user_id: user.id + can [:new, :create], Payment, user_id: user.id + + can [:create, :destroy], Subscription, user_id: user.id + + can [:new, :create], Event do |event| + event.program.cfp_open? && event.new_record? + end + + can [:update, :show, :delete, :index], Event do |event| + event.users.include?(user) + end + + # can manage the commercials of their own events + can :manage, Commercial, commercialable_type: 'Event', commercialable_id: user.events.pluck(:id) + + can [:destroy], Openid + can :access, Admin + can [:show], Conference + can :index, Commercial, commercialable_type: 'Conference' + cannot [:edit, :update, :destroy], Question, global: true + # for admins + can :manage, :all if user.is_admin + # even admin cannot create new users with ICHAIN enabled + cannot [:new, :create], User if ENV['OSEM_ICHAIN_ENABLED'] == 'true' + cannot :revert_object, PaperTrail::Version do |version| + (version.event == 'create' && %w[Conference User Event].include?(version.item_type)) + end + cannot :revert_attribute, PaperTrail::Version do |version| + version.event != 'update' || version.item.nil? + end + # Can't create cfp if there are no available cfp types + cannot [:new, :create], Cfp do |cfp| + cfp.program.remaining_cfp_types.empty? + end + cannot :destroy, Program + # Do not delete venue, when there are rooms being used + cannot :destroy, Venue do |venue| + venue.conference.program.events.where.not(room_id: nil).any? + end + end + + # Abilities for signed in users with roles + def signed_in_with_roles(user) + signed_in_with_organization_admin_role(user) if user.has_role? :organization_admin, :any + signed_in_with_organizer_role(user) if user.has_role? :organizer, :any + signed_in_with_cfp_role(user) if user.has_role? :cfp, :any + signed_in_with_info_desk_role(user) if user.has_role? :info_desk, :any + signed_in_with_volunteers_coordinator_role(user) if user.has_role? :volunteers_coordinator, :any + common_abilities_for_roles(user) + end + + def signed_in_with_organization_admin_role(user) + org_ids_for_organization_admin = Organization.with_role(:organization_admin, user).pluck(:id) + conf_ids_for_organization_admin = Conference.where(organization_id: org_ids_for_organization_admin).pluck(:id) + + can [:read, :update, :destroy], Organization, id: org_ids_for_organization_admin + can :new, Conference + can :manage, Conference, organization_id: org_ids_for_organization_admin + can [:index, :show], Role + can [:edit, :update], Role do |role| + role.resource_type == 'Organization' && (org_ids_for_organization_admin.include? role.resource_id) + end + signed_in_with_organizer_role(user, conf_ids_for_organization_admin) + end + + def signed_in_with_organizer_role(user, conf_ids_for_organization_admin = []) + # ids of all the conferences for which the user has the 'organizer' role and + # conferences that belong to organizations for which user is 'organization_admin' + conf_ids = conf_ids_for_organization_admin.concat(Conference.with_role(:organizer, user).pluck(:id)).uniq + can :manage, Resource, conference_id: conf_ids + can [:read, :update, :destroy], Conference, id: conf_ids + can :manage, Splashpage, conference_id: conf_ids + can :manage, Contact, conference_id: conf_ids + can :manage, EmailSettings, conference_id: conf_ids + can :manage, Campaign, conference_id: conf_ids + can :manage, Target, conference_id: conf_ids + can :manage, Commercial, commercialable_type: 'Conference', + commercialable_id: conf_ids + can :manage, Registration, conference_id: conf_ids + can :manage, RegistrationPeriod, conference_id: conf_ids + can :manage, Question, conference_id: conf_ids + can :manage, Question do |question| + !(question.conferences.pluck(:id) & conf_ids).empty? + end + can :manage, Vposition, conference_id: conf_ids + can :manage, Vday, conference_id: conf_ids + can :manage, Program, conference_id: conf_ids + can :manage, Schedule, program: { conference_id: conf_ids } + can :manage, EventSchedule, schedule: { program: { conference_id: conf_ids } } + can :manage, Cfp, program: { conference_id: conf_ids } + can :manage, Event, program: { conference_id: conf_ids } + can :manage, EventType, program: { conference_id: conf_ids } + can :manage, Track, program: { conference_id: conf_ids } + can :manage, DifficultyLevel, program: { conference_id: conf_ids } + can :manage, Commercial, commercialable_type: 'Event', + commercialable_id: Event.where(program_id: Program.where(conference_id: conf_ids).pluck(:id)).pluck(:id) + can :manage, Venue, conference_id: conf_ids + can :manage, Commercial, commercialable_type: 'Venue', + commercialable_id: Venue.where(conference_id: conf_ids).pluck(:id) + can :manage, Lodging, conference_id: conf_ids + can :manage, Room, venue: { conference_id: conf_ids } + can :manage, Sponsor, conference_id: conf_ids + can :manage, SponsorshipLevel, conference_id: conf_ids + can :manage, Ticket, conference_id: conf_ids + can :index, Comment, commentable_type: 'Event', + commentable_id: Event.where(program_id: Program.where(conference_id: conf_ids).pluck(:id)).pluck(:id) + + # Abilities for Role (Conference resource) + can [:index, :show], Role do |role| + role.resource_type == 'Conference' + end + + can [:edit, :update, :toggle_user], Role do |role| + role.resource_type == 'Conference' && (conf_ids.include? role.resource_id) + end + + can [:index, :revert_object, :revert_attribute], PaperTrail::Version do |version| + version.item_type == 'User' || (conf_ids.include? version.conference_id) + end + end + + def signed_in_with_cfp_role(user) + # ids of all the conferences for which the user has the 'cfp' role + conf_ids_for_cfp = Conference.with_role(:cfp, user).pluck(:id) + + can [:index, :show, :update], Resource, conference_id: conf_ids_for_cfp + can :manage, Event, program: { conference_id: conf_ids_for_cfp } + can :manage, EventType, program: { conference_id: conf_ids_for_cfp } + can :manage, Track, program: { conference_id: conf_ids_for_cfp } + can :manage, DifficultyLevel, program: { conference_id: conf_ids_for_cfp } + can :manage, EmailSettings, conference_id: conf_ids_for_cfp + can :manage, Schedule, program: { conference_id: conf_ids_for_cfp } + can :manage, Room, venue: { conference_id: conf_ids_for_cfp } + can :show, Venue, conference_id: conf_ids_for_cfp + can :show, Commercial, commercialable_type: 'Venue', commercialable_id: Venue.where(conference_id: conf_ids_for_cfp).pluck(:id) + can :manage, Cfp, program: { conference_id: conf_ids_for_cfp } + can :manage, Program, conference_id: conf_ids_for_cfp + can :manage, Commercial, commercialable_type: 'Event', + commercialable_id: Event.where(program_id: Program.where(conference_id: conf_ids_for_cfp).pluck(:id)).pluck(:id) + can :index, Comment, commentable_type: 'Event', + commentable_id: Event.where(program_id: Program.where(conference_id: conf_ids_for_cfp).pluck(:id)).pluck(:id) + + # Abilities for Role (Conference resource) + can [:index, :show], Role do |role| + role.resource_type == 'Conference' + end + # Can add or remove users from role, when user has that same role for the conference + # Eg. If you are member of the CfP team, you can add more CfP team members (add users to the role 'CfP') + can :toggle_user, Role do |role| + role.resource_type == 'Conference' && role.name == 'cfp' && + (Conference.with_role(:cfp, user).pluck(:id).include? role.resource_id) + end + + can [:index, :revert_object, :revert_attribute], PaperTrail::Version, item_type: 'Event', conference_id: conf_ids_for_cfp + can [:index, :revert_object, :revert_attribute], PaperTrail::Version, item_type: 'Vote', conference_id: conf_ids_for_cfp + can [:index, :revert_object, :revert_attribute], PaperTrail::Version do |version| + version.item_type == 'Commercial' && conf_ids_for_cfp.include?(version.conference_id) && + (version.object.to_s.include?('Event') || version.object_changes.to_s.include?('Event')) + end + end + + def signed_in_with_info_desk_role(user) + # ids of all the conferences for which the user has the 'info_desk' role + conf_ids_for_info_desk = Conference.with_role(:info_desk, user).pluck(:id) + + can [:index, :show, :update], Resource, conference_id: conf_ids_for_info_desk + can :manage, Registration, conference_id: conf_ids_for_info_desk + can :manage, Question, conference_id: conf_ids_for_info_desk + can :manage, Question do |question| + !(question.conferences.pluck(:id) & conf_ids_for_info_desk).empty? + end + + # Abilities for Role (Conference resource) + can [:index, :show], Role do |role| + role.resource_type == 'Conference' + end + # Can add or remove users from role, when user has that same role for the conference + # Eg. If you are member of the CfP team, you can add more CfP team members (add users to the role 'CfP') + can :toggle_user, Role do |role| + role.resource_type == 'Conference' && role.name == 'info_desk' && + (Conference.with_role(:info_desk, user).pluck(:id).include? role.resource_id) + end + end + + def signed_in_with_volunteers_coordinator_role(user) + # ids of all the conferences for which the user has the 'volunteers_coordinator' role + conf_ids_for_volunteers_coordinator = Conference.with_role(:volunteers_coordinator, user).pluck(:id) + + can [:index, :show, :update], Resource, conference_id: conf_ids_for_volunteers_coordinator + can :manage, Vposition, conference_id: conf_ids_for_volunteers_coordinator + can :manage, Vday, conference_id: conf_ids_for_volunteers_coordinator + + # Abilities for Role (Conference resource) + can [:index, :show], Role do |role| + role.resource_type == 'Conference' + end + # Can add or remove users from role, when user has that same role for the conference + # Eg. If you are member of the CfP team, you can add more CfP team members (add users to the role 'CfP') + can :toggle_user, Role do |role| + role.resource_type == 'Conference' && role.name == 'volunteers_coordinator' && + (Conference.with_role(:volunteers_coordinator, user).pluck(:id).include? role.resource_id) + end + end +end diff --git a/spec/models/ability_spec.rb b/spec/models/ability_spec.rb index 02aa4882..55f430f2 100644 --- a/spec/models/ability_spec.rb +++ b/spec/models/ability_spec.rb @@ -11,14 +11,8 @@ describe 'User' do let!(:organization) { create(:organization) } let!(:my_conference) { create(:full_conference, organization: organization) } - let(:my_venue) { my_conference.venue || create(:venue, conference: my_conference) } - let(:my_registration) { create(:registration, conference: my_conference, user: admin) } - let(:other_registration) { create(:registration, conference: conference_public) } - let(:my_event) { create(:event_full, program: my_conference.program) } let(:my_room) { create(:room, venue: my_conference.venue) } - let!(:my_event_scheduled) { create(:event_full, program: my_conference.program, room_id: my_room.id) } - let(:other_event) { create(:event_full, program: conference_public.program) } let(:conference_not_public) { create(:conference, splashpage: create(:splashpage, public: false)) } let(:conference_public) { create(:full_conference, splashpage: create(:splashpage, public: true)) } @@ -28,7 +22,6 @@ describe 'User' do let(:commercial_event_confirmed) { create(:commercial, commercialable: event_confirmed) } let(:commercial_event_unconfirmed) { create(:commercial, commercialable: event_unconfirmed) } - let(:resource) { create(:resource, conference: my_conference)} let(:registration) { create(:registration) } let(:program_with_cfp) { create(:program, :with_cfp) } @@ -38,11 +31,6 @@ describe 'User' do let(:conference_with_closed_registration) { create(:conference) } let!(:closed_registration_period) { create(:registration_period, conference: conference_with_closed_registration, start_date: Date.current - 6.days, end_date: Date.current - 6.days) } - let!(:my_schedule) { create(:schedule, program: my_conference.program) } - let!(:other_schedule) { create(:schedule, program: conference_public.program) } - - let!(:my_event_schedule) { create(:event_schedule, schedule: my_schedule) } - let!(:other_event_schedule) { create(:event_schedule, schedule: other_schedule) } # Test abilities for not signed in users context 'when user is not signed in' do it{ should be_able_to(:index, Organization)} @@ -127,354 +115,5 @@ describe 'User' do it{ should be_able_to(:manage, user_commercial) } it{ should_not be_able_to(:manage, commercial_event_unconfirmed) } end - - context 'user #is_admin?' do - let(:venue) { my_conference.venue } - let(:room) { create(:room, venue: venue) } - let!(:event) { create(:event_full, program: my_conference.program, room_id: room.id) } - let(:user) { create(:admin) } - it{ should be_able_to(:manage, :all) } - it{ should_not be_able_to(:destroy, my_conference.program) } - it{ should_not be_able_to(:destroy, my_venue) } - end - - shared_examples 'user with any role' do - let!(:other_organization) { create(:organization) } - let!(:other_conference) { create(:conference, organization: other_organization) } - - it{ should_not be_able_to(:update, Role.find_by(name: 'organization_admin', resource: other_organization)) } - it{ should_not be_able_to(:edit, Role.find_by(name: 'organization_admin', resource: other_organization)) } - it{ should_not be_able_to(:show, Role.find_by(name: 'organization_admin', resource: other_organization)) } - - %w(organizer cfp info_desk volunteers_coordinator).each do |role| - it{ should_not be_able_to(:toggle_user, Role.find_by(name: role, resource: other_conference)) } - it{ should_not be_able_to(:update, Role.find_by(name: role, resource: other_conference)) } - it{ should_not be_able_to(:edit, Role.find_by(name: role, resource: other_conference)) } - it{ should be_able_to(:show, Role.find_by(name: role, resource: other_conference)) } - it{ should be_able_to(:index, Role.find_by(name: role, resource: other_conference)) } - end - end - - shared_examples 'user with non-organizer role' do |role_name| - %w(organizer cfp info_desk volunteers_coordinator).each do |role| - if role == role_name - it{ should be_able_to(:toggle_user, Role.find_by(name: role, resource: my_conference)) } - else - it{ should_not be_able_to(:toggle_user, Role.find_by(name: role, resource: my_conference)) } - end - it{ should_not be_able_to(:update, Role.find_by(name: role, resource: my_conference)) } - it{ should_not be_able_to(:edit, Role.find_by(name: role, resource: my_conference)) } - it{ should be_able_to(:show, Role.find_by(name: role, resource: my_conference)) } - it{ should be_able_to(:index, Role.find_by(name: role, resource: my_conference)) } - end - end - - context 'when user has the role organization_admin' do - let(:role) { Role.find_by(name: 'organization_admin', resource: organization) } - let(:user) { create(:user, role_ids: [role.id]) } - let(:other_organization) { create(:organization) } - let(:other_conference) { create(:conference, organization: other_organization) } - - it{ should be_able_to(:manage, my_conference) } - it{ should be_able_to(:read, organization) } - it{ should be_able_to(:update, organization) } - it{ should be_able_to(:destroy, organization) } - it{ should be_able_to(:new, Conference.new) } - it{ should be_able_to(:create, Conference.new(organization_id: organization.id)) } - it{ should_not be_able_to(:manage, other_conference) } - it{ should_not be_able_to(:create, Conference.new(organization_id: other_organization.id)) } - it{ should_not be_able_to(:new, Organization.new) } - it{ should_not be_able_to(:create, Organization.new) } - end - - context 'when user has the role organizer' do - let(:role) { Role.find_by(name: 'organizer', resource: my_conference) } - let(:user) { create(:user, role_ids: [role.id]) } - - it{ should_not be_able_to(:destroy, my_conference.program) } - it 'when there is a room assigned to an event' do - should_not be_able_to(:destroy, my_venue) - end - - it 'when there are no rooms used' do - my_event_scheduled.room_id = nil - my_event_scheduled.save! - my_event_scheduled.reload - should be_able_to(:destroy, my_venue) - end - - it{ should_not be_able_to(:new, Organization.new)} - it{ should_not be_able_to(:create, Organization.new)} - it{ should_not be_able_to(:new, Conference.new)} - it{ should_not be_able_to(:create, Conference.new) } - it{ should be_able_to(:read, my_conference) } - it{ should be_able_to(:update, my_conference) } - it{ should be_able_to(:destroy, my_conference) } - it{ should_not be_able_to(:manage, conference_public) } - it{ should be_able_to(:manage, my_conference.splashpage) } - it{ should_not be_able_to(:manage, conference_public.splashpage) } - it{ should be_able_to(:manage, my_conference.contact) } - it{ should_not be_able_to(:manage, conference_public.contact) } - it{ should be_able_to(:manage, my_conference.email_settings) } - it{ should_not be_able_to(:manage, conference_public.email_settings) } - it{ should be_able_to(:manage, my_conference.campaigns.first) } - it{ should_not be_able_to(:manage, conference_public.campaigns.first) } - it{ should be_able_to(:manage, my_conference.targets.first) } - it{ should_not be_able_to(:manage, conference_public.targets.first) } - it{ should be_able_to(:manage, my_conference.commercials.first) } - it{ should_not be_able_to(:manage, conference_public.commercials.first) } - it{ should be_able_to(:manage, my_conference.registration_period) } - it{ should_not be_able_to(:manage, conference_public.registration_period) } - it{ should be_able_to(:manage, my_conference.questions.first) } - it{ should_not be_able_to(:manage, conference_public.questions.first) } - it{ should be_able_to(:manage, my_conference.program.cfp) } - it{ should_not be_able_to(:manage, conference_public.program.cfp) } - it{ should be_able_to(:manage, my_schedule) } - it{ should_not be_able_to(:manage, other_schedule) } - it{ should be_able_to(:manage, my_event_schedule) } - it{ should_not be_able_to(:manage, other_event_schedule) } - it{ should be_able_to(:manage, my_conference.venue) } - it{ should_not be_able_to(:manage, conference_public.venue) } - it{ should be_able_to(:manage, my_conference.lodgings.first) } - it{ should_not be_able_to(:manage, conference_public.lodgings.first) } - it{ should be_able_to(:manage, my_conference.sponsors.first) } - it{ should_not be_able_to(:manage, conference_public.sponsors.first) } - it{ should be_able_to(:manage, my_conference.sponsorship_levels.first) } - it{ should_not be_able_to(:manage, conference_public.sponsorship_levels.first) } - it{ should be_able_to(:manage, my_conference.tickets.first) } - it{ should_not be_able_to(:manage, conference_public.tickets.first) } - - it{ should be_able_to(:manage, my_registration) } - it{ should_not be_able_to(:manage, other_registration) } - - it{ should be_able_to(:manage, my_event) } - it{ should_not be_able_to(:manage, other_event) } - it{ should be_able_to(:manage, my_event.event_type) } - it{ should_not be_able_to(:manage, other_event.event_type) } - it{ should be_able_to(:manage, my_event.track) } - it{ should_not be_able_to(:manage, other_event.track) } - it{ should be_able_to(:manage, my_event.difficulty_level) } - it{ should_not be_able_to(:manage, other_event.difficulty_level) } - it{ should be_able_to(:manage, my_event.commercials.first) } - it{ should_not be_able_to(:manage, other_event.commercials.first) } - it{ should be_able_to(:index, my_event.comment_threads.first) } - it{ should_not be_able_to(:index, other_event.comment_threads.first) } - - it{ should be_able_to(:manage, resource)} - - %w(organizer cfp info_desk volunteers_coordinator).each do |role| - it{ should be_able_to(:toggle_user, Role.find_by(name: role, resource: my_conference)) } - it{ should be_able_to(:edit, Role.find_by(name: role, resource: my_conference)) } - it{ should be_able_to(:update, Role.find_by(name: role, resource: my_conference)) } - it{ should be_able_to(:show, Role.find_by(name: role, resource: my_conference)) } - it{ should be_able_to(:index, Role.find_by(name: role, resource: my_conference)) } - end - - it_behaves_like 'user with any role' - end - - context 'when user has the role cfp' do - let(:role) { Role.find_by(name: 'cfp', resource: my_conference) } - let(:user) { create(:user, role_ids: [role.id]) } - - it{ should_not be_able_to(:new, Conference.new) } - it{ should_not be_able_to(:create, Conference.new) } - it{ should_not be_able_to(:manage, my_conference) } - it{ should_not be_able_to(:manage, conference_public) } - it{ should_not be_able_to(:manage, my_conference.splashpage) } - it{ should_not be_able_to(:manage, conference_public.splashpage) } - it{ should_not be_able_to(:manage, my_conference.contact) } - it{ should_not be_able_to(:manage, conference_public.contact) } - it{ should be_able_to(:manage, my_conference.email_settings) } - it{ should_not be_able_to(:manage, conference_public.email_settings) } - it{ should_not be_able_to(:manage, my_conference.campaigns.first) } - it{ should_not be_able_to(:manage, conference_public.campaigns.first) } - it{ should_not be_able_to(:manage, my_conference.targets.first) } - it{ should_not be_able_to(:manage, conference_public.targets.first) } - it{ should_not be_able_to(:manage, my_conference.commercials.first) } - it{ should_not be_able_to(:manage, conference_public.commercials.first) } - it{ should_not be_able_to(:manage, my_conference.registration_period) } - it{ should_not be_able_to(:manage, conference_public.registration_period) } - it{ should_not be_able_to(:manage, my_conference.questions.first) } - it{ should_not be_able_to(:manage, conference_public.questions.first) } - it{ should be_able_to(:manage, my_conference.program.cfp) } - it{ should_not be_able_to(:manage, conference_public.program.cfp) } - it{ should be_able_to(:manage, my_schedule) } - it{ should_not be_able_to(:manage, other_schedule) } - it{ should_not be_able_to(:manage, my_event_schedule) } - it{ should_not be_able_to(:manage, other_event_schedule) } - it{ should_not be_able_to(:manage, my_conference.venue) } - it{ should be_able_to(:show, my_conference.venue) } - it{ should_not be_able_to(:manage, conference_public.venue) } - it{ should_not be_able_to(:manage, my_conference.lodgings.first) } - it{ should_not be_able_to(:manage, conference_public.lodgings.first) } - it{ should_not be_able_to(:manage, my_conference.sponsors.first) } - it{ should_not be_able_to(:manage, conference_public.sponsors.first) } - it{ should_not be_able_to(:manage, my_conference.sponsorship_levels.first) } - it{ should_not be_able_to(:manage, conference_public.sponsorship_levels.first) } - it{ should_not be_able_to(:manage, my_conference.tickets.first) } - it{ should_not be_able_to(:manage, conference_public.tickets.first) } - - it{ should_not be_able_to(:manage, my_registration) } - it{ should_not be_able_to(:manage, other_registration) } - - it{ should be_able_to(:manage, my_event) } - it{ should_not be_able_to(:manage, other_event) } - it{ should be_able_to(:manage, my_event.event_type) } - it{ should_not be_able_to(:manage, other_event.event_type) } - it{ should be_able_to(:manage, my_event.track) } - it{ should_not be_able_to(:manage, other_event.track) } - it{ should be_able_to(:manage, my_event.difficulty_level) } - it{ should_not be_able_to(:manage, other_event.difficulty_level) } - it{ should be_able_to(:manage, my_event.commercials.first) } - it{ should_not be_able_to(:manage, other_event.commercials.first) } - it{ should be_able_to(:index, my_event.comment_threads.first) } - it{ should_not be_able_to(:index, other_event.comment_threads.first) } - - it{ should_not be_able_to(:manage, resource)} - it{ should be_able_to(:index, resource)} - it{ should be_able_to(:show, resource)} - it{ should be_able_to(:update, resource)} - - it_behaves_like 'user with any role' - it_behaves_like 'user with non-organizer role', 'cfp' - end - - context 'when user has the role info_desk' do - let(:role) { Role.find_by(name: 'info_desk', resource: my_conference) } - let(:user) { create(:user, role_ids: [role.id]) } - - it{ should_not be_able_to(:new, Conference.new) } - it{ should_not be_able_to(:create, Conference.new) } - it{ should_not be_able_to(:manage, my_conference) } - it{ should_not be_able_to(:manage, conference_public) } - it{ should_not be_able_to(:manage, my_conference.splashpage) } - it{ should_not be_able_to(:manage, conference_public.splashpage) } - it{ should_not be_able_to(:manage, my_conference.contact) } - it{ should_not be_able_to(:manage, conference_public.contact) } - it{ should_not be_able_to(:manage, my_conference.email_settings) } - it{ should_not be_able_to(:manage, conference_public.email_settings) } - it{ should_not be_able_to(:manage, my_conference.campaigns.first) } - it{ should_not be_able_to(:manage, conference_public.campaigns.first) } - it{ should_not be_able_to(:manage, my_conference.targets.first) } - it{ should_not be_able_to(:manage, conference_public.targets.first) } - it{ should_not be_able_to(:manage, my_conference.commercials.first) } - it{ should_not be_able_to(:manage, conference_public.commercials.first) } - it{ should_not be_able_to(:manage, my_conference.registration_period) } - it{ should_not be_able_to(:manage, conference_public.registration_period) } - it{ should be_able_to(:manage, my_conference.questions.first) } - it{ should_not be_able_to(:manage, conference_public.questions.first) } - it{ should_not be_able_to(:manage, my_conference.program.cfp) } - it{ should_not be_able_to(:manage, conference_public.program.cfp) } - it{ should_not be_able_to(:manage, my_schedule) } - it{ should_not be_able_to(:manage, other_schedule) } - it{ should_not be_able_to(:manage, my_event_schedule) } - it{ should_not be_able_to(:manage, other_event_schedule) } - it{ should_not be_able_to(:manage, my_conference.venue) } - it{ should_not be_able_to(:show, my_conference.venue) } - it{ should_not be_able_to(:manage, conference_public.venue) } - it{ should_not be_able_to(:manage, my_conference.lodgings.first) } - it{ should_not be_able_to(:manage, conference_public.lodgings.first) } - it{ should_not be_able_to(:manage, my_conference.sponsors.first) } - it{ should_not be_able_to(:manage, conference_public.sponsors.first) } - it{ should_not be_able_to(:manage, my_conference.sponsorship_levels.first) } - it{ should_not be_able_to(:manage, conference_public.sponsorship_levels.first) } - it{ should_not be_able_to(:manage, my_conference.tickets.first) } - it{ should_not be_able_to(:manage, conference_public.tickets.first) } - - it{ should be_able_to(:manage, my_registration) } - it{ should_not be_able_to(:manage, other_registration) } - - it{ should_not be_able_to(:manage, my_event) } - it{ should_not be_able_to(:manage, other_event) } - it{ should_not be_able_to(:manage, my_event.event_type) } - it{ should_not be_able_to(:manage, other_event.event_type) } - it{ should_not be_able_to(:manage, my_event.track) } - it{ should_not be_able_to(:manage, other_event.track) } - it{ should_not be_able_to(:manage, my_event.difficulty_level) } - it{ should_not be_able_to(:manage, other_event.difficulty_level) } - it{ should_not be_able_to(:manage, my_event.commercials.first) } - it{ should_not be_able_to(:manage, other_event.commercials.first) } - it{ should_not be_able_to(:index, my_event.comment_threads.first) } - it{ should_not be_able_to(:index, other_event.comment_threads.first) } - - it{ should_not be_able_to(:manage, resource)} - it{ should be_able_to(:index, resource)} - it{ should be_able_to(:show, resource)} - it{ should be_able_to(:update, resource)} - - it_behaves_like 'user with any role' - it_behaves_like 'user with non-organizer role', 'info_desk' - end - - context 'when user has the role volunteers_coordinator' do - let(:role) { Role.find_by(name: 'volunteers_coordinator', resource: my_conference) } - let(:user) { create(:user, role_ids: [role.id]) } - - it{ should_not be_able_to(:new, Conference.new) } - it{ should_not be_able_to(:create, Conference.new) } - it{ should_not be_able_to(:manage, my_conference) } - it{ should_not be_able_to(:manage, conference_public) } - it{ should_not be_able_to(:manage, my_conference.splashpage) } - it{ should_not be_able_to(:manage, conference_public.splashpage) } - it{ should_not be_able_to(:manage, my_conference.contact) } - it{ should_not be_able_to(:manage, conference_public.contact) } - it{ should_not be_able_to(:manage, my_conference.email_settings) } - it{ should_not be_able_to(:manage, conference_public.email_settings) } - it{ should_not be_able_to(:manage, my_conference.campaigns.first) } - it{ should_not be_able_to(:manage, conference_public.campaigns.first) } - it{ should_not be_able_to(:manage, my_conference.targets.first) } - it{ should_not be_able_to(:manage, conference_public.targets.first) } - it{ should_not be_able_to(:manage, my_conference.commercials.first) } - it{ should_not be_able_to(:manage, conference_public.commercials.first) } - it{ should_not be_able_to(:manage, my_conference.registration_period) } - it{ should_not be_able_to(:manage, conference_public.registration_period) } - it{ should_not be_able_to(:manage, my_conference.questions.first) } - it{ should_not be_able_to(:manage, conference_public.questions.first) } - it{ should_not be_able_to(:manage, my_conference.program.cfp) } - it{ should_not be_able_to(:manage, conference_public.program.cfp) } - it{ should_not be_able_to(:manage, my_schedule) } - it{ should_not be_able_to(:manage, other_schedule) } - it{ should_not be_able_to(:manage, my_event_schedule) } - it{ should_not be_able_to(:manage, other_event_schedule) } - it{ should_not be_able_to(:manage, my_conference.venue) } - it{ should_not be_able_to(:show, my_conference.venue) } - it{ should_not be_able_to(:manage, conference_public.venue) } - it{ should_not be_able_to(:manage, my_conference.lodgings.first) } - it{ should_not be_able_to(:manage, conference_public.lodgings.first) } - it{ should_not be_able_to(:manage, my_conference.sponsors.first) } - it{ should_not be_able_to(:manage, conference_public.sponsors.first) } - it{ should_not be_able_to(:manage, my_conference.sponsorship_levels.first) } - it{ should_not be_able_to(:manage, conference_public.sponsorship_levels.first) } - it{ should_not be_able_to(:manage, my_conference.tickets.first) } - it{ should_not be_able_to(:manage, conference_public.tickets.first) } - - it{ should_not be_able_to(:manage, registration) } - it{ should_not be_able_to(:manage, other_registration) } - - it{ should_not be_able_to(:manage, my_event) } - it{ should_not be_able_to(:manage, other_event) } - it{ should_not be_able_to(:manage, my_event.event_type) } - it{ should_not be_able_to(:manage, other_event.event_type) } - it{ should_not be_able_to(:manage, my_event.track) } - it{ should_not be_able_to(:manage, other_event.track) } - it{ should_not be_able_to(:manage, my_event.difficulty_level) } - it{ should_not be_able_to(:manage, other_event.difficulty_level) } - it{ should_not be_able_to(:manage, my_event.commercials.first) } - it{ should_not be_able_to(:manage, other_event.commercials.first) } - it{ should_not be_able_to(:index, my_event.comment_threads.first) } - it{ should_not be_able_to(:index, other_event.comment_threads.first) } - - it{ should_not be_able_to(:manage, resource)} - it{ should be_able_to(:index, resource)} - it{ should be_able_to(:show, resource)} - it{ should be_able_to(:update, resource)} - - it 'should be_able to :manage Vposition' - it 'should be_able to :manage Vday' - - it_behaves_like 'user with any role' - it_behaves_like 'user with non-organizer role', 'volunteers_coordinator' - end end end diff --git a/spec/models/admin_ability_spec.rb b/spec/models/admin_ability_spec.rb new file mode 100644 index 00000000..486ff295 --- /dev/null +++ b/spec/models/admin_ability_spec.rb @@ -0,0 +1,396 @@ +require 'spec_helper' +require 'cancan/matchers' + +describe 'User with admin role' do + describe 'Abilities' do + let!(:admin) { create(:admin) } + + # see https://github.com/CanCanCommunity/cancancan/wiki/Testing-Abilities + subject(:ability){ AdminAbility.new(user) } + let(:user){ nil } + + let!(:organization) { create(:organization) } + let!(:my_conference) { create(:full_conference, organization: organization) } + let(:my_venue) { my_conference.venue || create(:venue, conference: my_conference) } + let(:my_registration) { create(:registration, conference: my_conference, user: admin) } + + let(:other_registration) { create(:registration, conference: conference_public) } + let(:my_event) { create(:event_full, program: my_conference.program) } + let(:my_room) { create(:room, venue: my_conference.venue) } + let!(:my_event_scheduled) { create(:event_full, program: my_conference.program, room_id: my_room.id) } + let(:other_event) { create(:event_full, program: conference_public.program) } + + let(:conference_not_public) { create(:conference, splashpage: create(:splashpage, public: false)) } + let(:conference_public) { create(:full_conference, splashpage: create(:splashpage, public: true)) } + + let(:event_confirmed) { create(:event, state: 'confirmed') } + let(:event_unconfirmed) { create(:event) } + + let(:commercial_event_confirmed) { create(:commercial, commercialable: event_confirmed) } + let(:commercial_event_unconfirmed) { create(:commercial, commercialable: event_unconfirmed) } + let(:resource) { create(:resource, conference: my_conference) } + let(:registration) { create(:registration) } + + let(:program_with_cfp) { create(:program, :with_cfp) } + let(:program_without_cfp) { create(:program) } + let(:conference_with_open_registration) { create(:conference) } + let!(:open_registration_period) { create(:registration_period, conference: conference_with_open_registration, start_date: Date.current - 6.days) } + let(:conference_with_closed_registration) { create(:conference) } + let!(:closed_registration_period) { create(:registration_period, conference: conference_with_closed_registration, start_date: Date.current - 6.days, end_date: Date.current - 6.days) } + + let!(:my_schedule) { create(:schedule, program: my_conference.program) } + let!(:other_schedule) { create(:schedule, program: conference_public.program) } + + let!(:my_event_schedule) { create(:event_schedule, schedule: my_schedule) } + let!(:other_event_schedule) { create(:event_schedule, schedule: other_schedule) } + + context 'user #is_admin?' do + let(:venue) { my_conference.venue } + let(:room) { create(:room, venue: venue) } + let!(:event) { create(:event_full, program: my_conference.program, room_id: room.id) } + let(:user) { create(:admin) } + it{ should be_able_to(:manage, :all) } + it{ should_not be_able_to(:destroy, my_conference.program) } + it{ should_not be_able_to(:destroy, my_venue) } + end + + shared_examples 'user with any role' do + let!(:other_organization) { create(:organization) } + let!(:other_conference) { create(:conference, organization: other_organization) } + + it{ should_not be_able_to(:update, Role.find_by(name: 'organization_admin', resource: other_organization)) } + it{ should_not be_able_to(:edit, Role.find_by(name: 'organization_admin', resource: other_organization)) } + it{ should_not be_able_to(:show, Role.find_by(name: 'organization_admin', resource: other_organization)) } + + %w[organizer cfp info_desk volunteers_coordinator].each do |role| + it{ should_not be_able_to(:toggle_user, Role.find_by(name: role, resource: other_conference)) } + it{ should_not be_able_to(:update, Role.find_by(name: role, resource: other_conference)) } + it{ should_not be_able_to(:edit, Role.find_by(name: role, resource: other_conference)) } + it{ should be_able_to(:show, Role.find_by(name: role, resource: other_conference)) } + it{ should be_able_to(:index, Role.find_by(name: role, resource: other_conference)) } + end + end + + shared_examples 'user with non-organizer role' do |role_name| + %w[organizer cfp info_desk volunteers_coordinator].each do |role| + if role == role_name + it{ should be_able_to(:toggle_user, Role.find_by(name: role, resource: my_conference)) } + else + it{ should_not be_able_to(:toggle_user, Role.find_by(name: role, resource: my_conference)) } + end + it{ should_not be_able_to(:update, Role.find_by(name: role, resource: my_conference)) } + it{ should_not be_able_to(:edit, Role.find_by(name: role, resource: my_conference)) } + it{ should be_able_to(:show, Role.find_by(name: role, resource: my_conference)) } + it{ should be_able_to(:index, Role.find_by(name: role, resource: my_conference)) } + end + end + + context 'when user has the role organization_admin' do + let(:role) { Role.find_by(name: 'organization_admin', resource: organization) } + let(:user) { create(:user, role_ids: [role.id]) } + let(:other_organization) { create(:organization) } + let(:other_conference) { create(:conference, organization: other_organization) } + + it{ should be_able_to(:manage, my_conference) } + it{ should be_able_to(:read, organization) } + it{ should be_able_to(:update, organization) } + it{ should be_able_to(:destroy, organization) } + it{ should be_able_to(:new, Conference.new) } + it{ should be_able_to(:create, Conference.new(organization_id: organization.id)) } + it{ should_not be_able_to(:manage, other_conference) } + it{ should_not be_able_to(:create, Conference.new(organization_id: other_organization.id)) } + it{ should_not be_able_to(:new, Organization.new) } + it{ should_not be_able_to(:create, Organization.new) } + end + + context 'when user has the role organizer' do + let(:role) { Role.find_by(name: 'organizer', resource: my_conference) } + let(:user) { create(:user, role_ids: [role.id]) } + + it{ should_not be_able_to(:destroy, my_conference.program) } + it 'when there is a room assigned to an event' do + should_not be_able_to(:destroy, my_venue) + end + + it 'when there are no rooms used' do + my_event_scheduled.room_id = nil + my_event_scheduled.save! + my_event_scheduled.reload + should be_able_to(:destroy, my_venue) + end + + it{ should_not be_able_to(:new, Organization.new) } + it{ should_not be_able_to(:create, Organization.new) } + it{ should_not be_able_to(:new, Conference.new) } + it{ should_not be_able_to(:create, Conference.new) } + it{ should be_able_to(:read, my_conference) } + it{ should be_able_to(:update, my_conference) } + it{ should be_able_to(:destroy, my_conference) } + it{ should_not be_able_to(:manage, conference_public) } + it{ should be_able_to(:manage, my_conference.splashpage) } + it{ should_not be_able_to(:manage, conference_public.splashpage) } + it{ should be_able_to(:manage, my_conference.contact) } + it{ should_not be_able_to(:manage, conference_public.contact) } + it{ should be_able_to(:manage, my_conference.email_settings) } + it{ should_not be_able_to(:manage, conference_public.email_settings) } + it{ should be_able_to(:manage, my_conference.campaigns.first) } + it{ should_not be_able_to(:manage, conference_public.campaigns.first) } + it{ should be_able_to(:manage, my_conference.targets.first) } + it{ should_not be_able_to(:manage, conference_public.targets.first) } + it{ should be_able_to(:manage, my_conference.commercials.first) } + it{ should_not be_able_to(:manage, conference_public.commercials.first) } + it{ should be_able_to(:manage, my_conference.registration_period) } + it{ should_not be_able_to(:manage, conference_public.registration_period) } + it{ should be_able_to(:manage, my_conference.questions.first) } + it{ should_not be_able_to(:manage, conference_public.questions.first) } + it{ should be_able_to(:manage, my_conference.program.cfp) } + it{ should_not be_able_to(:manage, conference_public.program.cfp) } + it{ should be_able_to(:manage, my_schedule) } + it{ should_not be_able_to(:manage, other_schedule) } + it{ should be_able_to(:manage, my_event_schedule) } + it{ should_not be_able_to(:manage, other_event_schedule) } + it{ should be_able_to(:manage, my_conference.venue) } + it{ should_not be_able_to(:manage, conference_public.venue) } + it{ should be_able_to(:manage, my_conference.lodgings.first) } + it{ should_not be_able_to(:manage, conference_public.lodgings.first) } + it{ should be_able_to(:manage, my_conference.sponsors.first) } + it{ should_not be_able_to(:manage, conference_public.sponsors.first) } + it{ should be_able_to(:manage, my_conference.sponsorship_levels.first) } + it{ should_not be_able_to(:manage, conference_public.sponsorship_levels.first) } + it{ should be_able_to(:manage, my_conference.tickets.first) } + it{ should_not be_able_to(:manage, conference_public.tickets.first) } + + it{ should be_able_to(:manage, my_registration) } + it{ should_not be_able_to(:manage, other_registration) } + + it{ should be_able_to(:manage, my_event) } + it{ should_not be_able_to(:manage, other_event) } + it{ should be_able_to(:manage, my_event.event_type) } + it{ should_not be_able_to(:manage, other_event.event_type) } + it{ should be_able_to(:manage, my_event.track) } + it{ should_not be_able_to(:manage, other_event.track) } + it{ should be_able_to(:manage, my_event.difficulty_level) } + it{ should_not be_able_to(:manage, other_event.difficulty_level) } + it{ should be_able_to(:manage, my_event.commercials.first) } + it{ should_not be_able_to(:manage, other_event.commercials.first) } + it{ should be_able_to(:index, my_event.comment_threads.first) } + it{ should_not be_able_to(:index, other_event.comment_threads.first) } + + it{ should be_able_to(:manage, resource) } + + %w[organizer cfp info_desk volunteers_coordinator].each do |role| + it{ should be_able_to(:toggle_user, Role.find_by(name: role, resource: my_conference)) } + it{ should be_able_to(:edit, Role.find_by(name: role, resource: my_conference)) } + it{ should be_able_to(:update, Role.find_by(name: role, resource: my_conference)) } + it{ should be_able_to(:show, Role.find_by(name: role, resource: my_conference)) } + it{ should be_able_to(:index, Role.find_by(name: role, resource: my_conference)) } + end + + it_behaves_like 'user with any role' + end + + context 'when user has the role cfp' do + let(:role) { Role.find_by(name: 'cfp', resource: my_conference) } + let(:user) { create(:user, role_ids: [role.id]) } + + it{ should_not be_able_to(:new, Conference.new) } + it{ should_not be_able_to(:create, Conference.new) } + it{ should_not be_able_to(:manage, my_conference) } + it{ should_not be_able_to(:manage, conference_public) } + it{ should_not be_able_to(:manage, my_conference.splashpage) } + it{ should_not be_able_to(:manage, conference_public.splashpage) } + it{ should_not be_able_to(:manage, my_conference.contact) } + it{ should_not be_able_to(:manage, conference_public.contact) } + it{ should be_able_to(:manage, my_conference.email_settings) } + it{ should_not be_able_to(:manage, conference_public.email_settings) } + it{ should_not be_able_to(:manage, my_conference.campaigns.first) } + it{ should_not be_able_to(:manage, conference_public.campaigns.first) } + it{ should_not be_able_to(:manage, my_conference.targets.first) } + it{ should_not be_able_to(:manage, conference_public.targets.first) } + it{ should_not be_able_to(:manage, my_conference.commercials.first) } + it{ should_not be_able_to(:manage, conference_public.commercials.first) } + it{ should_not be_able_to(:manage, my_conference.registration_period) } + it{ should_not be_able_to(:manage, conference_public.registration_period) } + it{ should_not be_able_to(:manage, my_conference.questions.first) } + it{ should_not be_able_to(:manage, conference_public.questions.first) } + it{ should be_able_to(:manage, my_conference.program.cfp) } + it{ should_not be_able_to(:manage, conference_public.program.cfp) } + it{ should be_able_to(:manage, my_schedule) } + it{ should_not be_able_to(:manage, other_schedule) } + it{ should_not be_able_to(:manage, my_event_schedule) } + it{ should_not be_able_to(:manage, other_event_schedule) } + it{ should_not be_able_to(:manage, my_conference.venue) } + it{ should be_able_to(:show, my_conference.venue) } + it{ should_not be_able_to(:manage, conference_public.venue) } + it{ should_not be_able_to(:manage, my_conference.lodgings.first) } + it{ should_not be_able_to(:manage, conference_public.lodgings.first) } + it{ should_not be_able_to(:manage, my_conference.sponsors.first) } + it{ should_not be_able_to(:manage, conference_public.sponsors.first) } + it{ should_not be_able_to(:manage, my_conference.sponsorship_levels.first) } + it{ should_not be_able_to(:manage, conference_public.sponsorship_levels.first) } + it{ should_not be_able_to(:manage, my_conference.tickets.first) } + it{ should_not be_able_to(:manage, conference_public.tickets.first) } + + it{ should_not be_able_to(:manage, my_registration) } + it{ should_not be_able_to(:manage, other_registration) } + + it{ should be_able_to(:manage, my_event) } + it{ should_not be_able_to(:manage, other_event) } + it{ should be_able_to(:manage, my_event.event_type) } + it{ should_not be_able_to(:manage, other_event.event_type) } + it{ should be_able_to(:manage, my_event.track) } + it{ should_not be_able_to(:manage, other_event.track) } + it{ should be_able_to(:manage, my_event.difficulty_level) } + it{ should_not be_able_to(:manage, other_event.difficulty_level) } + it{ should be_able_to(:manage, my_event.commercials.first) } + it{ should_not be_able_to(:manage, other_event.commercials.first) } + it{ should be_able_to(:index, my_event.comment_threads.first) } + it{ should_not be_able_to(:index, other_event.comment_threads.first) } + + it{ should_not be_able_to(:manage, resource) } + it{ should be_able_to(:index, resource) } + it{ should be_able_to(:show, resource) } + it{ should be_able_to(:update, resource) } + + it_behaves_like 'user with any role' + it_behaves_like 'user with non-organizer role', 'cfp' + end + + context 'when user has the role info_desk' do + let(:role) { Role.find_by(name: 'info_desk', resource: my_conference) } + let(:user) { create(:user, role_ids: [role.id]) } + + it{ should_not be_able_to(:new, Conference.new) } + it{ should_not be_able_to(:create, Conference.new) } + it{ should_not be_able_to(:manage, my_conference) } + it{ should_not be_able_to(:manage, conference_public) } + it{ should_not be_able_to(:manage, my_conference.splashpage) } + it{ should_not be_able_to(:manage, conference_public.splashpage) } + it{ should_not be_able_to(:manage, my_conference.contact) } + it{ should_not be_able_to(:manage, conference_public.contact) } + it{ should_not be_able_to(:manage, my_conference.email_settings) } + it{ should_not be_able_to(:manage, conference_public.email_settings) } + it{ should_not be_able_to(:manage, my_conference.campaigns.first) } + it{ should_not be_able_to(:manage, conference_public.campaigns.first) } + it{ should_not be_able_to(:manage, my_conference.targets.first) } + it{ should_not be_able_to(:manage, conference_public.targets.first) } + it{ should_not be_able_to(:manage, my_conference.commercials.first) } + it{ should_not be_able_to(:manage, conference_public.commercials.first) } + it{ should_not be_able_to(:manage, my_conference.registration_period) } + it{ should_not be_able_to(:manage, conference_public.registration_period) } + it{ should be_able_to(:manage, my_conference.questions.first) } + it{ should_not be_able_to(:manage, conference_public.questions.first) } + it{ should_not be_able_to(:manage, my_conference.program.cfp) } + it{ should_not be_able_to(:manage, conference_public.program.cfp) } + it{ should_not be_able_to(:manage, my_schedule) } + it{ should_not be_able_to(:manage, other_schedule) } + it{ should_not be_able_to(:manage, my_event_schedule) } + it{ should_not be_able_to(:manage, other_event_schedule) } + it{ should_not be_able_to(:manage, my_conference.venue) } + it{ should_not be_able_to(:show, my_conference.venue) } + it{ should_not be_able_to(:manage, conference_public.venue) } + it{ should_not be_able_to(:manage, my_conference.lodgings.first) } + it{ should_not be_able_to(:manage, conference_public.lodgings.first) } + it{ should_not be_able_to(:manage, my_conference.sponsors.first) } + it{ should_not be_able_to(:manage, conference_public.sponsors.first) } + it{ should_not be_able_to(:manage, my_conference.sponsorship_levels.first) } + it{ should_not be_able_to(:manage, conference_public.sponsorship_levels.first) } + it{ should_not be_able_to(:manage, my_conference.tickets.first) } + it{ should_not be_able_to(:manage, conference_public.tickets.first) } + + it{ should be_able_to(:manage, my_registration) } + it{ should_not be_able_to(:manage, other_registration) } + + it{ should_not be_able_to(:manage, my_event) } + it{ should_not be_able_to(:manage, other_event) } + it{ should_not be_able_to(:manage, my_event.event_type) } + it{ should_not be_able_to(:manage, other_event.event_type) } + it{ should_not be_able_to(:manage, my_event.track) } + it{ should_not be_able_to(:manage, other_event.track) } + it{ should_not be_able_to(:manage, my_event.difficulty_level) } + it{ should_not be_able_to(:manage, other_event.difficulty_level) } + it{ should_not be_able_to(:manage, my_event.commercials.first) } + it{ should_not be_able_to(:manage, other_event.commercials.first) } + it{ should_not be_able_to(:index, my_event.comment_threads.first) } + it{ should_not be_able_to(:index, other_event.comment_threads.first) } + + it{ should_not be_able_to(:manage, resource) } + it{ should be_able_to(:index, resource) } + it{ should be_able_to(:show, resource) } + it{ should be_able_to(:update, resource) } + + it_behaves_like 'user with any role' + it_behaves_like 'user with non-organizer role', 'info_desk' + end + + context 'when user has the role volunteers_coordinator' do + let(:role) { Role.find_by(name: 'volunteers_coordinator', resource: my_conference) } + let(:user) { create(:user, role_ids: [role.id]) } + + it{ should_not be_able_to(:new, Conference.new) } + it{ should_not be_able_to(:create, Conference.new) } + it{ should_not be_able_to(:manage, my_conference) } + it{ should_not be_able_to(:manage, conference_public) } + it{ should_not be_able_to(:manage, my_conference.splashpage) } + it{ should_not be_able_to(:manage, conference_public.splashpage) } + it{ should_not be_able_to(:manage, my_conference.contact) } + it{ should_not be_able_to(:manage, conference_public.contact) } + it{ should_not be_able_to(:manage, my_conference.email_settings) } + it{ should_not be_able_to(:manage, conference_public.email_settings) } + it{ should_not be_able_to(:manage, my_conference.campaigns.first) } + it{ should_not be_able_to(:manage, conference_public.campaigns.first) } + it{ should_not be_able_to(:manage, my_conference.targets.first) } + it{ should_not be_able_to(:manage, conference_public.targets.first) } + it{ should_not be_able_to(:manage, my_conference.commercials.first) } + it{ should_not be_able_to(:manage, conference_public.commercials.first) } + it{ should_not be_able_to(:manage, my_conference.registration_period) } + it{ should_not be_able_to(:manage, conference_public.registration_period) } + it{ should_not be_able_to(:manage, my_conference.questions.first) } + it{ should_not be_able_to(:manage, conference_public.questions.first) } + it{ should_not be_able_to(:manage, my_conference.program.cfp) } + it{ should_not be_able_to(:manage, conference_public.program.cfp) } + it{ should_not be_able_to(:manage, my_schedule) } + it{ should_not be_able_to(:manage, other_schedule) } + it{ should_not be_able_to(:manage, my_event_schedule) } + it{ should_not be_able_to(:manage, other_event_schedule) } + it{ should_not be_able_to(:manage, my_conference.venue) } + it{ should_not be_able_to(:show, my_conference.venue) } + it{ should_not be_able_to(:manage, conference_public.venue) } + it{ should_not be_able_to(:manage, my_conference.lodgings.first) } + it{ should_not be_able_to(:manage, conference_public.lodgings.first) } + it{ should_not be_able_to(:manage, my_conference.sponsors.first) } + it{ should_not be_able_to(:manage, conference_public.sponsors.first) } + it{ should_not be_able_to(:manage, my_conference.sponsorship_levels.first) } + it{ should_not be_able_to(:manage, conference_public.sponsorship_levels.first) } + it{ should_not be_able_to(:manage, my_conference.tickets.first) } + it{ should_not be_able_to(:manage, conference_public.tickets.first) } + + it{ should_not be_able_to(:manage, registration) } + it{ should_not be_able_to(:manage, other_registration) } + + it{ should_not be_able_to(:manage, my_event) } + it{ should_not be_able_to(:manage, other_event) } + it{ should_not be_able_to(:manage, my_event.event_type) } + it{ should_not be_able_to(:manage, other_event.event_type) } + it{ should_not be_able_to(:manage, my_event.track) } + it{ should_not be_able_to(:manage, other_event.track) } + it{ should_not be_able_to(:manage, my_event.difficulty_level) } + it{ should_not be_able_to(:manage, other_event.difficulty_level) } + it{ should_not be_able_to(:manage, my_event.commercials.first) } + it{ should_not be_able_to(:manage, other_event.commercials.first) } + it{ should_not be_able_to(:index, my_event.comment_threads.first) } + it{ should_not be_able_to(:index, other_event.comment_threads.first) } + + it{ should_not be_able_to(:manage, resource) } + it{ should be_able_to(:index, resource) } + it{ should be_able_to(:show, resource) } + it{ should be_able_to(:update, resource) } + + it 'should be_able to :manage Vposition' + it 'should be_able to :manage Vday' + + it_behaves_like 'user with any role' + it_behaves_like 'user with non-organizer role', 'volunteers_coordinator' + end + end +end