diff --git a/app/models/admin_ability.rb b/app/models/admin_ability.rb index 4244d049..716aecb0 100644 --- a/app/models/admin_ability.rb +++ b/app/models/admin_ability.rb @@ -18,7 +18,6 @@ class AdminAbility end def common_abilities_for_roles(user) - can :manage, User, id: user.id can :manage, Registration, user_id: user.id can :index, Conference diff --git a/spec/features/cfp_ability_spec.rb b/spec/features/cfp_ability_spec.rb index 46db11c2..d40a54a4 100644 --- a/spec/features/cfp_ability_spec.rb +++ b/spec/features/cfp_ability_spec.rb @@ -269,6 +269,12 @@ feature 'Has correct abilities' do visit edit_admin_conference_resource_path(conference.short_title, conference.resources.first) expect(current_path).to eq(edit_admin_conference_resource_path(conference.short_title, conference.resources.first)) + visit admin_users_path + expect(current_path).to eq(root_path) + + visit admin_user_path(user_cfp) + expect(current_path).to eq(root_path) + visit admin_revision_history_path expect(current_path).to eq(root_path) end diff --git a/spec/features/info_desk_ability_spec.rb b/spec/features/info_desk_ability_spec.rb index 20aa586b..c005f9de 100644 --- a/spec/features/info_desk_ability_spec.rb +++ b/spec/features/info_desk_ability_spec.rb @@ -237,6 +237,12 @@ feature 'Has correct abilities' do visit admin_conference_program_tracks_path(conference.short_title) expect(current_path).to eq(root_path) + visit admin_users_path + expect(current_path).to eq(root_path) + + visit admin_user_path(user_info_desk) + expect(current_path).to eq(root_path) + visit admin_conference_emails_path(conference.short_title) expect(current_path).to eq(root_path) end diff --git a/spec/features/organizer_ability_spec.rb b/spec/features/organizer_ability_spec.rb index 06a2a836..3ed6ee39 100644 --- a/spec/features/organizer_ability_spec.rb +++ b/spec/features/organizer_ability_spec.rb @@ -266,6 +266,12 @@ feature 'Has correct abilities' do visit edit_admin_conference_resource_path(conference.short_title, conference.resources.first) expect(current_path).to eq(edit_admin_conference_resource_path(conference.short_title, conference.resources.first)) + visit admin_users_path + expect(current_path).to eq(root_path) + + visit admin_user_path(user_organizer) + expect(current_path).to eq(root_path) + visit admin_revision_history_path expect(current_path).to eq(admin_revision_history_path) end diff --git a/spec/models/admin_ability_spec.rb b/spec/models/admin_ability_spec.rb index 9baae4a9..5398b7d2 100644 --- a/spec/models/admin_ability_spec.rb +++ b/spec/models/admin_ability_spec.rb @@ -64,6 +64,10 @@ describe 'User with admin role' do it{ should_not be_able_to(:edit, Role.find_by(name: 'organization_admin', resource: other_organization)) } it{ should_not be_able_to(:show, Role.find_by(name: 'organization_admin', resource: other_organization)) } + it{ should_not be_able_to(:new, User.new) } + it{ should_not be_able_to(:create, User.new) } + it{ should_not be_able_to(:manage, User) } + %w[organizer cfp info_desk volunteers_coordinator].each do |role| it{ should_not be_able_to(:toggle_user, Role.find_by(name: role, resource: other_conference)) } it{ should_not be_able_to(:update, Role.find_by(name: role, resource: other_conference)) }