diff --git a/Gemfile b/Gemfile index 01c8a4f0..03c0a34e 100644 --- a/Gemfile +++ b/Gemfile @@ -23,6 +23,9 @@ gem 'omniauth-google-oauth2' # Use cancancan as authorization framework gem 'cancancan' +# Use rolify to set roles +gem 'rolify' + # Use transitions as state machine gem 'transitions', :require => %w( transitions active_record/transitions ) diff --git a/Gemfile.lock b/Gemfile.lock index 5c4b58ac..7152bfcb 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -296,6 +296,7 @@ GEM request_store (1.0.6) rest-client (1.6.7) mime-types (>= 1.16) + rolify (3.4.0) rspec (3.0.0) rspec-core (~> 3.0.0) rspec-expectations (~> 3.0.0) @@ -441,6 +442,7 @@ DEPENDENCIES rails-observers rdoc-generator-fivefish redcarpet + rolify rspec-activemodel-mocks rspec-rails rubocop diff --git a/app/controllers/admin/callforpapers_controller.rb b/app/controllers/admin/callforpapers_controller.rb index b97bebb0..c18e6018 100644 --- a/app/controllers/admin/callforpapers_controller.rb +++ b/app/controllers/admin/callforpapers_controller.rb @@ -1,52 +1,55 @@ -class Admin::CallforpapersController < ApplicationController - before_filter :verify_organizer +module Admin + class CallforpapersController < ApplicationController + load_and_authorize_resource :conference, find_by: :short_title +# load_and_authorize_resource :call_for_paper, class: 'CallForPapers', through: :conference - def show - @cfp = @conference.call_for_papers - if @cfp.nil? - @cfp = CallForPapers.new + def show + @cfp = @conference.call_for_papers + if @cfp.nil? + @cfp = CallForPapers.new + end end - end - def update - @cfp = @conference.call_for_papers - @cfp.assign_attributes(params[:call_for_papers]) - notify_on_schedule_public = @cfp.schedule_public_changed? && @cfp.schedule_public\ - && @conference.email_settings.send_on_call_for_papers_schedule_public\ - && !@conference.email_settings.call_for_papers_schedule_public_subject.blank?\ - && !@conference.email_settings.call_for_papers_schedule_public_template.blank? + def update + @cfp = @conference.call_for_papers + @cfp.assign_attributes(params[:call_for_papers]) + notify_on_schedule_public = @cfp.schedule_public_changed? && @cfp.schedule_public\ + && @conference.email_settings.send_on_call_for_papers_schedule_public\ + && !@conference.email_settings.call_for_papers_schedule_public_subject.blank?\ + && !@conference.email_settings.call_for_papers_schedule_public_template.blank? - notify_on_cfp_date_update = !@cfp.end_date.blank? && !@cfp.start_date.blank?\ - && (@cfp.start_date_changed? || @cfp.end_date_changed?)\ - && @conference.email_settings.send_on_call_for_papers_dates_updates\ - && !@conference.email_settings.call_for_papers_dates_updates_subject.blank?\ - && !@conference.email_settings.call_for_papers_dates_updates_template.blank? + notify_on_cfp_date_update = !@cfp.end_date.blank? && !@cfp.start_date.blank?\ + && (@cfp.start_date_changed? || @cfp.end_date_changed?)\ + && @conference.email_settings.send_on_call_for_papers_dates_updates\ + && !@conference.email_settings.call_for_papers_dates_updates_subject.blank?\ + && !@conference.email_settings.call_for_papers_dates_updates_template.blank? - if @cfp.update_attributes(params[:call_for_papers]) - Mailbot.delay.send_on_call_for_papers_dates_updates(@conference) if notify_on_cfp_date_update - Mailbot.delay.send_on_schedule_public(@conference) if notify_on_schedule_public - redirect_to(admin_conference_callforpapers_path( - id: @conference.short_title), - notice: 'Call for Papers was successfully updated.') - else - redirect_to(admin_conference_callforpapers_path( - id: @conference.short_title), - alert: "Updating call for papers failed. #{@cfp.errors.to_a.join(". ")}.") + if @cfp.update_attributes(params[:call_for_papers]) + Mailbot.delay.send_on_call_for_papers_dates_updates(@conference) if notify_on_cfp_date_update + Mailbot.delay.send_on_schedule_public(@conference) if notify_on_schedule_public + redirect_to(admin_conference_callforpapers_path( + id: @conference.short_title), + notice: 'Call for Papers was successfully updated.') + else + redirect_to(admin_conference_callforpapers_path( + id: @conference.short_title), + alert: "Updating call for papers failed. #{@cfp.errors.to_a.join(". ")}.") + end end - end - def create - @cfp = CallForPapers.new(params[:call_for_papers]) - if @cfp.valid? - @cfp.save - @conference.call_for_papers = @cfp - redirect_to(admin_conference_callforpapers_path( - id: @conference.short_title), - notice: 'Call for Papers was successfully created.') - else - redirect_to(admin_conference_callforpapers_path( - id: @conference.short_title), - alert: "Creating the call for papers failed. #{@cfp.errors.to_a.join(". ")}.") + def create + @cfp = CallForPapers.new(params[:call_for_papers]) + if @cfp.valid? + @cfp.save + @conference.call_for_papers = @cfp + redirect_to(admin_conference_callforpapers_path( + id: @conference.short_title), + notice: 'Call for Papers was successfully created.') + else + redirect_to(admin_conference_callforpapers_path( + id: @conference.short_title), + alert: "Creating the call for papers failed. #{@cfp.errors.to_a.join(". ")}.") + end end end end diff --git a/app/controllers/admin/campaigns_controller.rb b/app/controllers/admin/campaigns_controller.rb index 68c4521d..a51ee16e 100644 --- a/app/controllers/admin/campaigns_controller.rb +++ b/app/controllers/admin/campaigns_controller.rb @@ -1,6 +1,7 @@ module Admin class CampaignsController < ApplicationController - before_filter :verify_organizer + load_and_authorize_resource :conference, find_by: :short_title + load_and_authorize_resource :campaign, through: :conference def index @conference = Conference.find_by(short_title: params[:conference_id]) diff --git a/app/controllers/admin/conference_controller.rb b/app/controllers/admin/conference_controller.rb index 7b1867e5..34cd0d10 100644 --- a/app/controllers/admin/conference_controller.rb +++ b/app/controllers/admin/conference_controller.rb @@ -1,133 +1,136 @@ -class Admin::ConferenceController < ApplicationController - before_filter :verify_organizer +module Admin + class ConferenceController < ApplicationController + load_and_authorize_resource :conference, find_by: :short_title - def index - # Redirect to new form if there is no conference - if Conference.count == 0 - redirect_to new_admin_conference_path - return + def index + # Redirect to new form if there is no conference + if Conference.count == 0 + redirect_to new_admin_conference_path + return + end + + @total_user = User.count + @new_user = User.where('created_at > ?', current_user.last_sign_in_at).count + + @total_reg = Registration.count + @new_reg = Registration.where('created_at > ?', current_user.last_sign_in_at).count + + @total_submissions = Event.count + @new_submissions = Event.where('created_at > ?', current_user.last_sign_in_at).count + + @active_conferences = Conference.get_active_conferences_for_dashboard # pending or the last two + @deactive_conferences = Conference. + get_conferences_without_active_for_dashboard(@active_conferences) # conferences without active + @conferences = @active_conferences + @deactive_conferences + + @recent_users = User.limit(5).order(created_at: :desc) + @recent_events = Event.limit(5).order(created_at: :desc) + @recent_registrations = Registration.limit(5).order(created_at: :desc) + + @top_submitter = Conference.get_top_submitter + + @submissions = {} + @cfp_weeks = [0] + + @registrations = {} + @registration_weeks = [0] + + @conferences.each do |c| + # Event submissions over time chart + @submissions[c.short_title] = c.get_submissions_per_week + @cfp_weeks.push(@submissions[c.short_title].length) + + # Conference registrations over time chart + @registrations[c.short_title] = c.get_registrations_per_week + @registration_weeks.push(@registrations[c.short_title].length) + end + + @cfp_weeks = @cfp_weeks.max + @submissions = normalize_array_length(@submissions, @cfp_weeks) + @cfp_weeks = @cfp_weeks > 0 ? (1..@cfp_weeks).to_a : 1 + + @registration_weeks = @registration_weeks.max + @registrations = normalize_array_length(@registrations, @registration_weeks) + @registration_weeks = @registration_weeks > 0 ? (1..@registration_weeks).to_a : 1 + + @event_distribution = Conference.event_distribution + @user_distribution = Conference.user_distribution end - @total_user = User.count - @new_user = User.where('created_at > ?', current_user.last_sign_in_at).count - - @total_reg = Registration.count - @new_reg = Registration.where('created_at > ?', current_user.last_sign_in_at).count - - @total_submissions = Event.count - @new_submissions = Event.where('created_at > ?', current_user.last_sign_in_at).count - - @active_conferences = Conference.get_active_conferences_for_dashboard # pending or the last two - @deactive_conferences = Conference. - get_conferences_without_active_for_dashboard(@active_conferences) # conferences without active - @conferences = @active_conferences + @deactive_conferences - - @recent_users = User.limit(5).order(created_at: :desc) - @recent_events = Event.limit(5).order(created_at: :desc) - @recent_registrations = Registration.limit(5).order(created_at: :desc) - - @top_submitter = Conference.get_top_submitter - - @submissions = {} - @cfp_weeks = [0] - - @registrations = {} - @registration_weeks = [0] - - @conferences.each do |c| - # Event submissions over time chart - @submissions[c.short_title] = c.get_submissions_per_week - @cfp_weeks.push(@submissions[c.short_title].length) - - # Conference registrations over time chart - @registrations[c.short_title] = c.get_registrations_per_week - @registration_weeks.push(@registrations[c.short_title].length) + def new + @conference = Conference.new end - @cfp_weeks = @cfp_weeks.max - @submissions = normalize_array_length(@submissions, @cfp_weeks) - @cfp_weeks = @cfp_weeks > 0 ? (1..@cfp_weeks).to_a : 1 + def create + @conference = Conference.new(params[:conference]) - @registration_weeks = @registration_weeks.max - @registrations = normalize_array_length(@registrations, @registration_weeks) - @registration_weeks = @registration_weeks > 0 ? (1..@registration_weeks).to_a : 1 - - @event_distribution = Conference.event_distribution - @user_distribution = Conference.user_distribution - end - - def new - @conference = Conference.new - end - - def create - @conference = Conference.new(params[:conference]) - if @conference.valid? - @conference.save - redirect_to(admin_conference_path(id: @conference.short_title), - notice: 'Conference was successfully created.') - else - render action: 'new' - end - end - - def update - @conference = Conference.find_by(short_title: params[:id]) - short_title = @conference.short_title - @conference.assign_attributes(params[:conference]) - if @conference.start_date_changed? || @conference.end_date_changed? - if @conference.email_settings.send_on_updated_conference_dates && - !@conference.email_settings.updated_conference_dates_subject.blank? && - @conference.email_settings.updated_conference_dates_template - Mailbot.conference_date_update_mail(@conference).deliver + if @conference.valid? + @conference.save + # user that creates the conference becomes organizer of that conference + current_user.add_role :organizer, @conference + redirect_to(admin_conference_path(id: @conference.short_title), + notice: 'Conference was successfully created.') + else + render action: 'new' end end - if @conference.registration_start_date_changed? || @conference.registration_end_date_changed? - if @conference.email_settings.send_on_updated_conference_registration_dates && - !@conference.email_settings.updated_conference_registration_dates_subject.blank? && - @conference.email_settings.updated_conference_registration_dates_template - Mailbot.conference_registration_date_update_mail(@conference).deliver + def update + short_title = @conference.short_title + @conference.assign_attributes(params[:conference]) + if @conference.start_date_changed? || @conference.end_date_changed? + if @conference.email_settings.send_on_updated_conference_dates && + !@conference.email_settings.updated_conference_dates_subject.blank? && + @conference.email_settings.updated_conference_dates_template + Mailbot.conference_date_update_mail(@conference).deliver + end + end + + if @conference.registration_start_date_changed? || @conference.registration_end_date_changed? + if @conference.email_settings.send_on_updated_conference_registration_dates && + !@conference.email_settings.updated_conference_registration_dates_subject.blank? && + @conference.email_settings.updated_conference_registration_dates_template + Mailbot.conference_registration_date_update_mail(@conference).deliver + end + end + + if @conference.update_attributes(params[:conference]) + redirect_to(edit_admin_conference_path(id: @conference.short_title), + notice: 'Conference was successfully updated.') + else + redirect_to(edit_admin_conference_path(id: short_title), + alert: 'Updating conference failed. ' \ + "#{@conference.errors.full_messages.join('. ')}.") end end - if @conference.update_attributes(params[:conference]) - redirect_to(edit_admin_conference_path(id: @conference.short_title), - notice: 'Conference was successfully updated.') - else - redirect_to(edit_admin_conference_path(id: short_title), - alert: 'Updating conference failed. ' \ - "#{@conference.errors.full_messages.join('. ')}.") - end - end + def show + @conference = Conference.find_by(short_title: params[:id]) - def show - @conference = Conference.find_by(short_title: params[:id]) + # Overview and since last login information + @total_reg = @conference.registrations.count + @new_reg = @conference.registrations.where('created_at > ?', current_user.last_sign_in_at).count - # Overview and since last login information - @total_reg = @conference.registrations.count - @new_reg = @conference.registrations.where('created_at > ?', current_user.last_sign_in_at).count + @total_submissions = @conference.events.count + @new_submissions = @conference.events. + where('created_at > ?', current_user.last_sign_in_at).count - @total_submissions = @conference.events.count - @new_submissions = @conference.events. - where('created_at > ?', current_user.last_sign_in_at).count + @program_length = @conference.current_program_hours + @new_program_length = @conference.new_program_hours(current_user.last_sign_in_at) - @program_length = @conference.current_program_hours - @new_program_length = @conference.new_program_hours(current_user.last_sign_in_at) + # Step by step list + @conference_progress = @conference.get_status - # Step by step list - @conference_progress = @conference.get_status + # Line charts + @registrations = { @conference.short_title => @conference.get_registrations_per_week } + @registration_weeks = [0] + @registration_weeks.push(@registrations[@conference.short_title].length) - # Line charts - @registrations = { @conference.short_title => @conference.get_registrations_per_week } - @registration_weeks = [0] - @registration_weeks.push(@registrations[@conference.short_title].length) + @registration_weeks = @registration_weeks.max + @registrations = normalize_array_length(@registrations, @registration_weeks) + @registration_weeks = @registration_weeks > 0 ? (1..@registration_weeks).to_a : 1 - @registration_weeks = @registration_weeks.max - @registrations = normalize_array_length(@registrations, @registration_weeks) - @registration_weeks = @registration_weeks > 0 ? (1..@registration_weeks).to_a : 1 - - @submissions = Conference.get_event_state_line_colors + @submissions = Conference.get_event_state_line_colors @submissions_data = {} @submissions_data = @conference.get_submissions_data @@ -137,43 +140,44 @@ class Admin::ConferenceController < ApplicationController @submissions_data = @submissions_data.except('Weeks') end - # Doughnut charts - @event_type_distribution = @conference.event_type_distribution - @event_type_distribution_confirmed = @conference.event_type_distribution(:confirmed) + # Doughnut charts + @event_type_distribution = @conference.event_type_distribution + @event_type_distribution_confirmed = @conference.event_type_distribution(:confirmed) - @difficulty_levels_distribution = @conference.difficulty_levels_distribution - @difficulty_levels_distribution_confirmed = @conference. - difficulty_levels_distribution(:confirmed) + @difficulty_levels_distribution = @conference.difficulty_levels_distribution + @difficulty_levels_distribution_confirmed = @conference. + difficulty_levels_distribution(:confirmed) - @tracks_distribution = @conference.tracks_distribution - @tracks_distribution_confirmed = @conference.tracks_distribution(:confirmed) + @tracks_distribution = @conference.tracks_distribution + @tracks_distribution_confirmed = @conference.tracks_distribution(:confirmed) - # Recent actions information - @recent_events = @conference.events.limit(5).order(created_at: :desc) - @recent_registrations = @conference.registrations.limit(5).order(created_at: :desc) + # Recent actions information + @recent_events = @conference.events.limit(5).order(created_at: :desc) + @recent_registrations = @conference.registrations.limit(5).order(created_at: :desc) - @top_submitter = @conference.get_top_submitter + @top_submitter = @conference.get_top_submitter - # get targets - @registration_targets = @conference.get_targets(Target.units[:registrations]) - @submission_targets = @conference.get_targets(Target.units[:submissions]) - @program_minutes_targets = @conference.get_targets(Target.units[:program_minutes]) + # get targets + @registration_targets = @conference.get_targets(Target.units[:registrations]) + @submission_targets = @conference.get_targets(Target.units[:submissions]) + @program_minutes_targets = @conference.get_targets(Target.units[:program_minutes]) - # get campaigns - @campaigns = @conference.get_campaigns + # get campaigns + @campaigns = @conference.get_campaigns - respond_to do |format| - format.html - format.json { render json: @conference.to_json } + respond_to do |format| + format.html + format.json { render json: @conference.to_json } + end end - end - def edit - @conferences = Conference.all - @conference = Conference.find_by(short_title: params[:id]) - respond_to do |format| - format.html - format.json { render json: @conference.to_json } + def edit + @conferences = Conference.all + @conference = Conference.find_by(short_title: params[:id]) + respond_to do |format| + format.html + format.json { render json: @conference.to_json } + end end end end diff --git a/app/controllers/admin/dietchoices_controller.rb b/app/controllers/admin/dietchoices_controller.rb index cf315a40..bf1ffdf5 100644 --- a/app/controllers/admin/dietchoices_controller.rb +++ b/app/controllers/admin/dietchoices_controller.rb @@ -1,16 +1,19 @@ -class Admin::DietchoicesController < ApplicationController - before_filter :verify_organizer +module Admin + class DietchoicesController < ApplicationController + load_and_authorize_resource :conference, find_by: :short_title + load_and_authorize_resource :dietary_choice, through: :conference - def show - render :diets_list - end + def show + render :diets_list + end - def update - begin - @conference.update_attributes!(params[:conference]) - redirect_to(admin_conference_dietary_list_path(conference_id: @conference.short_title), notice: 'Dietary choices were successfully updated.') - rescue => e - redirect_to(admin_conference_dietary_list_path(conference_id: @conference.short_title), alert: "Dietary choices update failed: #{e.message}") + def update + begin + @conference.update_attributes!(params[:conference]) + redirect_to(admin_conference_dietary_list_path(conference_id: @conference.short_title), notice: 'Dietary choices were successfully updated.') + rescue => e + redirect_to(admin_conference_dietary_list_path(conference_id: @conference.short_title), alert: "Dietary choices update failed: #{e.message}") + end end end end diff --git a/app/controllers/admin/difficulty_levels_controller.rb b/app/controllers/admin/difficulty_levels_controller.rb index 51aacd7f..af652b40 100644 --- a/app/controllers/admin/difficulty_levels_controller.rb +++ b/app/controllers/admin/difficulty_levels_controller.rb @@ -1,29 +1,32 @@ -class Admin::DifficultyLevelsController < ApplicationController - before_filter :verify_organizer - - def index - @conference = Conference.find_by(short_title: params[:conference_id]) - end +module Admin + class DifficultyLevelsController < ApplicationController + load_and_authorize_resource :conference, find_by: :short_title + authorize_resource :difficulty_level, through: :conference - def update - if @conference.update_attributes(params[:conference]) - if !(@conference.difficulty_levels.count > 0) && @conference.use_difficulty_levels == true - begin - @conference.use_difficulty_levels = false - @conference.save! - flash[:error] = "You cannot enable the usage of difficulty levels without having set any levels." + def index + @conference = Conference.find_by(short_title: params[:conference_id]) + end + + def update + if @conference.update_attributes(params[:conference]) + if !(@conference.difficulty_levels.count > 0) && @conference.use_difficulty_levels == true + begin + @conference.use_difficulty_levels = false + @conference.save! + flash[:error] = "You cannot enable the usage of difficulty levels without having set any levels." + redirect_to(admin_conference_difficulty_levels_path(conference_id: @conference.short_title)) + rescue ActiveRecord::RecordInvalid + flash[:error] = "Something went wrong. Difficulty Levels update failed." + redirect_to(admin_conference_difficulty_levels_path(conference_id: @conference.short_title)) + end + else + flash[:notice] = "Difficulty Levels were successfully updated." redirect_to(admin_conference_difficulty_levels_path(conference_id: @conference.short_title)) - rescue ActiveRecord::RecordInvalid - flash[:error] = "Something went wrong. Difficulty Levels update failed." - redirect_to(admin_conference_difficulty_levels_path(conference_id: @conference.short_title)) end else - flash[:notice] = "Difficulty Levels were successfully updated." + flash[:error] = "Difficulty Levels update failed." redirect_to(admin_conference_difficulty_levels_path(conference_id: @conference.short_title)) end - else - flash[:error] = "Difficulty Levels update failed." - redirect_to(admin_conference_difficulty_levels_path(conference_id: @conference.short_title)) end end end diff --git a/app/controllers/admin/emails_controller.rb b/app/controllers/admin/emails_controller.rb index dbdfc44d..92c0b8bf 100644 --- a/app/controllers/admin/emails_controller.rb +++ b/app/controllers/admin/emails_controller.rb @@ -1,14 +1,17 @@ -class Admin::EmailsController < ApplicationController - before_filter :verify_organizer +module Admin + class EmailsController < ApplicationController + load_and_authorize_resource :conference, find_by: :short_title + load_and_authorize_resource :emails, class: EmailSettings - def update - @conference.email_settings.update_attributes(params[:email_settings]) - redirect_to(admin_conference_emails_path( - @conference.short_title), - notice: 'Settings have been successfully updated.') - end + def update + @conference.email_settings.update_attributes(params[:email_settings]) + redirect_to(admin_conference_emails_path( + @conference.short_title), + notice: 'Settings have been successfully updated.') + end - def index - @settings = @conference.email_settings + def index + @settings = @conference.email_settings + end end end diff --git a/app/controllers/admin/event_types_controller.rb b/app/controllers/admin/event_types_controller.rb new file mode 100644 index 00000000..e8d76491 --- /dev/null +++ b/app/controllers/admin/event_types_controller.rb @@ -0,0 +1,21 @@ +module Admin + class EventTypesController < ApplicationController + load_and_authorize_resource :conference, find_by: :short_title + authorize_resource :event_type, through: :conference + + def show + render :eventtypes + end + + def update + @conference.update_attributes!(params[:conference]) + redirect_to(admin_conference_event_types_path( + conference_id: @conference.short_title), + notice: 'Event types were successfully updated.') + rescue Exception => e + redirect_to(admin_conference_event_types_path( + conference_id: @conference.short_title), + alert: "Event types update failed: #{e.message}") + end + end +end diff --git a/app/controllers/admin/events_controller.rb b/app/controllers/admin/events_controller.rb index 99dbfbc2..c38b8b54 100644 --- a/app/controllers/admin/events_controller.rb +++ b/app/controllers/admin/events_controller.rb @@ -1,8 +1,8 @@ module Admin class EventsController < ApplicationController - before_filter :verify_organizer - - before_action :get_event, except: [:index, :create] + load_resource :conference, find_by: :short_title + load_and_authorize_resource :event, through: :conference + before_filter :authorize_conference # FIXME: The timezome should only be applied on output, otherwise # you get lost in timezone conversions... @@ -168,15 +168,6 @@ module Admin private - def get_event - @event = @conference.events.find_by_id(params[:id]) - if !@event - redirect_to(admin_conference_events_path(conference_id: @conference.short_title), - alert: 'Error! Could not find event!') && return - end - @event - end - def update_state(transition, notice, mail = false, subject = false, send_mail = false) alert = @event.update_state(transition, mail, subject, send_mail, params[:send_mail].blank?) diff --git a/app/controllers/admin/lodgings_controller.rb b/app/controllers/admin/lodgings_controller.rb index 34dfa628..35e36939 100644 --- a/app/controllers/admin/lodgings_controller.rb +++ b/app/controllers/admin/lodgings_controller.rb @@ -1,6 +1,7 @@ module Admin class LodgingsController < ApplicationController - before_filter :verify_organizer + load_and_authorize_resource :conference, find_by: :short_title + authorize_resource :lodging, through: :conference def index @venue = @conference.venue diff --git a/app/controllers/admin/questions_controller.rb b/app/controllers/admin/questions_controller.rb index 1e9e4551..101e720e 100644 --- a/app/controllers/admin/questions_controller.rb +++ b/app/controllers/admin/questions_controller.rb @@ -1,94 +1,88 @@ -class Admin::QuestionsController < ApplicationController - before_filter :verify_organizer +module Admin + class QuestionsController < ApplicationController + load_and_authorize_resource :conference, find_by: :short_title + authorize_resource :question, through: :conference - def index - @conference = Conference.find_by(short_title: params[:conference_id]) - @questions = Question.where(global: true).all | Question.where(conference_id: @conference.id) - @questions_conference = @conference.questions - @new_question = @conference.questions.new - end + def index + @questions = Question.where(global: true).all | Question.where(conference_id: @conference.id) + @questions_conference = @conference.questions + @new_question = @conference.questions.new + end - def new - @conference = Conference.find_by(short_title: params[:conference_id]) - @new_question = @conference.questions.new - end + def new + @new_question = @conference.questions.new + end - def create - @conference = Conference.find_by(short_title: params[:conference_id]) - @question = @conference.questions.new(params[:question]) - @question.conference_id = @conference.id + def create + @question = @conference.questions.new(params[:question]) + @question.conference_id = @conference.id - respond_to do |format| - if @conference.save - format.html { redirect_to admin_conference_questions_path, notice: 'Question was successfully created.' } - else - flash[:error] = "Oops, couldn't save. Question and answer(s) have titles?" - format.html { redirect_to admin_conference_questions_path } + respond_to do |format| + if @conference.save + format.html { redirect_to admin_conference_questions_path, notice: 'Question was successfully created.' } + else + flash[:error] = "Oops, couldn't save. Question and answer(s) have titles?" + format.html { redirect_to admin_conference_questions_path } + end end - end - end - - # GET questions/1/edit - def edit - @conference = Conference.find_by(short_title: params[:conference_id]) - @question = Question.find(params[:id]) - - if @question.global == true && !has_role?(current_user, "Admin") - redirect_to(admin_conference_questions_path(conference_id: @conference.short_title), alert: "Sorry, you cannot edit global questions. Create a new one.") end - end - # PUT questions/1 - def update - - @conference = Conference.find_by(short_title: params[:conference_id]) - @question = Question.find(params[:id]) + # GET questions/1/edit + def edit - if @question.update_attributes(params[:question]) - redirect_to(admin_conference_questions_path(conference_id: @conference.short_title), notice: "Question '#{@question.title}' for #{@conference.short_title} successfully updated.") - else - redirect_to(admin_conference_questions_path(conference_id: @conference.short_title), notice: "Update of questions for #{@conference.short_title} failed.") - end - end - - # Update questions used for the conference - def update_conference - @conference = Conference.find_by(short_title: params[:conference_id]) - - if @conference.update_attributes(params[:conference]) - redirect_to(admin_conference_questions_path(conference_id: @conference.short_title), notice: "Questions for #{@conference.short_title} successfully updated.") - else - redirect_to(admin_conference_questions_path(conference_id: @conference.short_title), notice: "Update of questions for #{@conference.short_title} failed.") - end - end - - # DELETE questions/1 - def destroy - if has_role?(current_user, "Admin") @question = Question.find(params[:id]) - # Do not delete global questions - if @question.global == false + if @question.global == true && !(current_user.has_role? :organizer, @conference) + redirect_to(admin_conference_questions_path(conference_id: @conference.short_title), alert: "Sorry, you cannot edit global questions. Create a new one.") + end + end - # Delete question and its answers - begin - Question.transaction do + # PUT questions/1 + def update + @question = Question.find(params[:id]) - @question.delete - @question.answers.each do |a| - a.delete - end - flash[:notice] = "Deleted question: #{@question.title} and its answers: #{@question.answers.map {|a| a.title}.join ','}" + if @conference.update_attributes(params[:conference]) + redirect_to(admin_conference_questions_path(conference_id: @conference.short_title), notice: "Questions for #{@conference.short_title} successfully updated.") + else + redirect_to(admin_conference_questions_path(conference_id: @conference.short_title), notice: "Update of questions for #{@conference.short_title} failed.") + end + end + + # Update questions used for the conference + def update_conference + if @conference.update_attributes(params[:conference]) + redirect_to(admin_conference_questions_path(:conference_id => @conference.short_title), :notice => "Questions for #{@conference.short_title} successfully updated.") + else + redirect_to(admin_conference_questions_path(:conference_id => @conference.short_title), :notice => "Update of questions for #{@conference.short_title} failed.") + end + end + + # DELETE questions/1 + def destroy + if can? :destroy, @question + + # Do not delete global questions + if @question.global == false + + # Delete question and its answers + begin + Question.transaction do + + @question.delete + @question.answers.each do |a| + a.delete + end + flash[:notice] = "Deleted question: #{@question.title} and its answers: #{@question.answers.map {|a| a.title}.join ','}" end - rescue ActiveRecord::RecordInvalid - flash[:error] = "Could not delete question." + rescue ActiveRecord::RecordInvalid + flash[:error] = "Could not delete question." + end + else + flash[:error] = "You cannot delete global questions." end else - flash[:error] = "You cannot delete global questions." + flash[:error] = "You must be an admin to delete a question." end - else - flash[:error] = "You must be an admin to delete a question." - end @questions = Question.where(global: true).all | Question.where(conference_id: @conference.id) @questions_conference = @conference.questions diff --git a/app/controllers/admin/registrations_controller.rb b/app/controllers/admin/registrations_controller.rb index 6ebe3db0..9b67f454 100644 --- a/app/controllers/admin/registrations_controller.rb +++ b/app/controllers/admin/registrations_controller.rb @@ -1,6 +1,7 @@ module Admin class RegistrationsController < ApplicationController - before_filter :verify_organizer + load_and_authorize_resource :conference, find_by: :short_title + load_and_authorize_resource through: :conference def index session[:return_to] ||= request.referer @@ -12,7 +13,6 @@ module Admin end def change_field - @registration = Registration.find(params[:id]) field = params[:view_field] if @registration.send(field.to_sym) @registration.update_attribute(:"#{field}", 0) @@ -26,12 +26,10 @@ module Admin end def edit - @registration = @conference.registrations.where('id = ?', params[:id]).first @user = User.where('id = ?', @registration.user_id).first end def update - @registration = @conference.registrations.where('id = ?', params[:id]).first @user = User.where('id = ?', @registration.user_id).first begin @user.update_attributes!(params[:registration][:user_attributes]) @@ -55,6 +53,7 @@ module Admin def new @user = User.new @registration = @user.registrations.new + @registration.conference_id = @conference.id @supporter_registration = @conference.supporter_registrations.new end @@ -97,7 +96,7 @@ module Admin end def destroy - if has_role?(current_user, 'Admin') + if can? :destroy, @registration registration = @conference.registrations.where(id: params[:id]).first user = User.where('id = ?', registration.user_id).first diff --git a/app/controllers/admin/rooms_controller.rb b/app/controllers/admin/rooms_controller.rb index 00342258..fae3adab 100644 --- a/app/controllers/admin/rooms_controller.rb +++ b/app/controllers/admin/rooms_controller.rb @@ -1,19 +1,22 @@ -class Admin::RoomsController < ApplicationController - before_filter :verify_organizer +module Admin + class RoomsController < ApplicationController + load_and_authorize_resource :conference, find_by: :short_title + authorize_resource :room, through: :conference - def show - render :rooms_list - end + def show + render :rooms_list + end - def update - if @conference.update_attributes(params[:conference]) - redirect_to(admin_conference_rooms_path( - conference_id: @conference.short_title), - notice: 'Rooms were successfully updated.') - else - redirect_to(admin_conference_rooms_path( - conference_id: @conference.short_title), - notice: 'Room update failed.') + def update + if @conference.update_attributes(params[:conference]) + redirect_to(admin_conference_rooms_path( + conference_id: @conference.short_title), + notice: 'Rooms were successfully updated.') + else + redirect_to(admin_conference_rooms_path( + conference_id: @conference.short_title), + notice: 'Room update failed.') + end end end end diff --git a/app/controllers/admin/schedules_controller.rb b/app/controllers/admin/schedules_controller.rb index cd7fff2b..dfdbe676 100644 --- a/app/controllers/admin/schedules_controller.rb +++ b/app/controllers/admin/schedules_controller.rb @@ -1,6 +1,10 @@ module Admin class SchedulesController < ApplicationController - before_filter :verify_organizer + # By authorizing 'conference' resource, we can ensure there will be no unauthorized access to + # the schedule of a conference, which should not be accessed in the first place + load_and_authorize_resource :conference, find_by: :short_title + authorize_resource class: false + skip_before_filter :verify_authenticity_token, only: [:update] layout 'schedule' diff --git a/app/controllers/admin/social_events_controller.rb b/app/controllers/admin/social_events_controller.rb index b11b38f4..47bbeceb 100644 --- a/app/controllers/admin/social_events_controller.rb +++ b/app/controllers/admin/social_events_controller.rb @@ -1,15 +1,18 @@ -class Admin::SocialEventsController < ApplicationController - before_filter :verify_organizer +module Admin + class SocialEventsController < ApplicationController + load_and_authorize_resource :conference, find_by: :short_title + authorize_resource :social_event, through: :conference - def show - render :social_events_list - end + def show + render :social_events_list + end - def update - if @conference.update_attributes(params[:conference]) - redirect_to(admin_conference_social_events_path(conference_id: @conference.short_title), notice: 'Social events were successfully updated.') - else - redirect_to(admin_conference_social_events_path(conference_id: @conference.short_title), notice: 'Social events update failed.') + def update + if @conference.update_attributes(params[:conference]) + redirect_to(admin_conference_social_events_path(conference_id: @conference.short_title), notice: 'Social events were successfully updated.') + else + redirect_to(admin_conference_social_events_path(conference_id: @conference.short_title), notice: 'Social events update failed.') + end end end end diff --git a/app/controllers/admin/speakers_controller.rb b/app/controllers/admin/speakers_controller.rb index 76fd40ce..cddb0bd0 100644 --- a/app/controllers/admin/speakers_controller.rb +++ b/app/controllers/admin/speakers_controller.rb @@ -1,15 +1,15 @@ module Admin class SpeakersController < ApplicationController - before_filter :verify_organizer + load_and_authorize_resource :conference, find_by: :short_title + load_resource :event, through: :conference + respond_to :js, :html def edit - @event = @conference.events.find(params[:event_id]) @speaker = @event.event_users.where(event_role: 'speaker').first end def update - @event = @conference.events.find(params[:event_id]) @speaker = @event.event_users.where(event_role: 'speaker').first @speaker.user_id = params[:speaker][:user_id] @speaker.save diff --git a/app/controllers/admin/sponsors_controller.rb b/app/controllers/admin/sponsors_controller.rb index d37c1cb4..7ee8d7f4 100644 --- a/app/controllers/admin/sponsors_controller.rb +++ b/app/controllers/admin/sponsors_controller.rb @@ -1,6 +1,7 @@ module Admin class SponsorsController < ApplicationController - before_filter :verify_organizer + load_and_authorize_resource :conference, find_by: :short_title + authorize_resource :sponsor, through: :conference def update if @conference.update_attributes(params[:conference]) diff --git a/app/controllers/admin/sponsorship_levels_controller.rb b/app/controllers/admin/sponsorship_levels_controller.rb index 1d0a61bc..9661f416 100644 --- a/app/controllers/admin/sponsorship_levels_controller.rb +++ b/app/controllers/admin/sponsorship_levels_controller.rb @@ -1,6 +1,7 @@ module Admin class SponsorshipLevelsController < ApplicationController - before_filter :verify_organizer + load_and_authorize_resource :conference, find_by: :short_title + authorize_resource :sponsorship_level, through: :conference def update if @conference.update_attributes(params[:conference]) diff --git a/app/controllers/admin/stats_controller.rb b/app/controllers/admin/stats_controller.rb index b5685bff..35ec18dd 100644 --- a/app/controllers/admin/stats_controller.rb +++ b/app/controllers/admin/stats_controller.rb @@ -1,6 +1,7 @@ module Admin class StatsController < ApplicationController - before_filter :verify_organizer + load_and_authorize_resource + load_and_authorize_resource :conference, find_by: :short_title def index @registrations = @conference.registrations.includes(:user) diff --git a/app/controllers/admin/supporter_levels_controller.rb b/app/controllers/admin/supporter_levels_controller.rb index 33218920..7b422d11 100644 --- a/app/controllers/admin/supporter_levels_controller.rb +++ b/app/controllers/admin/supporter_levels_controller.rb @@ -1,12 +1,13 @@ -class Admin::SupporterLevelsController < ApplicationController - before_filter :verify_organizer +module Admin + class Admin::SupporterLevelsController < ApplicationController + load_and_authorize_resource :conference, find_by: :short_title + authorize_resource :supporter_level, through: :conference - def show - render :supporter_levels - end + def show + render :supporter_levels + end - def update - begin + def update @conference.update_attributes!(params[:conference]) redirect_to(admin_conference_supporter_levels_path(conference_id: @conference.short_title), notice: 'Supporter levels were successfully updated.') rescue => e diff --git a/app/controllers/admin/supporters_controller.rb b/app/controllers/admin/supporters_controller.rb index a114daca..c9f6f0e0 100644 --- a/app/controllers/admin/supporters_controller.rb +++ b/app/controllers/admin/supporters_controller.rb @@ -1,16 +1,21 @@ -class Admin::SupportersController < ApplicationController - before_filter :verify_organizer +module Admin + class Admin::SupportersController < ApplicationController + load_and_authorize_resource :conference, find_by: :short_title + load_and_authorize_resource :supporter, through: :conference - def index - respond_to do |format| - format.html - format.json { render json: DatatableSupporters.new(@conference.supporter_registrations, view_context) } + def index + respond_to do |format| + format.html + format.json { render json: DatatableSupporters. + new(@conference.supporter_registrations, view_context) } + end + end + + def create + params[:supporter_registration][:conference_id] = @conference.id + supporter = SupporterRegistration.create!(params[:supporter_registration]) + redirect_to(admin_conference_supporters_path(conference_id: @conference.short_title), + notice: 'Supporter added') end end - - def create - params[:supporter_registration][:conference_id] = @conference.id - SupporterRegistration.create!(params[:supporter_registration]) - redirect_to(admin_conference_supporters_path(conference_id: @conference.short_title), notice: "Supporter added") - end end diff --git a/app/controllers/admin/targets_controller.rb b/app/controllers/admin/targets_controller.rb index 94562de3..eadc2737 100644 --- a/app/controllers/admin/targets_controller.rb +++ b/app/controllers/admin/targets_controller.rb @@ -1,6 +1,7 @@ module Admin class TargetsController < ApplicationController - before_filter :verify_organizer + load_and_authorize_resource :conference, find_by: :short_title + authorize_resource :target, through: :conference def index end diff --git a/app/controllers/admin/tracks_controller.rb b/app/controllers/admin/tracks_controller.rb index 102cdd68..ea360b88 100644 --- a/app/controllers/admin/tracks_controller.rb +++ b/app/controllers/admin/tracks_controller.rb @@ -1,22 +1,25 @@ -class Admin::TracksController < ApplicationController - before_filter :verify_organizer +module Admin + class TracksController < ApplicationController + load_and_authorize_resource :conference, find_by: :short_title + authorize_resource through: :conference - def show - respond_to do |format| - format.html { render :tracks_list } - format.json { render json: @conference.tracks.to_json } + def show + respond_to do |format| + format.html { render :tracks_list } + format.json { render json: @conference.tracks.to_json } + end end - end - def update - if @conference.update_attributes(params[:conference]) - redirect_to(admin_conference_tracks_path( - conference_id: @conference.short_title), - notice: 'Tracks were successfully updated.') - else - redirect_to(admin_conference_tracks_path( - conference_id: @conference.short_title), - notice: 'Tracks update failed.') + def update + if @conference.update_attributes(params[:conference]) + redirect_to(admin_conference_tracks_path( + conference_id: @conference.short_title), + notice: 'Tracks were successfully updated.') + else + redirect_to(admin_conference_tracks_path( + conference_id: @conference.short_title), + notice: 'Tracks update failed.') + end end end end diff --git a/app/controllers/admin/users_controller.rb b/app/controllers/admin/users_controller.rb index b6966822..727354fb 100644 --- a/app/controllers/admin/users_controller.rb +++ b/app/controllers/admin/users_controller.rb @@ -1,40 +1,44 @@ module Admin class UsersController < ApplicationController - before_filter :verify_admin + load_and_authorize_resource def index @users = User.all + @roles = Role.all.where(resource_type: nil) end def show - @user = User.find(params[:id]) - # Variable @show_attributes holds the attributes that are visible for the 'show' action # If you want to change the attributes that are shown in the 'show' action of users # add/remove the attributes in the following string array - @show_attributes = %w(name email affiliation biography registered attended created_at + @show_attributes = %w(name email affiliation biography registered attended roles created_at updated_at sign_in_count current_sign_in_at last_sign_in_at current_sign_in_ip last_sign_in_ip) end def update - user = User.find(params[:id]) - user.update_attributes!(params[:user]) - redirect_to admin_users_path, notice: "Updated #{user.email}" + params[:user].delete :roles_attributes if params[:user] + @user.update_attributes!(params[:user]) + redirect_to admin_users_path, notice: "Updated #{@user.email}" + end + + def add_role + role = params[:user][:roles_attributes][:"0"] + @user.add_role role['name'].parameterize.underscore.to_sym, Conference.find(role['resource_id']) + + respond_to do |format| + format.html + format.js + end + end def edit - @user = User.find(params[:id]) - end - - def delete - @user = User.find(params[:id]) end def destroy - @user = User.find(params[:id]) @user.destroy - redirect_to admin_users_path, notice: 'User got deleted' + redirect_to admin_users_path, notice: "User #{@user.name} (#{@user.email})got deleted" end end end diff --git a/app/controllers/admin/venue_controller.rb b/app/controllers/admin/venue_controller.rb index 5f511971..e277b9d6 100644 --- a/app/controllers/admin/venue_controller.rb +++ b/app/controllers/admin/venue_controller.rb @@ -1,34 +1,37 @@ -class Admin::VenueController < ApplicationController - before_filter :verify_organizer +module Admin + class VenueController < ApplicationController + load_and_authorize_resource :conference, find_by: :short_title + load_and_authorize_resource :venue, through: :conference, singleton: true - def index - end + def index + end - def update - @venue = @conference.venue - @venue.assign_attributes(params[:venue]) - unless @venue.name.blank? || @venue.address.blank? || @conference.registrations.blank? - if (@venue.name_changed? || - @venue.address_changed?) && - (@conference.email_settings.send_on_venue_update && - !@conference.email_settings.venue_update_subject.blank? && - @conference.email_settings.venue_update_template) - venue_notify = Mailbot.send_email_on_venue_update(@conference) + def update + @venue = @conference.venue + @venue.assign_attributes(params[:venue]) + unless @venue.name.blank? || @venue.address.blank? || @conference.registrations.blank? + if (@venue.name_changed? || + @venue.address_changed?) && + (@conference.email_settings.send_on_venue_update && + !@conference.email_settings.venue_update_subject.blank? && + @conference.email_settings.venue_update_template) + venue_notify = Mailbot.send_email_on_venue_update(@conference) + end + end + + if @venue.update_attributes(params[:venue]) + venue_notify.deliver unless venue_notify.blank? + redirect_to(admin_conference_venue_info_path(conference_id: @conference.short_title), + notice: 'Venue was successfully updated.') + else + redirect_to(admin_conference_venue_info_path(conference_id: @conference.short_title), + notice: 'Venue Updation Failed!') end end - if @venue.update_attributes(params[:venue]) - venue_notify.deliver unless venue_notify.blank? - redirect_to(admin_conference_venue_info_path(conference_id: @conference.short_title), - notice: 'Venue was successfully updated.') - else - redirect_to(admin_conference_venue_info_path(conference_id: @conference.short_title), - notice: 'Venue Updation Failed!') + def show + @venue = @conference.venue + render :venue_info end end - - def show - @venue = @conference.venue - render :venue_info - end end diff --git a/app/controllers/admin/volunteers_controller.rb b/app/controllers/admin/volunteers_controller.rb index afc688c9..e2253fc1 100644 --- a/app/controllers/admin/volunteers_controller.rb +++ b/app/controllers/admin/volunteers_controller.rb @@ -1,25 +1,28 @@ -class Admin::VolunteersController < ApplicationController - def index - @conference = Conference.find_by(short_title: params[:conference_id]) - render :index - end - - def show - @conference = Conference.find_by(short_title: params[:conference_id]) - if @conference.use_vpositions - @volunteers = @conference.registrations.joins(:vchoices).uniq - else - @volunteers = @conference.registrations.where(volunteer: true) - end - end +module Admin + class VolunteersController < ApplicationController + load_and_authorize_resource :conference, find_by: :short_title + authorize_resource class: false, through: :conference - def update - @conference = Conference.find_by(short_title: params[:conference_id]) - begin - @conference.update_attributes!(params[:conference]) - redirect_to(admin_conference_volunteers_info_path(conference_id: params[:conference_id]), notice: "Volunteering options were successfully updated.") - rescue => e - redirect_to(admin_conference_volunteers_info_path(conference_id: params[:conference_id]), alert: "Volunteering options update failed: #{e.message}") + def index + render :index + end + + def show + if @conference.use_vpositions + @volunteers = @conference.registrations.joins(:vchoices).uniq + else + @volunteers = @conference.registrations.where(volunteer: true) + end + end + + def update + @conference = Conference.find_by(short_title: params[:conference_id]) + begin + @conference.update_attributes!(params[:conference]) + redirect_to(admin_conference_volunteers_info_path(conference_id: params[:conference_id]), notice: "Volunteering options were successfully updated.") + rescue => e + redirect_to(admin_conference_volunteers_info_path(conference_id: params[:conference_id]), alert: "Volunteering options update failed: #{e.message}") + end end end end diff --git a/app/controllers/application_controller.rb b/app/controllers/application_controller.rb index 2a27b803..85564e87 100644 --- a/app/controllers/application_controller.rb +++ b/app/controllers/application_controller.rb @@ -3,14 +3,17 @@ class ApplicationController < ActionController::Base protect_from_forgery before_filter :get_conferences before_filter :store_location + before_filter :verify_user_admin helper_method :date_string + # Ensure every controller authorizes resource or skips authorization (skip_authorization_check) + check_authorization unless: :devise_controller? def store_location session[:return_to] = request.fullpath if request.get? and controller_name != "user_sessions" and controller_name != "sessions" end def after_sign_in_path_for(resource) - if organizer_or_admin? && + if (can? :view, Conference) && (!session[:return_to] || session[:return_to] && session[:return_to] == root_path) @@ -31,6 +34,20 @@ class ApplicationController < ActionController::Base @conferences =Conference.all end + def authorize_conference + authorize! :update, @conference + end + + def verify_user_admin + if self.class.to_s.split('::').first == 'Admin' && verify_user + unless (current_user.has_role? :organizer, :any) || (current_user.has_role? :cfp, :any) || + (current_user.has_role? :info_desk, :any) || + (current_user.has_role? :volunteers_coordinator, :any) || (current_user.is_admin) + raise CanCan::AccessDenied.new('You are not authorized to access this area!') + end + end + end + def verify_user :authenticate_user! @@ -39,36 +56,17 @@ class ApplicationController < ActionController::Base return false end - @conference = Conference.find_by(short_title: params[:conference_id]) true end - def organizer_or_admin? - has_role?(current_user, 'admin') || has_role?(current_user, 'organizer') - end - - def verify_organizer - if !verify_user - return - end - - ## Todo simplify this - redirect_to root_path unless has_role?(current_user, 'admin') || has_role?(current_user, 'organizer') - end - - def verify_admin - if !verify_user - return - end - - redirect_to root_path unless has_role?(current_user, 'admin') + def current_ability + @current_ability ||= Ability.new(current_user) end rescue_from CanCan::AccessDenied do |exception| Rails.logger.debug("Access denied!") redirect_to root_path, alert: exception.message end - helper_method :organizer_or_admin? def not_found raise ActionController::RoutingError.new('Not Found') diff --git a/app/controllers/conference_controller.rb b/app/controllers/conference_controller.rb index b3f6dae2..57dd0014 100644 --- a/app/controllers/conference_controller.rb +++ b/app/controllers/conference_controller.rb @@ -1,11 +1,12 @@ class ConferenceController < ApplicationController + load_and_authorize_resource find_by: :short_title + def show - @conference = Conference.find_by_short_title(params[:id]) not_found unless @conference.make_conference_public? end def gallery_photos - @photos = Conference.find_by_short_title(params[:id]).photos + @photos = @conference.photos render "photos", formats: [:js] end end diff --git a/app/controllers/conference_registration_controller.rb b/app/controllers/conference_registration_controller.rb index 3d9f0513..62965ea9 100644 --- a/app/controllers/conference_registration_controller.rb +++ b/app/controllers/conference_registration_controller.rb @@ -1,9 +1,9 @@ class ConferenceRegistrationController < ApplicationController before_filter :verify_user + load_resource :conference, find_by: :short_title + load_and_authorize_resource :conference_registration, class: Registration def register - # TODO Figure out how to change the route's id from :id to :conference_id - @conference = Conference.find_by(short_title: params[:id]) @workshops = @conference.events.where('require_registration = ? AND state LIKE ?', true, 'confirmed') @user = current_user @@ -23,9 +23,8 @@ class ConferenceRegistrationController < ApplicationController # TODO this is ugly def update - conference = Conference.find_by(short_title: params[:id]) user = current_user - registration = user.registrations.where(conference_id: conference.id).first + registration = user.registrations.where(conference_id: @conference.id).first update_registration = true # First verify that the supporter code is legit if !params[:registration][:supporter_registration_attributes].nil? && @@ -35,9 +34,9 @@ class ConferenceRegistrationController < ApplicationController if regs.count != 0 if regs.where(email: user.email).count == 0 - redirect_to(register_conference_path(id: conference.short_title), + redirect_to(conference_register_path(conference_id: @conference.short_title), alert: "This code is already in use. - Please contact #{conference.contact_email} for assistance.") + Please contact #{@conference.contact_email} for assistance.") return end end @@ -50,7 +49,7 @@ class ConferenceRegistrationController < ApplicationController supporter_reg = params[:registration][:supporter_registration_attributes] params[:registration].delete :supporter_registration_attributes registration = user.registrations.new(registration_params) - if conference.use_supporter_levels? && !supporter_reg.nil? + if @conference.use_supporter_levels? && !supporter_reg.nil? if !supporter_reg[:id].blank? # Means that their supporter registration was entered ahead of time, by an admin registration.supporter_registration = SupporterRegistration.find(supporter_reg[:id]) @@ -58,19 +57,19 @@ class ConferenceRegistrationController < ApplicationController raise 'Invalid code' end else - registration.supporter_registration = conference. + registration.supporter_registration = @conference. supporter_registrations.new(registration_params[:supporter_registration_attributes]) end end - registration.conference_id = conference.id + registration.conference_id = @conference.id registration.save! else registration.update_attributes!(registration_params) end rescue => e Rails.logger.debug e.backtrace.join('\n') - redirect_to(register_conference_path(id: conference.short_title), + redirect_to(conference_register_path(conference_id: @conference.short_title), alert: 'Registration failed:' + e.message) return end @@ -81,18 +80,17 @@ class ConferenceRegistrationController < ApplicationController else # Track ahoy event ahoy.track 'Registered', title: 'New registration' - if conference.email_settings.send_on_registration? - Mailbot.registration_mail(conference, current_user).deliver + if @conference.email_settings.send_on_registration? + Mailbot.registration_mail(@conference, current_user).deliver end end - redirect_to(register_conference_path(id: conference.short_title), + redirect_to(conference_register_path(conference_id: @conference.short_title), notice: redirect_message) end def unregister - conference = Conference.find_by(short_title: params[:id]) user = current_user - registration = user.registrations.where(conference_id: conference.id).first + registration = user.registrations.where(conference_id: @conference.id).first registration.destroy redirect_to :root end @@ -107,6 +105,7 @@ class ConferenceRegistrationController < ApplicationController :other_dietary_choice, :handicapped_access_required, :dietary_choice_id, :volunteer, :other_special_needs, social_event_ids: [], + event_ids: [], vchoice_ids: [], qanswer_ids: [], qanswers_attributes: [], diff --git a/app/controllers/event_attachments_controller.rb b/app/controllers/event_attachments_controller.rb index a54fc2a4..c5904482 100644 --- a/app/controllers/event_attachments_controller.rb +++ b/app/controllers/event_attachments_controller.rb @@ -1,9 +1,11 @@ class EventAttachmentsController < ApplicationController + load_and_authorize_resource :conference, find_by: :short_title + load_and_authorize_resource :proposal, class: Event + load_and_authorize_resource :upload, class: EventAttachment, through: :proposal before_filter :verify_user skip_before_filter :verify_user, only: [:show] def index - @proposal = Event.find(params[:proposal_id]) @uploads = @proposal.event_attachments @uploads = @uploads.map{|upload| upload.to_jq_upload } @@ -14,9 +16,9 @@ class EventAttachmentsController < ApplicationController end def show - upload = EventAttachment.find(params[:id]) - if upload.public? - send_file upload.attachment.path + + if @upload.public? + send_file @upload.attachment.path return end @@ -26,7 +28,7 @@ class EventAttachmentsController < ApplicationController end if organizer_or_admin? || current_user == upload.event.submitter - send_file upload.attachment.path + send_file @upload.attachment.path else raise ActionController::RoutingError.new('Not Found') end @@ -42,7 +44,6 @@ class EventAttachmentsController < ApplicationController end def edit - @upload = EventAttachment.find(params[:id]) end def create @@ -50,7 +51,7 @@ class EventAttachmentsController < ApplicationController params[:event_attachment][:public] = false params[:event_attachment][:event_id] = params[:proposal_id] - if !organizer_or_admin? + if cannot? :create, EventAttachment begin current_user.events.find(params[:proposal_id]) rescue @@ -83,8 +84,6 @@ class EventAttachmentsController < ApplicationController end def update - @proposal = current_user.events.find(params[:proposal_id]) - @upload = @proposal.event_attachments.find(params[:proposal_id]) respond_to do |format| if @upload.update_attributes(params[:upload]) @@ -98,14 +97,13 @@ class EventAttachmentsController < ApplicationController end def destroy - @proposal = Event.find(params[:proposal_id]) - - if organizer_or_admin? || current_user == @proposal.submitter + + if can? :destroy, @proposal @upload = @proposal.event_attachments.find(params[:id]) end - + @upload.destroy if !@upload.nil? - + respond_to do |format| format.html { redirect_back_or_to conference_proposal_index_path(@conference.short_title), notice: "Deleted successfully attachment '#{@upload.title}' for proposal '#{@proposal.title}'" } diff --git a/app/controllers/home_controller.rb b/app/controllers/home_controller.rb index 1b6a0373..8da4883f 100644 --- a/app/controllers/home_controller.rb +++ b/app/controllers/home_controller.rb @@ -1,5 +1,6 @@ class HomeController < ApplicationController before_filter :respond_to_options + skip_authorization_check def index @today = Date.current diff --git a/app/controllers/proposal_controller.rb b/app/controllers/proposal_controller.rb index dd2bf657..bce1856f 100644 --- a/app/controllers/proposal_controller.rb +++ b/app/controllers/proposal_controller.rb @@ -1,32 +1,35 @@ class ProposalController < ApplicationController before_filter :verify_user, except: [:show] - before_action :set_conference, only: [:show] - before_action :set_event, only: [:show, :edit, :update, :destroy, :confirm, :restart] + load_resource :conference, find_by: :short_title + load_and_authorize_resource :event, parent: false + before_filter :setup + + def setup + @user = current_user if current_user + @url = conference_proposal_index_path(@conference.short_title) + @event_types = @conference.event_types + end def index @events = current_user.proposals(@conference) end def show - authorize! :show, @event # FIXME: We should show more than the first speaker @speaker = @event.speakers.first || @event.submitter end def new - authorize! :new, Event @url = conference_proposal_index_path(@conference.short_title) @event = Event.new end def edit - authorize! :edit, @event @url = conference_proposal_path(@conference.short_title, params[:id]) @attachments = @event.event_attachments end def create - authorize! :create, Event @url = conference_proposal_index_path(@conference.short_title) params[:event].delete :user @@ -53,7 +56,7 @@ class ProposalController < ApplicationController registration = current_user.registrations.where(conference_id: @conference.id).first ahoy.track 'Event submission', title: 'New submission' if registration.nil? - redirect_to(register_conference_path(@conference.short_title), + redirect_to(conference_register_path(@conference.short_title), alert: 'Event was successfully submitted. You should register for the conference now.') else @@ -63,7 +66,6 @@ class ProposalController < ApplicationController end def update - authorize! :update, @event @url = conference_proposal_path(@conference.short_title, params[:id]) # First, update the submitter's info, if they've changed anything @@ -103,7 +105,6 @@ class ProposalController < ApplicationController end def confirm - authorize! :update, @event @url = conference_proposal_path(@conference.short_title, params[:id]) begin @@ -129,12 +130,12 @@ class ProposalController < ApplicationController end def restart - authorize! :update, @event @url = conference_proposal_path(@conference.short_title, params[:id]) - + begin @event.restart rescue Transitions::InvalidTransition + redirect_to(conference_proposal_index_path(conference_id: @conference.short_title), error: "The proposal can't be re-submitted.") return @@ -149,14 +150,4 @@ class ProposalController < ApplicationController redirect_to(conference_proposal_index_path(conference_id: @conference.short_title), notice: "The proposal was re-submitted. The #{@conference.short_title} organizers will review it again.") end - - private - - def set_conference - @conference = Conference.find_by(short_title: params[:conference_id]) - end - - def set_event - @event = Event.find(params[:id]) - end end diff --git a/app/controllers/schedule_controller.rb b/app/controllers/schedule_controller.rb index 365d8bf2..df534eac 100644 --- a/app/controllers/schedule_controller.rb +++ b/app/controllers/schedule_controller.rb @@ -1,6 +1,7 @@ class ScheduleController < ApplicationController + authorize_resource class: false layout "application" - + def index @conference = Conference.includes(:rooms, {events: [:speakers, :track, :event_type]}).where("conferences.short_title" => params[:conference_id]).first @rooms = @conference.rooms diff --git a/app/controllers/users/omniauth_callbacks_controller.rb b/app/controllers/users/omniauth_callbacks_controller.rb index aca14642..4412a8ae 100644 --- a/app/controllers/users/omniauth_callbacks_controller.rb +++ b/app/controllers/users/omniauth_callbacks_controller.rb @@ -1,6 +1,7 @@ module Users class OmniauthCallbacksController < Devise::OmniauthCallbacksController skip_before_filter :verify_authenticity_token + skip_authorization_check User.omniauth_providers.each do |provider| define_method(provider) { handle(provider) } diff --git a/app/models/ability.rb b/app/models/ability.rb index 8c09734e..f76eaf1e 100644 --- a/app/models/ability.rb +++ b/app/models/ability.rb @@ -2,16 +2,158 @@ class Ability include CanCan::Ability def initialize(user) - # guest user (not logged in) - user ||= User.new - if user.admin? || user.organizer? - # An admin can manage everything - can :manage, :all - else - can [:update, :destroy], Event do |event| - event.users.include?(user) + # The first argument to `can` is the action you are giving the user permission to do. + # If you pass :manage it will apply to every action. Other common actions here are + # :read, :create, :update and :destroy. + # + # The second argument is the resource the user can perform the action on. If you pass + # :all it will apply to every resource. Otherwise pass a Ruby class of the resource. + # + # The third argument is an optional hash of conditions to further filter the objects. + # For example, here the user can only update published articles. + # + # can :update, Article, :published => true + # + # See the wiki for details: https://github.com/ryanb/cancan/wiki/Defining-Abilities + + # Order Abilities + # (Check https://github.com/CanCanCommunity/cancancan/wiki/Ability-Precedence) + + user ||= User.new # guest user (not logged in) + + # Check roles of user, using rolify. Role name is *case sensitive* + # user.is_organizer? or user.has_role? :organizer + # We only assign roles per conference, so: + # user.is_cfp_of? Conference.find(1) or user.has_role? :cfp, @conference + # user.is_info_desk_of? @conference + # user.is_volunteer_coordinator_of? @conference + # user.is_attendee_of? @conference + # The following is wrong because a user will only have 'cfp' role for a specific conference + # user.is_cfp? # Always FALSE + + # Ids of all the conferences for which the user has an 'organizer' role + conf_ids_for_organizer = + Conference.with_role(:organizer, user).pluck(:id) unless user.new_record? + # Ids of the venues of the conference for which (conferences) the user has an 'organizer' role + conf_ids_for_organizer_venue = + Conference.with_role(:organizer, user).pluck(:venue_id) unless user.new_record? + # Ids of all the conferences for which the user has a 'cfp' role + conf_ids_for_cfp = + Conference.with_role(:cfp, user).pluck(:id) unless user.new_record? + # Ids of all the conferences for which the user has an 'info_desk' role + conf_ids_for_info_desk = + Conference.with_role(:info_desk, user).pluck(:id) unless user.new_record? + # Ids of all the conferences for which the user has a 'volunteer_coordinator' role + conf_ids_for_volunteer_coordinator = + Conference.with_role(:volunteer_coordinator, user).pluck(:id) unless user.new_record? + event_ids_for_user = + EventUser.where(user_id: user.id).pluck(:event_id) + + ## Abilities for everyone (incl. GUESTS - not logged in users) + can :show, Conference, make_conference_public: true + + can :show, Event, state: 'confirmed' + + can :index, :schedule + + ## Abilities for signed in users + unless user.new_record? + # Conference Registration + can [:register, :update, :unregister], Registration, user_id: user.id + + # Proposals + # Users can edit their own proposals + # Organizer and CfP team can edit any proposal they want + # Can manage an event if the user is a speaker or a submitter of that event + + can :create, Event + can :manage, Event do |event| + event.event_users.where(:user_id => user.id).present? end - can [:create, :read], Event + + can :manage, EventAttachment do |ea| + Event.find(ea.event_id).event_users.where(user_id: user.id).present? + end + can :create, EventAttachment + end + + ## Abilities for admins + if user.is_admin # is_admin is an attribute of User + can :create, Conference + can :index, Conference # this will allow the Conference to appear in the menu + can :show, Conference # for /admin/conference overview + can :manage, User # to make other users admins + end + + ## Abilities for ORGANIZER + # If a user is organizer of a conference, they can manage everything related to this conference + + if user.has_role? :organizer, :any + can :manage, :all, conference_id: conf_ids_for_organizer + + # Registrations controller authorizes conference resource too, so we don't have to worry about + # accessing the new registration page of a conference we don't have access to + can :create, Registration, conference_id: conf_ids_for_organizer + + # Override previous can because + # Models Conference, Venue, User, Schedule do not have a 'conference_id' attribute + cannot :manage, Conference + cannot :manage, Venue + cannot :manage, User + cannot :manage, :schedule + can :manage, :schedule + + # Authorize explicitely, so that it doesn't look for a 'conference_id' + can :manage, :volunteer + + # Authorize Conference by its 'id' attribute + can :manage, Conference, id: conf_ids_for_organizer + # Authorize venues of conferences, which user can manage + can :manage, Venue, id: conf_ids_for_organizer_venue + # id: Conference.where(id: conf_ids_for_organizer).map(&:venue_id) + # User can view the admin 'users' page if he is an organizer for any conference + can :manage, User + # To assign roles to users + # can :manage, Role, resource_id: conf_ids_for_organizer + end + + ## Abilities for CfP + # A user can manage events of the conference, for which conference the user has a 'cfp' role + if user.has_role? :cfp, :any + # Can view dashboard for specific conference (show) and for all conference (index) + can [:index, :show], Conference, id: conf_ids_for_cfp + can :manage, Event, conference_id: conf_ids_for_cfp + can :manage, CallForPapers, conference_id: conf_ids_for_cfp + can :manage, EventType, conference_id: conf_ids_for_cfp + can :manage, Track, conference_id: conf_ids_for_cfp + can :manage, DifficultyLevel, conference_id: conf_ids_for_cfp + can :manage, :schedule + + can :manage, EmailSettings, conference_id: conf_ids_for_cfp + can :index, User + end + + ## Abilities for Info Desk + if user.has_role? :info_desk, :any + can [:index, :show], Conference, id: conf_ids_for_info_desk + can :manage, Registration, conference_id: conf_ids_for_info_desk + can :manage, Question, conference_id: conf_ids_for_info_desk + + # Previously we authorized Registrations of a specific conference, but that doesn't work + # if we want to create a new one, which does not belong to any conference yet + # Registrations controller authorizes conference resource too, so we don't have to worry about + # accessing the new registration page of a conference we don't have access to + can :create, Registration, conference_id: conf_ids_for_info_desk + + can :index, User + end + + ## Abilities for Volunteer Coordinator + if user.has_role? :volunteer_coordinator, :any + can [:index, :show], Conference, id: conf_ids_for_volunteer_coordinator + can :manage, Vposition, conference_id: conf_ids_for_volunteer_coordinator + can :manage, Vday, conference_id: conf_ids_for_volunteer_coordinator + can :manage, :volunteer end end end diff --git a/app/models/conference.rb b/app/models/conference.rb index d2a3a907..c8c949ef 100644 --- a/app/models/conference.rb +++ b/app/models/conference.rb @@ -4,6 +4,7 @@ class Conference < ActiveRecord::Base require 'uri' serialize :events_per_week, Hash + resourcify # Needed to call 'Conference.with_role' in /models/ability.rb and admin_ability.rb attr_accessible :title, :short_title, :social_tag, :contact_email, :timezone, :html_export_path, :start_date, :end_date, :rooms_attributes, :tracks_attributes, diff --git a/app/models/event_attachment.rb b/app/models/event_attachment.rb index 41915248..819f3b6d 100644 --- a/app/models/event_attachment.rb +++ b/app/models/event_attachment.rb @@ -6,6 +6,7 @@ class EventAttachment < ActiveRecord::Base has_attached_file :attachment, path: ":rails_root/storage/:rails_env/attachments/:id/:style/:basename.:extension" include Rails.application.routes.url_helpers + do_not_validate_attachment_file_type :attachment def to_jq_upload { diff --git a/app/models/role.rb b/app/models/role.rb index e6d7cb0a..5e582323 100644 --- a/app/models/role.rb +++ b/app/models/role.rb @@ -1,4 +1,10 @@ class Role < ActiveRecord::Base - attr_accessible :name + attr_accessible :name, :description has_and_belongs_to_many :users + belongs_to :resource, polymorphic: true + + scopify + + LABELS = ['Participant', 'Attendee', 'Volunteer', 'Speaker', 'Sponsor', 'Press', + 'Organizer', 'CfP', 'Info Desk', 'Volunteers Coordinator'] end diff --git a/app/models/user.rb b/app/models/user.rb index c86c773e..70e589b3 100644 --- a/app/models/user.rb +++ b/app/models/user.rb @@ -1,7 +1,10 @@ class User < ActiveRecord::Base + rolify include Gravtastic gravtastic size: 32 + before_create :setup_role + # Include default devise modules. Others available are: # :token_authenticatable, :confirmable, # :lockable, :timeoutable and :omniauthable @@ -9,22 +12,19 @@ class User < ActiveRecord::Base :recoverable, :rememberable, :trackable, :validatable, :confirmable, :omniauthable, omniauth_providers: [:novell, :google, :facebook] - has_and_belongs_to_many :roles - has_many :openids - attr_accessible :email, :password, :password_confirmation, :remember_me, :role_id, :role_ids, :name, :email_public, :biography, :nickname, :affiliation + has_and_belongs_to_many :roles + has_many :openids has_many :event_users, dependent: :destroy has_many :events, -> { uniq }, through: :event_users has_many :registrations, dependent: :destroy has_many :votes, dependent: :destroy - has_many :voted_events, through: :votes, source: :events + has_many :voted_events, through: :votes, source: :event accepts_nested_attributes_for :roles - before_create :setup_role - validates :name, presence: true # Searches for user based on email. Returns found user or new user. @@ -47,26 +47,12 @@ class User < ActiveRecord::Base user end - def role?(role) - Rails.logger.debug('Checking role in user') - !!roles.find_by_name(role.to_s.downcase.camelize) - end - - def admin? - role?('Admin') - end - - def organizer? - role?('Organizer') - end - def get_roles roles end def setup_role - roles << Role.where(name: 'Admin') if User.count == 0 - roles << Role.where(name: 'Participant') if roles.empty? + self.is_admin = true if User.count == 0 end def self.prepare(params) diff --git a/app/views/admin/conference/_todo_list.html.haml b/app/views/admin/conference/_todo_list.html.haml index 3f87ecbd..06972f0a 100644 --- a/app/views/admin/conference/_todo_list.html.haml +++ b/app/views/admin/conference/_todo_list.html.haml @@ -23,7 +23,7 @@ = link_to 'Add tracks', admin_conference_tracks_path(conference_progress['short_title']) %li{'class'=>class_for_todo(conference_progress['event_types'])} %span{'class'=>icon_for_todo(conference_progress['event_types'])} - = link_to 'Add event types', admin_conference_eventtypes_path(conference_progress['short_title']) + = link_to 'Add event types', admin_conference_event_types_path(conference_progress['short_title']) %li{'class'=>class_for_todo(conference_progress['difficulty_levels'])} %span{'class'=>icon_for_todo(conference_progress['difficulty_levels'])} = link_to 'Add difficulty levels', admin_conference_difficulty_levels_path(conference_progress['short_title']) diff --git a/app/views/admin/eventtypes/_event_type_fields.html.erb b/app/views/admin/event_types/_event_type_fields.html.erb similarity index 100% rename from app/views/admin/eventtypes/_event_type_fields.html.erb rename to app/views/admin/event_types/_event_type_fields.html.erb diff --git a/app/views/admin/eventtypes/index.html.haml b/app/views/admin/event_types/index.html.haml similarity index 76% rename from app/views/admin/eventtypes/index.html.haml rename to app/views/admin/event_types/index.html.haml index ad9256d1..c225bd66 100644 --- a/app/views/admin/eventtypes/index.html.haml +++ b/app/views/admin/event_types/index.html.haml @@ -1,5 +1,5 @@ .row .col-md-8 - = semantic_form_for(@conference, url: admin_conference_eventtypes_path(@conference.short_title, @conference.event_types)) do |f| + = semantic_form_for(@conference, url: admin_conference_event_types_path(@conference.short_title, @conference.event_types)) do |f| = dynamic_association :event_types, "Event Types", f = f.action :submit, :as => :button, :button_html => {:class => "btn btn-primary"} diff --git a/app/views/admin/questions/_questions.html.haml b/app/views/admin/questions/_questions.html.haml index 9feda3aa..d5577cb6 100644 --- a/app/views/admin/questions/_questions.html.haml +++ b/app/views/admin/questions/_questions.html.haml @@ -18,11 +18,13 @@ = ',' = label_tag dom_id(q), "Answers: #{q.answers.map {|a| a.title}.join(', ')}" - %td= link_to 'Edit', edit_admin_conference_question_path(@conference.short_title, q), - class: 'btn btn-primary', - disabled: q.global == true && !has_role?(current_user, 'Admin') + - if can? :update, q + %td= link_to 'Edit', edit_admin_conference_question_path(@conference.short_title, q), + class: 'btn btn-primary', + disabled: q.global == true - %td= link_to 'Delete', admin_conference_question_path(@conference.short_title, q), - method: :delete, remote: true, class: 'btn btn-danger', - confirm: "Delete question '#{q.title}'?", - disabled: q.global == true && !has_role?(current_user, "Admin") + - if can? :destroy, q + %td= link_to 'Delete', admin_conference_question_path(@conference.short_title, q), + method: :delete, remote: true, class" 'btn btn-danger', + confirm: "Delete question '#{q.title}'?", + disabled: q.global == true diff --git a/app/views/admin/registrations/index.html.haml b/app/views/admin/registrations/index.html.haml index 78aa4db7..a0590a59 100644 --- a/app/views/admin/registrations/index.html.haml +++ b/app/views/admin/registrations/index.html.haml @@ -7,9 +7,11 @@ = "(#{@registrations.length})" = " - Attended (#{@attended})" .btn-group.pull-right - = link_to "New", new_admin_conference_registration_path(@conference.short_title), :class => "btn btn-default" - = link_to "Export PDF", admin_conference_registrations_path(@conference.short_title, :format => :pdf), :class => "btn btn-default" - = link_to "Export XLS", {:format => :xlsx}, :class => "btn btn-default" + - if can? :create, Registration + = link_to "New", new_admin_conference_registration_path(@conference.short_title), :class => "btn btn-default" + - if can? :read, Registration + = link_to "Export PDF", admin_conference_registrations_path(@conference.short_title, :format => :pdf), :class => "btn btn-default" + = link_to "Export XLS", {:format => :xlsx}, :class => "btn btn-default" %table.table.table-bordered.table-striped.table-hover#registrations %thead %th @@ -21,7 +23,7 @@ %th %th %th - - counter = 0 + - counter = 0 - @registrations.each do |registration| %tr %td @@ -33,7 +35,7 @@ - if registration.supporter_level && registration.supporter_level.title != 'Free' %p{:style => "color:red"} = registration.supporter_level.title - + -elsif field == 'attended' = link_to "#{registration.send(field.to_sym)}", admin_conference_registrations_change_field_path(@conference.short_title, :id => registration.id, :view_field => "#{field}"), :method => :patch, ":#{field}" => registration.send(field.to_sym), :class => "btn btn-success" @@ -64,11 +66,11 @@ "bLengthChange": false } ); } ); - + function toggle(rowid) { if( document.getElementById(rowid).style.display=='none' ){ document.getElementById(rowid).style.display = ''; }else{ document.getElementById(rowid).style.display = 'none'; } - }; \ No newline at end of file + }; diff --git a/app/views/admin/users/_add_roles.html.haml b/app/views/admin/users/_add_roles.html.haml new file mode 100644 index 00000000..93a0651f --- /dev/null +++ b/app/views/admin/users/_add_roles.html.haml @@ -0,0 +1,11 @@ += semantic_form_for(user, url: add_role_admin_user_path(user), remote: true) do |f| + .pull-left + = f.action :submit, as: :button, label: 'Add Role', button_html: {value: 'Save', class: 'btn btn-success'} + %br + %br + = f.fields_for :roles, Role.new do |role| + = role.input :name, label: 'Select role', collection: Role::LABELS + = role.label 'Select Conference' + %br + = role.input :resource, label: false, collection: Conference.all.map { |c| [c.short_title, c.id] } + %br diff --git a/app/views/admin/users/_form.html.haml b/app/views/admin/users/_form.html.haml index ddd33cf8..18a751f5 100644 --- a/app/views/admin/users/_form.html.haml +++ b/app/views/admin/users/_form.html.haml @@ -1,8 +1,13 @@ = semantic_form_for [:admin, @user] do |f| - = f.inputs "Basic Information" do + = f.inputs 'Basic Information' do = f.input :name, :as => :string = f.input :email - = f.input :affiliation, :as => :string - = f.input :biography, :input_html => {:rows => 10} - = f.actions do - = f.action :submit, :button_html => {:class => "btn btn-primary"} + = f.input :affiliation, as: :string + = f.input :biography, input_html: { rows: 5, "onkeyup" => "word_count(this, 'biography-count', 150)" } + You have used + %span#biography-count #{@user.biography_word_count} + words. Biographies are limited to 150 words. + %br + %br + = f.actions do + = f.action :submit, button_html: { class: 'btn btn-primary' } diff --git a/app/views/admin/users/_user_roles.html.haml b/app/views/admin/users/_user_roles.html.haml new file mode 100644 index 00000000..caceec39 --- /dev/null +++ b/app/views/admin/users/_user_roles.html.haml @@ -0,0 +1,10 @@ +- user ||= @user +.roles{ id: 'current_roles' } + = semantic_form_for(user, url: admin_user_path(user)) do |f| + = f.action :submit, as: :button, label: 'Update Roles', button_html: {value: 'Save', class: 'btn btn-primary'} + = f.inputs "Roles for #{@user.name}" do + - user.roles.each do |role| + %br + = hidden_field_tag "user[role_ids][]", nil + = check_box_tag "user[role_ids][]", role.id, user.roles.include?(role), id: dom_id(role) + = label_tag dom_id(role), "#{ role.name.capitalize } for #{ role.resource_type.constantize.find(role.resource_id).short_title }" diff --git a/app/views/admin/users/add_role.js.erb b/app/views/admin/users/add_role.js.erb new file mode 100644 index 00000000..9c38fbbd --- /dev/null +++ b/app/views/admin/users/add_role.js.erb @@ -0,0 +1 @@ +$('#current_roles').html("<%= escape_javascript(render partial: 'user_roles').html_safe %>"); diff --git a/app/views/admin/users/edit.html.haml b/app/views/admin/users/edit.html.haml new file mode 100644 index 00000000..2536e5b6 --- /dev/null +++ b/app/views/admin/users/edit.html.haml @@ -0,0 +1,19 @@ +.row + .col-md-12 + .tabbable + %ul.nav.nav-tabs + %li.active + = link_to 'User', '#user-content', 'data-toggle'=>'tab' + %li= link_to 'Roles', '#roles-content', 'data-toggle'=>'tab' + .tab-content + #user-content.tab-pane.active + = render partial: 'form' + + #roles-content.tab-pane + .row + .col-md-6 + %br + = render partial: 'user_roles', locals: { user: @user } + .col-md-6 + %br + = render partial: 'add_roles', locals: { user: @user } diff --git a/app/views/admin/users/index.html.haml b/app/views/admin/users/index.html.haml index d66a475d..65ec886e 100644 --- a/app/views/admin/users/index.html.haml +++ b/app/views/admin/users/index.html.haml @@ -5,7 +5,7 @@ - if @users = "(#{@users.length})" - = link_to "New User", new_admin_user_path, :class => "btn btn-success pull-right" + = link_to "New User", new_admin_user_path, class: 'btn btn-success pull-right' .well %table.table.table-striped.table-bordered.table-hover#users %thead @@ -40,37 +40,21 @@ %td = user.registrations.count %td - .modal.fade{:id => "user-role-selection-#{user.id}", "role" => "dialog", "aria-hidden" => "true"} - .modal-dialog - .modal-content - .modal-header - %button{"type"=>"button", :class=>"close", "data-dismiss"=>"modal", "aria-hidden"=>"true"} - × - %h3{:id => "role-selector-header-#{user.id}"} - Modifying Roles - .modal-body - - if current_user == user - You cannot modify your own role! - %br - %button{:class=> "btn btn-danger", "data-dismiss"=> "modal", "aria-hidden"=>"true"} - Cancel - - else - = "Give #{user.name} (#{user.email}) the following roles:" - = semantic_form_for(user, :url => admin_user_path(user), :method => :put) do |f| - = f.input :roles, :label => false - %button{:class=> "btn btn-danger", "data-dismiss"=> "modal", "aria-hidden"=>"true"} - Cancel - = f.action :submit, :as => :button, :button_html => {:value => "Save", :class => "btn btn-primary"} - =link_to "#{user.roles.map { |role| role.name }.join ', '}", "#", "data-toggle" => "modal", "data-target" => "#user-role-selection-#{user.id}",id: "user-modify-role-#{user.id}" - %td - = link_to "Edit", edit_admin_user_path(user) - %td - = link_to "View", admin_user_path(user) - %td - - if current_user.id == user.id or user.role_ids.include? 3 - =link_to 'Delete',admin_user_path(user), :method => :delete , :data => {:confirm => 'Are you sure ?'}, :disabled => true,:class => "btn btn-primary disabled btn-danger",:role => "button" + - if can? :update, Role + = link_to "#{ user.roles.present? ? (user.roles.map { |role| "#{ role.name.titleize }(#{ role.resource_type.constantize.find(role.resource_id).short_title })" }.join ', ') : 'Add Role'}", "#", "data-toggle" => "modal", "data-target" => "#user-role-selection-#{user.id}",id: "user-modify-role-#{user.id}" + - else - =link_to 'Delete',admin_user_path(user), :method=> :delete , :data=> {:confirm => 'Are you sure ?'},:class => "btn btn-primary btn-danger" + = user.roles.map { |role| "#{ role.name.capitalize } for #{ role.resource_type.constantize.find(role.resource_id).short_title }" }.join ', ' + - if can? :show, user + %td + = link_to "View", admin_user_path(user), class: 'btn btn-success' + - if can? :update, user + %td + = link_to "Edit", edit_admin_user_path(user), class: 'btn btn-primary' + - if can? :destroy, user + %td= link_to 'Delete',admin_user_path(user), :method=> :delete , :data=> {:confirm => 'Are you sure ?'},:class => "btn btn-primary btn-danger" + - else + %td= link_to 'Delete',admin_user_path(user), :method => :delete , :data => {:confirm => 'Are you sure ?'}, :disabled => true,:class => "btn btn-primary disabled btn-danger",:role => "button" :javascript diff --git a/app/views/admin/users/show.html.haml b/app/views/admin/users/show.html.haml index c41a6b3b..9ad4c8ab 100644 --- a/app/views/admin/users/show.html.haml +++ b/app/views/admin/users/show.html.haml @@ -1,7 +1,14 @@ +- if can? :update, @user + .pull-right + = link_to "Edit", edit_admin_user_path(@user), class: 'btn btn-primary' %table.table - @show_attributes.each do |attr| %tr - %td + %td{style: 'width:20%'} %b = attr.capitalize.gsub('_', ' ') - %td= @user.send(attr) + - if attr == 'roles' + %td + = @user.send(attr).map { |role| "#{ role.name.capitalize } of #{ role.resource_type.constantize.find(role.resource_id).short_title }"}.join(', ') + - else + %td= @user.send(attr) diff --git a/app/views/conference/_registration.html.haml b/app/views/conference/_registration.html.haml index 124d3209..5efe1223 100644 --- a/app/views/conference/_registration.html.haml +++ b/app/views/conference/_registration.html.haml @@ -13,7 +13,7 @@ -else %h4 Registration is Closed, it was from #{ date_string(@conference.registration_start_date, @conference.registration_end_date) } - if @conference.registration_open? - = link_to "Register for #{@conference.short_title}", register_conference_path(@conference.short_title), :class =>"btn btn-success btn-lg", target: '_blank' + = link_to "Register for #{@conference.short_title}", conference_register_path(@conference.short_title), :class =>"btn btn-success btn-lg", target: '_blank' - if @conference.use_supporter_levels? - if @conference.include_tickets_in_splash? = render 'tickets' diff --git a/app/views/conference_registration/register.html.haml b/app/views/conference_registration/register.html.haml index 13b6b568..4019ed01 100644 --- a/app/views/conference_registration/register.html.haml +++ b/app/views/conference_registration/register.html.haml @@ -1,6 +1,6 @@ .row .col-md-12 - = semantic_form_for(@registration, :url => register_conference_path(@conference.short_title), :html => { :method => :patch }) do |f| + = semantic_form_for(@registration, :url => conference_register_path(@conference.short_title), :html => { :method => :patch }) do |f| .tabbable %ul.nav.nav-tabs %li.active @@ -16,7 +16,7 @@ = render 'conference_registration/volunteer', :f => f - if @registered = f.action :submit, :button_html => { :value => "Update Registration", :class => "btn btn-primary" } - = link_to "Unregister", register_conference_path(@conference.short_title),:method => :delete, :class => "btn btn-danger", + = link_to "Unregister", conference_register_path(@conference.short_title),:method => :delete, :class => "btn btn-danger", :confirm => "Are you sure you want to unregister?" - else = f.action :submit, :button_html => { :value => "Register", :class => "btn btn-primary", id: 'register' } diff --git a/app/views/home/_conference_details.html.haml b/app/views/home/_conference_details.html.haml index a401ea44..46fe2bde 100644 --- a/app/views/home/_conference_details.html.haml +++ b/app/views/home/_conference_details.html.haml @@ -25,9 +25,9 @@ = link_to "View Conference", conference_path(conference.short_title), :class =>"btn btn-default" - if conference.registration_open? - if conference.user_registered?(current_user) - = link_to "Modify Registration", register_conference_path(conference.short_title), :class =>"btn btn-default" + = link_to "Modify Registration", conference_register_path(conference.short_title), :class =>"btn btn-default" - else - = link_to "Register", register_conference_path(conference.short_title), :class =>"btn btn-success" + = link_to "Register", conference_register_path(conference.short_title), :class =>"btn btn-success" = link_to "Schedule", conference_schedule_path(conference.short_title), :class =>"btn btn-default" if conference.call_for_papers and conference.call_for_papers.schedule_public - if !current_user.nil? && current_user.proposal_count(conference) > 0 = link_to "View My Proposals", conference_proposal_index_path(conference.short_title), :class =>"btn btn-default" diff --git a/app/views/layouts/_admin_sidebar.html.haml b/app/views/layouts/_admin_sidebar.html.haml index f9eddd03..13a4d34f 100644 --- a/app/views/layouts/_admin_sidebar.html.haml +++ b/app/views/layouts/_admin_sidebar.html.haml @@ -10,83 +10,104 @@ %span.glyphicon.glyphicon-home All Conferences - @conferences.each do |conference| + - if can? :show, conference + %li + = link_to(admin_conference_path(conference.short_title)) do + %span.glyphicon.glyphicon-cog + Manage + = conference.short_title + - if can? :create, Conference %li - = link_to(admin_conference_path(conference.short_title)) do - %span.glyphicon.glyphicon-cog - Manage - = conference.short_title - %li - = link_to(new_admin_conference_path) do - %span.glyphicon.glyphicon-plus - New Conference + = link_to(new_admin_conference_path) do + %span.glyphicon.glyphicon-plus + New Conference %hr - %li{:class=> "#{active_nav_li(admin_conference_path(@conference.short_title))} nav-header nav-header-bigger"} - = link_to(admin_conference_path(@conference.short_title)) do - %span.glyphicon.glyphicon-dashboard - Manage - %li{:class=> active_nav_li(admin_conference_events_path(@conference.short_title))} - = link_to(admin_conference_events_path(@conference.short_title)) do - %span.glyphicon.glyphicon-comment - Events - %li{:class=> active_nav_li(admin_conference_registrations_path(@conference.short_title))} - = link_to(admin_conference_registrations_path(@conference.short_title)) do - %span.glyphicon.glyphicon-user - Registrations - %li{class: active_nav_li(admin_conference_schedule_path(@conference.short_title))} - = link_to(admin_conference_schedule_path(@conference.short_title), target: '_blank') do - %span.glyphicon.glyphicon-calendar - Schedule - %li{class: active_nav_li(admin_conference_campaigns_path(@conference.short_title))} - = link_to(admin_conference_campaigns_path(@conference.short_title)) do - %span.glyphicon.glyphicon-bullhorn - Campaigns + - if can? :show, @conference + %li{:class=> "#{active_nav_li(admin_conference_path(@conference.short_title))} nav-header nav-header-bigger"} + = link_to(admin_conference_path(@conference.short_title)) do + %span.glyphicon.glyphicon-dashboard + Manage + - if can? :index, Event, conference_id: @conference.id + %li{:class=> active_nav_li(admin_conference_events_path(@conference.short_title))} + = link_to(admin_conference_events_path(@conference.short_title)) do + %span.glyphicon.glyphicon-comment + Events + - if can? :index, @conference => Registration + %li{:class=> active_nav_li(admin_conference_registrations_path(@conference.short_title))} + = link_to(admin_conference_registrations_path(@conference.short_title)) do + %span.glyphicon.glyphicon-user + Registrations + - if can? :update, :schedule + %li{class: active_nav_li(admin_conference_schedule_path(@conference.short_title))} + = link_to(admin_conference_schedule_path(@conference.short_title), target: '_blank') do + %span.glyphicon.glyphicon-calendar + Schedule + - if can? :index, Campaign, conference_id: @conference.id + %li{class: active_nav_li(admin_conference_campaigns_path(@conference.short_title))} + = link_to(admin_conference_campaigns_path(@conference.short_title)) do + %span.glyphicon.glyphicon-bullhorn + Campaigns %hr - %li{:class=> "#{active_nav_li(edit_admin_conference_path(@conference.short_title))} nav-header nav-header-bigger"} - = link_to(edit_admin_conference_path(@conference.short_title)) do - %span.glyphicon.glyphicon-cog - Settings - %li{:class=> "#{active_nav_li(admin_conference_targets_path(@conference.short_title))}"} - = link_to(admin_conference_targets_path(@conference.short_title)) do - %span.glyphicon.glyphicon-flag - Targets - %li{:class=> "#{active_nav_li(admin_conference_venue_info_path(@conference.short_title))} myAccordion"} - = link_to(admin_conference_venue_info_path(@conference.short_title)) do - %span.glyphicon.glyphicon-road - Venue - %span.small.glyphicon.glyphicon-chevron-right - %ul.nav.nav-stacked.nav-pills.small.collapse.subNav - %li{:class=> active_nav_li(admin_conference_rooms_path(@conference.short_title))} - = link_to 'Rooms', admin_conference_rooms_path(@conference.short_title) - %li{ class: active_nav_li(admin_conference_lodgings_path(@conference.short_title)) } - = link_to 'Lodgings', admin_conference_lodgings_path(@conference.short_title) - %li{:class=> "#{active_nav_li(admin_conference_sponsorship_levels_path(@conference.short_title))} myAccordion" } - = link_to(admin_conference_sponsorship_levels_path(@conference.short_title)) do - %span.glyphicon.glyphicon-star - Sponsorship - %span.small.glyphicon.glyphicon-chevron-right - %ul.nav.nav-stacked.nav-pills.small.collapse.subNav - %li{:class=> active_nav_li(admin_conference_sponsors_path(@conference.short_title))} - = link_to 'Sponsors', admin_conference_sponsors_path(@conference.short_title) - %li{ class: active_nav_li(admin_conference_supporter_levels_path(@conference.short_title)) } - = link_to(admin_conference_supporter_levels_path(@conference.short_title)) do - %span.glyphicon.glyphicon-usd - Supporter Levels - %li{:class=> active_nav_li(admin_conference_emails_path(@conference.short_title))} - = link_to(admin_conference_emails_path(@conference.short_title)) do - %span.glyphicon.glyphicon-envelope - E-Mails - %li{:class=> "#{active_nav_li(admin_conference_callforpapers_path(@conference.short_title))} myAccordion"} - = link_to(admin_conference_callforpapers_path(@conference.short_title)) do - %span.glyphicon.glyphicon-comment - Call for papers - %span.small.glyphicon.glyphicon-chevron-right - %ul.nav.nav-stacked.nav-pills.small.collapse.subNav - %li{:class=> active_nav_li(admin_conference_tracks_path(@conference.short_title))} - = link_to 'Tracks', admin_conference_tracks_path(@conference.short_title) - %li{:class=> active_nav_li(admin_conference_eventtypes_path(@conference.short_title))} - = link_to 'Event types', admin_conference_eventtypes_path(@conference.short_title) - %li{:class=> active_nav_li(admin_conference_difficulty_levels_path(@conference.short_title))} - = link_to 'Difficulty levels', admin_conference_difficulty_levels_path(@conference.short_title) + - if can? :update, Conference, id: @conference.id + %li{:class=> "#{active_nav_li(edit_admin_conference_path(@conference.short_title))} nav-header nav-header-bigger"} + = link_to(edit_admin_conference_path(@conference.short_title)) do + %span.glyphicon.glyphicon-cog + Settings + - if can? :index, Target, conference_id: @conference.id + %li{:class=> "#{active_nav_li(admin_conference_targets_path(@conference.short_title))}"} + = link_to(admin_conference_targets_path(@conference.short_title)) do + %span.glyphicon.glyphicon-flag + Targets + - if can? :index, Venue, id: @conference.venue.id + %li{:class=> "#{active_nav_li(admin_conference_venue_info_path(@conference.short_title))} myAccordion"} + = link_to(admin_conference_venue_info_path(@conference.short_title)) do + %span.glyphicon.glyphicon-road + Venue + %span.small.glyphicon.glyphicon-chevron-right + %ul.nav.nav-stacked.nav-pills.small.collapse.subNav + - if can? :index, Room, conference_id: @conference.id + %li{:class=> active_nav_li(admin_conference_rooms_path(@conference.short_title))} + = link_to 'Rooms', admin_conference_rooms_path(@conference.short_title) + - if can? :index, Lodging, venue_id: @conference.venue.id + %li{ class: active_nav_li(admin_conference_lodgings_path(@conference.short_title)) } + = link_to 'Lodgings', admin_conference_lodgings_path(@conference.short_title) + - if can? :index, SponsorshipLevel, conference_id: @conference.id + %li{:class=> "#{active_nav_li(admin_conference_sponsorship_levels_path(@conference.short_title))} myAccordion" } + = link_to(admin_conference_sponsorship_levels_path(@conference.short_title)) do + %span.glyphicon.glyphicon-star + Sponsorship + %span.small.glyphicon.glyphicon-chevron-right + %ul.nav.nav-stacked.nav-pills.small.collapse.subNav + - if can? :index, Sponsor, conference_id: @conference.id + %li{:class=> active_nav_li(admin_conference_sponsors_path(@conference.short_title))} + = link_to 'Sponsors', admin_conference_sponsors_path(@conference.short_title) + - if can? :index, SupporterLevel, conference_id: @conference.id + %li{ class: active_nav_li(admin_conference_supporter_levels_path(@conference.short_title)) } + = link_to(admin_conference_supporter_levels_path(@conference.short_title)) do + %span.glyphicon.glyphicon-usd + Supporter Levels + - if can? :index, EmailSettings, conference_id: @conference.id + %li{:class=> active_nav_li(admin_conference_emails_path(@conference.short_title))} + = link_to(admin_conference_emails_path(@conference.short_title)) do + %span.glyphicon.glyphicon-envelope + E-Mails + - if can? :index, CallForPapers, conference_id: @conference.id + %li{:class=> "#{active_nav_li(admin_conference_callforpapers_path(@conference.short_title))} myAccordion"} + = link_to(admin_conference_callforpapers_path(@conference.short_title)) do + %span.glyphicon.glyphicon-comment + Call for papers + %span.small.glyphicon.glyphicon-chevron-right + %ul.nav.nav-stacked.nav-pills.small.collapse.subNav + - if can? :index, @conference => Track + %li{:class=> active_nav_li(admin_conference_tracks_path(@conference.short_title))} + = link_to 'Tracks', admin_conference_tracks_path(@conference.short_title) + - if can? :index, EventType, conference_id: @conference.id + %li{:class=> active_nav_li(admin_conference_event_types_path(@conference.short_title))} + = link_to 'Event types', admin_conference_event_types_path(@conference.short_title) + - if can? :index, DifficultyLevel, conference_id: @conference.id + %li{:class=> active_nav_li(admin_conference_difficulty_levels_path(@conference.short_title))} + = link_to 'Difficulty levels', admin_conference_difficulty_levels_path(@conference.short_title) + - if can? :index, Question, conference_id: @conference.id %li{:class=> active_nav_li(admin_conference_questions_path(@conference.short_title))} = link_to(admin_conference_questions_path(@conference.short_title)) do %span.glyphicon.glyphicon-question-sign diff --git a/app/views/layouts/_admin_sidebar_index.html.haml b/app/views/layouts/_admin_sidebar_index.html.haml index a5f4191c..08e8b3fb 100644 --- a/app/views/layouts/_admin_sidebar_index.html.haml +++ b/app/views/layouts/_admin_sidebar_index.html.haml @@ -10,17 +10,20 @@ %span.glyphicon.glyphicon-home All Conferences - @conferences.each do |conference| + - if can? :show, conference + %li + = link_to(admin_conference_path(conference.short_title)) do + %span.glyphicon.glyphicon-cog + Manage + = conference.short_title + - if can? :create, Conference %li - = link_to(admin_conference_path(conference.short_title)) do - %span.glyphicon.glyphicon-cog - Manage - = conference.short_title - %li - = link_to(new_admin_conference_path) do - %span.glyphicon.glyphicon-plus - New Conference - %hr - %li - = link_to(admin_users_path) do - %span.glyphicon.glyphicon-user - Users + = link_to(new_admin_conference_path) do + %span.glyphicon.glyphicon-plus + New Conference + - if can? :index, User + %hr + %li + = link_to(admin_users_path) do + %span.glyphicon.glyphicon-user + Users diff --git a/app/views/layouts/_user_menu.html.haml b/app/views/layouts/_user_menu.html.haml index bfcbfa6f..fe5edfb3 100644 --- a/app/views/layouts/_user_menu.html.haml +++ b/app/views/layouts/_user_menu.html.haml @@ -11,13 +11,13 @@ = link_to(destroy_user_session_path, :method=>'delete') do %span.glyphicon.glyphicon-minus Sign out --if has_role?(current_user, "admin") || has_role?(current_user, "organizer") +- if can? :index, Conference %li.divider %li = link_to(admin_conference_index_path()) do %span.glyphicon.glyphicon-home Administration - -if @conference and @conference.id + -if @conference and @conference.id and can? :index, @conference %li = link_to(admin_conference_path(@conference.short_title)) do %span.glyphicon.glyphicon-cog diff --git a/app/views/proposal/_form.html.haml b/app/views/proposal/_form.html.haml index e8c8d17d..0e88e38a 100644 --- a/app/views/proposal/_form.html.haml +++ b/app/views/proposal/_form.html.haml @@ -45,7 +45,7 @@ data.formData = inputs.serializeArray(); }); $.getJSON($('#fileupload').prop('action'), function (files) { - var fu = $('#fileupload').data('fileupload'), + var fu = $('#fileupload').data('blueimpFileupload'), template; fu._adjustMaxNumberOfFiles(-files.length); template = fu._renderDownload(files) diff --git a/app/views/proposal/_proposal_form.html.haml b/app/views/proposal/_proposal_form.html.haml index 86681512..dc182c12 100644 --- a/app/views/proposal/_proposal_form.html.haml +++ b/app/views/proposal/_proposal_form.html.haml @@ -1,20 +1,20 @@ = semantic_form_for(@event, :url => @url) do |f| %section#basic = f.inputs :name => "Session Information" do - - if !@conference.call_for_papers.schedule_changes && @event.state == "confirmed" && !organizer_or_admin? + - if can? :update, @event or can? :create, @event + = f.input :title, :as => :string, :required => true + - else Title: #{@event.title} %br %br - - else - = f.input :title, :as => :string, :required => true = f.input :subtitle, :as => :string %section#details - - if (@event.state === "unconfirmed" || @event.state === "confirmed") && !organizer_or_admin? && !@conference.call_for_papers.schedule_changes + - if can? :update, @event or can? :create, @event + = f.input :event_type_id,:as => :select, :collection => @conference.event_types.map {|x| ["#{x.title} - #{show_time(x.length)}", x.id]}, :include_blank => false, :label => "Session Type" + - else Event type: #{@event.event_type.title} %br %br - - else - = f.input :event_type_id,:as => :select, :collection => @conference.event_types.map {|x| ["#{x.title} - #{show_time(x.length)}", x.id]}, :include_blank => false, :label => "Session Type" = f.input :difficulty_level, :as => :select, :collection => @conference.difficulty_levels, :include_blank => "(Please select)" if @conference.use_difficulty_levels = f.input :require_registration = f.input :abstract, :input_html => {:rows => 5, :class => "span11"}, diff --git a/app/views/proposal/index.html.haml b/app/views/proposal/index.html.haml index 96c8a4fc..5338a138 100644 --- a/app/views/proposal/index.html.haml +++ b/app/views/proposal/index.html.haml @@ -27,7 +27,7 @@ (Pre-registered: #{pre_registered(event).count}) - if event.confirmed? && !@conference.user_registered?(current_user) %br - = link_to "Register to attend", register_conference_path(@conference.short_title), :style => "font-size:10px;" + = link_to "Register to attend", conference_register_path(@conference.short_title), :style => "font-size:10px;" %td .pull-right - if event.transition_possible? :confirm diff --git a/app/views/proposal/show.html.haml b/app/views/proposal/show.html.haml index 1478b3ae..23cc2945 100644 --- a/app/views/proposal/show.html.haml +++ b/app/views/proposal/show.html.haml @@ -7,7 +7,7 @@ %small = @event.subtitle = link_to "Schedule", conference_schedule_path(@conference.short_title), :class =>"btn btn-success pull-right" - - if has_role?(current_user, "admin") + - if can? :edit, @event = link_to "Edit", edit_admin_conference_event_path(@conference.short_title, @event), :class => "btn btn-mini btn-primary pull-right" .row .col-md-3 @@ -37,7 +37,7 @@ %span.label{:style =>"background-color: #{@event.difficulty_level.color};"} = @event.difficulty_level.title - if @event.require_registration - = link_to "Registration required!", register_conference_path(@conference.short_title), :class => "btn btn-xs btn-warning" + = link_to "Registration required!", conference_register_path(@conference.short_title), :class => "btn btn-xs btn-warning" .col-md-9 .row .col-md-12 diff --git a/config/initializers/rolify.rb b/config/initializers/rolify.rb new file mode 100644 index 00000000..30651dd0 --- /dev/null +++ b/config/initializers/rolify.rb @@ -0,0 +1,8 @@ +Rolify.configure do |config| + # By default ORM adapter is ActiveRecord. uncomment to use mongoid + # config.use_mongoid + + # Dynamic shortcuts for User class (user.is_admin? like methods). Default is: false + # Enable this feature _after_ running rake db:migrate as it relies on the roles table + config.use_dynamic_shortcuts +end diff --git a/config/routes.rb b/config/routes.rb index 20c43a75..feab1685 100644 --- a/config/routes.rb +++ b/config/routes.rb @@ -5,7 +5,11 @@ Osem::Application.routes.draw do path: 'accounts' namespace :admin do - resources :users + resources :users do + member do + patch 'add_role' => 'users#add_role' + end + end resources :people resources :conference do resource :schedule, only: [:show, :update] @@ -37,7 +41,7 @@ Osem::Application.routes.draw do resources :campaigns - resources :eventtypes, only: [:show, :index] do + resources :event_types, only: [:show, :index] do collection do patch :update end @@ -88,10 +92,10 @@ Osem::Application.routes.draw do resource :schedule, only: [] do get "/" => "schedule#index" end + get "/register" => "conference_registration#register" + patch "/register" => "conference_registration#update" + delete "/register" => "conference_registration#unregister" member do - get "/register" => "conference_registration#register" - patch "/register" => "conference_registration#update" - delete "/register" => "conference_registration#unregister" get "gallery_photos" end end diff --git a/db/migrate/20140711072651_add_description_and_resource_to_roles.rb b/db/migrate/20140711072651_add_description_and_resource_to_roles.rb new file mode 100644 index 00000000..8e5a16ec --- /dev/null +++ b/db/migrate/20140711072651_add_description_and_resource_to_roles.rb @@ -0,0 +1,10 @@ +class AddDescriptionAndResourceToRoles < ActiveRecord::Migration + def change + add_column :roles, :description, :string + add_reference :roles, :resource, polymorphic: true + + add_index(:roles, :name) + add_index(:roles, [:name, :resource_type, :resource_id]) + add_index(:roles_users, [:user_id, :role_id]) + end +end diff --git a/db/migrate/20140718103856_add_is_admin_to_users.rb b/db/migrate/20140718103856_add_is_admin_to_users.rb new file mode 100644 index 00000000..def2bbb0 --- /dev/null +++ b/db/migrate/20140718103856_add_is_admin_to_users.rb @@ -0,0 +1,5 @@ +class AddIsAdminToUsers < ActiveRecord::Migration + def change + add_column :users, :is_admin, :boolean + end +end diff --git a/db/schema.rb b/db/schema.rb index 4f112525..086eb71a 100644 --- a/db/schema.rb +++ b/db/schema.rb @@ -352,15 +352,23 @@ ActiveRecord::Schema.define(version: 20140724113107) do create_table "roles", force: true do |t| t.string "name" + t.string "description" + t.integer "resource_id" + t.string "resource_type" t.datetime "created_at" t.datetime "updated_at" end + add_index "roles", ["name", "resource_type", "resource_id"], name: "index_roles_on_name_and_resource_type_and_resource_id" + add_index "roles", ["name"], name: "index_roles_on_name" + create_table "roles_users", id: false, force: true do |t| t.integer "role_id" t.integer "user_id" end + add_index "roles_users", ["user_id", "role_id"], name: "index_roles_users_on_user_id_and_role_id" + create_table "rooms", force: true do |t| t.string "guid", null: false t.integer "conference_id" @@ -466,6 +474,7 @@ ActiveRecord::Schema.define(version: 20140724113107) do t.string "tshirt" t.string "languages" t.text "volunteer_experience" + t.boolean "is_admin" end add_index "users", ["confirmation_token"], name: "index_users_on_confirmation_token", unique: true diff --git a/db/seeds.rb b/db/seeds.rb index 92d873a8..9d72ff17 100644 --- a/db/seeds.rb +++ b/db/seeds.rb @@ -5,22 +5,28 @@ # # cities = City.create([{ name: 'Chicago' }, { name: 'Copenhagen' }]) # Mayor.create(name: 'Emanuel', city: cities.first) -Role.create(name: "Participant") -Role.create(name: "Organizer") -Role.create(name: "Admin") -qtype_yesno = QuestionType.create(title: "Yes/No") -QuestionType.create(title: "Single Choice") -QuestionType.create(title: "Multiple Choice") +# Questions +qtype_yesno = QuestionType.create(title: 'Yes/No') +qtype_single = QuestionType.create(title: 'Single Choice') +qtype_multiple = QuestionType.create(title: 'Multiple Choice') -answer_yes = Answer.create(title: "Yes") -answer_no = Answer.create(title: "No") +<<<<<<< HEAD +questions_yes_no.each do |i| + q = Question.create(title: i, question_type_id: qtype_yesno.id, global: true) -questions_yes_no = ["Do you need handicapped access to the venue?", "Are you attending with partner?", "Will you attend the social event(s)?", "Will you stay at suggested hotel?"] +======= +answer_yes = Answer.create(title: 'Yes') +answer_no = Answer.create(title: 'No') + +questions_yes_no = ['Do you need handicapped access to the venue?', + 'Are you attending with partner?', 'Will you attend the social event(s)?', + 'Will you stay at suggested hotel?'] questions_yes_no.each do |i| q = Question.create(title: i, question_type_id: qtype_yesno.id, global: true) +>>>>>>> rework roles with rolify Qanswer.create(question_id: q.id, answer_id: answer_no.id) Qanswer.create(question_id: q.id, answer_id: answer_yes.id) end diff --git a/spec/controllers/admin/conferences_controller_spec.rb b/spec/controllers/admin/conferences_controller_spec.rb index 86523fc1..25ba9ccb 100644 --- a/spec/controllers/admin/conferences_controller_spec.rb +++ b/spec/controllers/admin/conferences_controller_spec.rb @@ -3,16 +3,14 @@ require 'spec_helper' describe Admin::ConferenceController do # It is necessary to use bang version of let to build roles before user - let!(:organizer_role) { create(:organizer_role) } - let!(:participant_role) { create(:participant_role) } - let!(:admin_role) { create(:admin_role) } - let(:conference) { create(:conference) } - let(:admin) { create(:admin) } - let(:organizer) { create(:organizer) } + let!(:participant_role) { create(:participant_role) } + let!(:organizer_role) { create(:organizer_conference_1_role, resource_id: conference.id) } + + let(:organizer) { create(:organizer_conference_1, is_admin: true) } let(:participant) { create(:participant) } - shared_examples 'access as administration or organizer' do + shared_examples 'access as administration' do describe 'PATCH #update' do @@ -27,7 +25,7 @@ describe Admin::ConferenceController do it 'changes conference attributes' do patch :update, id: conference.short_title, conference: attributes_for(:conference, title: 'Example Con', - short_title: 'ExCon') + short_title: 'ExCon') conference.reload expect(conference.title).to eq('Example Con') @@ -67,7 +65,7 @@ describe Admin::ConferenceController do it 'does not change conference attributes' do patch :update, id: conference.short_title, conference: attributes_for(:conference, title: 'Example Con', - short_title: nil) + short_title: nil) conference.reload expect(flash[:alert]). @@ -79,7 +77,7 @@ describe Admin::ConferenceController do it 're-renders the #show template' do patch :update, id: conference.short_title, conference: attributes_for(:conference, title: 'Example Con', - short_title: nil) + short_title: nil) expect(flash[:alert]). to eq("Updating conference failed. Short title can't be blank.") @@ -216,59 +214,64 @@ describe Admin::ConferenceController do describe 'administrator access' do before do - sign_in(admin) - end - - it_behaves_like 'access as administration or organizer' - - end - - describe 'organizer access' do - - before(:each) do sign_in(organizer) end - it_behaves_like 'access as administration or organizer' + it_behaves_like 'access as administration' end - shared_examples 'access as participant or guest' do |success_path| + shared_examples 'access as participant or guest' do |path, message| describe 'GET #show' do - it 'requires admin privileges' do + it 'requires organizer privileges' do get :show, id: conference.short_title - expect(response).to redirect_to(send(success_path)) + expect(response).to redirect_to(send(path)) + if message + expect(flash[:alert]).to match(/#{message}/) + end end end describe 'GET #index' do - it 'requires admin privileges' do + it 'requires organizer privileges' do get :index - expect(response).to redirect_to(send(success_path)) + expect(response).to redirect_to(send(path)) + if message + expect(flash[:alert]).to match(/#{message}/) + end end end describe 'GET #new' do - it 'requires admin privileges' do + it 'requires organizer privileges' do get :new - expect(response).to redirect_to(send(success_path)) + expect(response).to redirect_to(send(path)) + if message + expect(flash[:alert]).to match(/#{message}/) + end end end describe 'POST #create' do - it 'requires admin privileges' do + it 'requires organizer privileges' do post :create, conference: attributes_for(:conference, short_title: 'ExCon') - expect(response).to redirect_to(send(success_path)) + expect(response).to redirect_to(send(path)) + if message + expect(flash[:alert]).to match(/#{message}/) + end end end describe 'PATCH #update' do - it 'requires admin privileges' do + it 'requires organizer privileges' do patch :update, id: conference.short_title, - conference: attributes_for(:conference, - short_title: 'ExCon') - expect(response).to redirect_to(send(success_path)) + conference: attributes_for(:conference, + short_title: 'ExCon') + expect(response).to redirect_to(send(path)) + if message + expect(flash[:alert]).to match(/#{message}/) + end end end end @@ -278,7 +281,7 @@ describe Admin::ConferenceController do sign_in(participant) end - it_behaves_like 'access as participant or guest', :root_path + it_behaves_like 'access as participant or guest', :root_path, 'You are not authorized to access this page.' end diff --git a/spec/controllers/admin/users_controller_spec.rb b/spec/controllers/admin/users_controller_spec.rb index e3f64829..a98afa7d 100644 --- a/spec/controllers/admin/users_controller_spec.rb +++ b/spec/controllers/admin/users_controller_spec.rb @@ -1,18 +1,18 @@ require 'spec_helper' describe Admin::UsersController do - let!(:admin_role) { create(:admin_role) } + let!(:organizer_role) { create(:organizer_conference_1_role ) } let!(:participant_role) { create(:participant_role) } - let(:admin) { create(:admin) } + let(:organizer) { create(:organizer_conference_1) } let(:user) { create(:user) } before(:each) do - sign_in(admin) + sign_in(organizer) end describe 'GET #index' do it 'populates an array of users' do user1 = create(:user, email: 'gopesh.7500@gmail.com') user2 = create(:user, email: 'gopesh_750@gmail.com') get :index - expect(assigns(:users)).to match_array([user, admin, user1, user2]) + expect(assigns(:users)).to match_array([user, organizer, user1, user2]) end it 'renders index template' do get :index @@ -31,13 +31,13 @@ describe Admin::UsersController do :user, email: 'example@incoherent.de', id: user.id).email). to eq('example@incoherent.de') end - it "redirects to the updated user" do + it 'redirects to the updated user' do patch :update, id: user.id expect(response).to redirect_to admin_users_path end end end - describe 'DELETE #destroy' do + describe 'DELETE #destroy' do before :each do @user = create(:user) end diff --git a/spec/factories/roles.rb b/spec/factories/roles.rb index 6d56375f..6bd4c883 100644 --- a/spec/factories/roles.rb +++ b/spec/factories/roles.rb @@ -1,16 +1,18 @@ FactoryGirl.define do factory :role do - factory :admin_role do - name 'Admin' - end - factory :organizer_role do - name 'Organizer' + name 'organizer' end factory :participant_role do name 'Participant' end + + factory :organizer_conference_1_role do + name 'organizer' + resource_type 'Conference' + resource_id 1 + end end end diff --git a/spec/factories/users.rb b/spec/factories/users.rb index 7ab2b62c..5b029441 100644 --- a/spec/factories/users.rb +++ b/spec/factories/users.rb @@ -19,12 +19,12 @@ FactoryGirl.define do after(:create) { |user| user.role_ids = create(:participant_role).id } end - factory :admin do - after(:create) { |user| user.role_ids = create(:admin_role).id } + factory :organizer_conference_1 do + after(:create) { |user| user.role_ids = create(:organizer_conference_1_role).id } end - factory :organizer do - after(:create) { |user| user.role_ids = create(:organizer_role).id } + factory :admin do + is_admin true end end end diff --git a/spec/features/campaign_spec.rb b/spec/features/campaign_spec.rb index 9c71a759..6580d736 100644 --- a/spec/features/campaign_spec.rb +++ b/spec/features/campaign_spec.rb @@ -3,9 +3,8 @@ require 'spec_helper' feature Campaign do # It is necessary to use bang version of let to build roles before user - let!(:organizer_role) { create(:organizer_role) } let!(:participant_role) { create(:participant_role) } - let!(:admin_role) { create(:admin_role) } + let!(:organizer_conference_1_role) { create(:organizer_conference_1_role) } shared_examples 'add and update campaign' do |user| scenario 'adds and update a campaign', feature: true, js: true do @@ -42,7 +41,7 @@ feature Campaign do expect(Campaign.count).to eq(expected_count) - campaign = Campaign.where('name'=> 'Test Campaign').first + campaign = Campaign.where('name' => 'Test Campaign').first visit edit_admin_conference_campaign_path(conference.short_title, campaign.id) fill_in 'campaign_name', with: 'Test Campaign 42' @@ -52,8 +51,7 @@ feature Campaign do end end - describe 'admin' do - it_behaves_like 'add and update campaign', :admin - it_behaves_like 'add and update campaign', :organizer + describe 'organizer' do + it_behaves_like 'add and update campaign', :organizer_conference_1 end end diff --git a/spec/features/cfp_spec.rb b/spec/features/cfp_spec.rb index 4c185872..e024e11b 100644 --- a/spec/features/cfp_spec.rb +++ b/spec/features/cfp_spec.rb @@ -3,9 +3,8 @@ require 'spec_helper' feature Conference do # It is necessary to use bang version of let to build roles before user - let!(:organizer_role) { create(:organizer_role) } let!(:participant_role) { create(:participant_role) } - let!(:admin_role) { create(:admin_role) } + let!(:organizer_conference_1_role) { create(:organizer_conference_1_role) } shared_examples 'add and update cfp' do |user| scenario 'adds a new cfp', feature: true, js: true do @@ -87,8 +86,7 @@ feature Conference do end end - describe 'admin' do - it_behaves_like 'add and update cfp', :admin - it_behaves_like 'add and update cfp', :organizer + describe 'organizer' do + it_behaves_like 'add and update cfp', :organizer_conference_1 end end diff --git a/spec/features/conference_spec.rb b/spec/features/conference_spec.rb index 06fb21dc..6eed458d 100644 --- a/spec/features/conference_spec.rb +++ b/spec/features/conference_spec.rb @@ -3,9 +3,8 @@ require 'spec_helper' feature Conference do # It is necessary to use bang version of let to build roles before user - let!(:organizer_role) { create(:organizer_role) } let!(:participant_role) { create(:participant_role) } - let!(:admin_role) { create(:admin_role) } + let!(:organizer_conference_1_role) { create(:organizer_conference_1_role) } shared_examples 'add and update conference' do |user| scenario 'adds a new conference', feature: true, js: true do @@ -37,7 +36,7 @@ feature Conference do scenario 'update conference', feature: true, js: true do conference = create(:conference) expected_count = Conference.count - sign_in create(user) + sign_in create(:organizer_conference_1_role) visit edit_admin_conference_path(conference.short_title) fill_in 'conference_title', with: 'New Con' @@ -56,12 +55,7 @@ feature Conference do end end - describe 'admin' do + describe 'organizer' do it_behaves_like 'add and update conference', :admin end - - describe 'organizer' do - it_behaves_like 'add and update conference', :organizer - end - end diff --git a/spec/features/difficulty_levels_spec.rb b/spec/features/difficulty_levels_spec.rb index 6dcfb990..c5ef30a4 100644 --- a/spec/features/difficulty_levels_spec.rb +++ b/spec/features/difficulty_levels_spec.rb @@ -2,9 +2,8 @@ require 'spec_helper' feature DifficultyLevel do # It is necessary to use bang version of let to build roles before user - let!(:organizer_role) { create(:organizer_role) } let!(:participant_role) { create(:participant_role) } - let!(:admin_role) { create(:admin_role) } + let!(:organizer_conference_1_role) { create(:organizer_conference_1_role) } shared_examples 'difficulty levels' do |user| scenario 'adds and updates difficulty level', feature: true, js: true do @@ -50,11 +49,7 @@ feature DifficultyLevel do end end - describe 'admin' do - it_behaves_like 'difficulty levels', :admin - end - describe 'organizer' do - it_behaves_like 'difficulty levels', :organizer + it_behaves_like 'difficulty levels', :organizer_conference_1 end end diff --git a/spec/features/email_spec.rb b/spec/features/email_spec.rb index 54a51897..877a4d24 100644 --- a/spec/features/email_spec.rb +++ b/spec/features/email_spec.rb @@ -2,9 +2,8 @@ require 'spec_helper' feature Event do # It is necessary to use bang version of let to build roles before user - let!(:organizer_role) { create(:organizer_role) } let!(:participant_role) { create(:participant_role) } - let!(:admin_role) { create(:admin_role) } + let!(:organizer_conference_1_role) { create(:organizer_conference_1_role) } shared_examples 'email settings' do |user| scenario 'updates email settings', @@ -91,11 +90,7 @@ feature Event do end end - describe 'admin' do - it_behaves_like 'email settings', :admin - end - describe 'organizer' do - it_behaves_like 'email settings', :organizer + it_behaves_like 'email settings', :organizer_conference_1 end end diff --git a/spec/features/event_types_spec.rb b/spec/features/event_types_spec.rb index c900c65d..f417ac34 100644 --- a/spec/features/event_types_spec.rb +++ b/spec/features/event_types_spec.rb @@ -2,18 +2,17 @@ require 'spec_helper' feature EventType do # It is necessary to use bang version of let to build roles before user - let!(:organizer_role) { create(:organizer_role) } let!(:participant_role) { create(:participant_role) } - let!(:admin_role) { create(:admin_role) } + let!(:organizer_conference_1_role) { create(:organizer_conference_1_role) } shared_examples 'event types' do |user| scenario 'adds and updates event type', feature: true, js: true do conference = create(:conference) sign_in create(user) - visit admin_conference_eventtypes_path( + visit admin_conference_event_types_path( conference_id: conference.short_title) - expect(page.all('div.nested-fields').count == 2).to be true + expect(page.all('div.nested-fields').count == 2).to be true # Add event type click_link 'Add event_type' expect(page.all('div.nested-fields').count == 3).to be true @@ -55,11 +54,7 @@ feature EventType do end end - describe 'admin' do - it_behaves_like 'event types', :admin - end - describe 'organizer' do - it_behaves_like 'event types', :organizer + it_behaves_like 'event types', :organizer_conference_1 end end diff --git a/spec/features/lodgings_spec.rb b/spec/features/lodgings_spec.rb index 10576cc9..a52d8ed4 100644 --- a/spec/features/lodgings_spec.rb +++ b/spec/features/lodgings_spec.rb @@ -2,9 +2,8 @@ require 'spec_helper' feature Lodging do # It is necessary to use bang version of let to build roles before user - let!(:organizer_role) { create(:organizer_role) } let!(:participant_role) { create(:participant_role) } - let!(:admin_role) { create(:admin_role) } + let!(:organizer_conference_1_role) { create(:organizer_conference_1_role) } shared_examples 'lodgings' do |user| scenario 'adds and updates lodgings', feature: true, js: true do @@ -56,11 +55,7 @@ feature Lodging do end end - describe 'admin' do - it_behaves_like 'lodgings', :admin - end - describe 'organizer' do - it_behaves_like 'lodgings', :organizer + it_behaves_like 'lodgings', :organizer_conference_1 end end diff --git a/spec/features/omniauth_spec.rb b/spec/features/omniauth_spec.rb index 89ef91c6..cb37cbc4 100644 --- a/spec/features/omniauth_spec.rb +++ b/spec/features/omniauth_spec.rb @@ -2,7 +2,7 @@ require 'spec_helper' feature Openid do let!(:participant_role) { create(:participant_role) } - let!(:admin_role) { create(:admin_role) } + let!(:organizer_role) { create(:organizer_role) } shared_examples 'sign in with openid' do diff --git a/spec/features/proposal_spec.rb b/spec/features/proposal_spec.rb index fd25f51f..9f7e6bc6 100644 --- a/spec/features/proposal_spec.rb +++ b/spec/features/proposal_spec.rb @@ -2,16 +2,15 @@ require 'spec_helper' feature Event do # It is necessary to use bang version of let to build roles before user - let!(:organizer_role) { create(:organizer_role) } let!(:participant_role) { create(:participant_role) } - let!(:admin_role) { create(:admin_role) } + let!(:organizer_conference_1_role) { create(:organizer_conference_1_role) } shared_examples 'proposal workflow' do scenario 'submitts a proposal, accepts and confirms', feature: true, js: true do - admin = create(:admin, email: 'admin@example.com') - participant = create(:participant, email: 'participant@example.com', biography: "") + organizer = create(:organizer_conference_1, email: 'admin@example.com') + participant = create(:participant, email: 'participant@example.com') expected_count = Event.count + 1 conference = create(:conference) @@ -49,7 +48,7 @@ feature Event do expect(page.has_content?('Example Proposal')).to be true sign_out - sign_in admin + sign_in organizer # Reject proposal visit admin_conference_events_path(conference.short_title) diff --git a/spec/features/rooms_spec.rb b/spec/features/rooms_spec.rb index dc88f9bd..0025267e 100644 --- a/spec/features/rooms_spec.rb +++ b/spec/features/rooms_spec.rb @@ -2,9 +2,8 @@ require 'spec_helper' feature Room do # It is necessary to use bang version of let to build roles before user - let!(:organizer_role) { create(:organizer_role) } let!(:participant_role) { create(:participant_role) } - let!(:admin_role) { create(:admin_role) } + let!(:organizer_conference_1_role) { create(:organizer_conference_1_role) } shared_examples 'rooms' do |user| scenario 'adds and updates rooms', feature: true, js: true do @@ -43,11 +42,7 @@ feature Room do end end - describe 'admin' do - it_behaves_like 'rooms', :admin - end - describe 'organizer' do - it_behaves_like 'rooms', :organizer + it_behaves_like 'rooms', :organizer_conference_1 end end diff --git a/spec/features/sponsor_spec.rb b/spec/features/sponsor_spec.rb index 24998340..c09a093e 100644 --- a/spec/features/sponsor_spec.rb +++ b/spec/features/sponsor_spec.rb @@ -2,9 +2,8 @@ require 'spec_helper' feature Sponsor do # It is necessary to use bang version of let to build roles before user - let!(:organizer_role) { create(:organizer_role) } let!(:participant_role) { create(:participant_role) } - let!(:admin_role) { create(:admin_role) } + let!(:organizer_conference_1_role) { create(:organizer_conference_1_role) } shared_examples 'sponsors' do |user| scenario 'adds and updates sponsors', feature: true, js: true do @@ -69,11 +68,7 @@ feature Sponsor do end end - describe 'admin' do - it_behaves_like 'sponsors', :admin - end - describe 'organizer' do - it_behaves_like 'sponsors', :organizer + it_behaves_like 'sponsors', :organizer_conference_1 end end diff --git a/spec/features/sponsorship_level_spec.rb b/spec/features/sponsorship_level_spec.rb index c6f75ce4..0974d770 100644 --- a/spec/features/sponsorship_level_spec.rb +++ b/spec/features/sponsorship_level_spec.rb @@ -1,10 +1,9 @@ require 'spec_helper' feature SponsorshipLevel do -# It is necessary to use bang version of let to build roles before user - let!(:organizer_role) { create(:organizer_role) } + # It is necessary to use bang version of let to build roles before user let!(:participant_role) { create(:participant_role) } - let!(:admin_role) { create(:admin_role) } + let!(:organizer_conference_1_role) { create(:organizer_conference_1_role) } shared_examples 'sponsorship levels' do |user| scenario 'adds and updates sponsorship level', feature: true, js: true do @@ -36,11 +35,7 @@ feature SponsorshipLevel do end end - describe 'admin' do - it_behaves_like 'sponsorship levels', :admin - end - describe 'organizer' do - it_behaves_like 'sponsorship levels', :organizer + it_behaves_like 'sponsorship levels', :organizer_conference_1 end end diff --git a/spec/features/supporter_levels_spec.rb b/spec/features/supporter_levels_spec.rb index ee55a385..4b384e03 100644 --- a/spec/features/supporter_levels_spec.rb +++ b/spec/features/supporter_levels_spec.rb @@ -2,9 +2,8 @@ require 'spec_helper' feature SupporterLevel do # It is necessary to use bang version of let to build roles before user - let!(:organizer_role) { create(:organizer_role) } let!(:participant_role) { create(:participant_role) } - let!(:admin_role) { create(:admin_role) } + let!(:organizer_conference_1_role) { create(:organizer_conference_1_role) } shared_examples 'supporter levels' do |user| scenario 'adds and updates supporter level', feature: true, js: true do @@ -43,11 +42,7 @@ feature SupporterLevel do end end - describe 'admin' do - it_behaves_like 'supporter levels', :admin - end - describe 'organizer' do - it_behaves_like 'supporter levels', :organizer + it_behaves_like 'supporter levels', :organizer_conference_1 end end diff --git a/spec/features/tracks_spec.rb b/spec/features/tracks_spec.rb index b1ff4925..d625bbae 100644 --- a/spec/features/tracks_spec.rb +++ b/spec/features/tracks_spec.rb @@ -2,9 +2,8 @@ require 'spec_helper' feature Track do # It is necessary to use bang version of let to build roles before user - let!(:organizer_role) { create(:organizer_role) } let!(:participant_role) { create(:participant_role) } - let!(:admin_role) { create(:admin_role) } + let!(:organizer_conference_1_role) { create(:organizer_conference_1_role) } shared_examples 'tracks' do |user| scenario 'adds and updates tracks', feature: true, js: true do @@ -50,11 +49,7 @@ feature Track do end end - describe 'admin' do - it_behaves_like 'tracks', :admin - end - describe 'organizer' do - it_behaves_like 'tracks', :organizer + it_behaves_like 'tracks', :organizer_conference_1 end end diff --git a/spec/features/user_spec.rb b/spec/features/user_spec.rb index 5e5a57df..51c722d0 100644 --- a/spec/features/user_spec.rb +++ b/spec/features/user_spec.rb @@ -1,14 +1,13 @@ require 'spec_helper' feature User do # It is necessary to use bang version of let to build roles before user - let!(:organizer_role) { create(:organizer_role) } let!(:participant_role) { create(:participant_role) } - let!(:admin_role) { create(:admin_role) } - let(:admin) { create(:admin) } + let!(:organizer_role) { create(:organizer_role) } + let(:organizer) { create(:organizer) } - shared_examples 'admin ability' do + shared_examples 'organizer ability' do |_user| scenario 'deletes a user', feature: true, js: true do - sign_in(admin) + sign_in(organizer) visit admin_users_path expected_count = User.count - 1 page.all('btn btn-primary btn-danger') do @@ -22,7 +21,7 @@ feature User do end scenario 'can modify roles', feature: true, js: true do @user = create(:user) - sign_in(admin) + sign_in(organizer) visit admin_users_path find("#user-modify-role-#{@user.id}").click if find("#user-role-selection-#{@user.id}").visible? @@ -36,7 +35,7 @@ feature User do end end - describe 'admin' do - it_behaves_like 'admin ability', :admin + describe 'organizer' do + it_behaves_like 'organizer ability', :organizer end end diff --git a/spec/features/venue_spec.rb b/spec/features/venue_spec.rb index 7f2e82a3..3c838312 100644 --- a/spec/features/venue_spec.rb +++ b/spec/features/venue_spec.rb @@ -3,9 +3,8 @@ require 'spec_helper' feature Conference do # It is necessary to use bang version of let to build roles before user - let!(:organizer_role) { create(:organizer_role) } let!(:participant_role) { create(:participant_role) } - let!(:admin_role) { create(:admin_role) } + let!(:organizer_role) { create(:organizer_conference_1_role) } shared_examples 'venue' do |user| scenario 'adds and updates venue' do @@ -59,12 +58,8 @@ feature Conference do end end - describe 'admin' do - it_behaves_like 'venue', :admin - end - describe 'organizer' do - it_behaves_like 'venue', :organizer + it_behaves_like 'venue', :organizer_conference_1 end end diff --git a/spec/features/volunteers_spec.rb b/spec/features/volunteers_spec.rb index bb82c468..907e4e69 100644 --- a/spec/features/volunteers_spec.rb +++ b/spec/features/volunteers_spec.rb @@ -2,15 +2,14 @@ require 'spec_helper' feature Conference do # It is necessary to use bang version of let to build roles before user - let!(:organizer_role) { create(:organizer_role) } let!(:participant_role) { create(:participant_role) } - let!(:admin_role) { create(:admin_role) } - let(:admin) { create(:admin) } + let!(:organizer_conference_1_role) { create(:organizer_conference_1_role) } + let(:organizer) { create(:organizer_conference_1) } let(:conference) { create(:conference) } shared_examples 'volunteer' do scenario 'adds and updates vdays', feature: true, js: true do - sign_in(admin) + sign_in(organizer) visit admin_conference_volunteers_info_path( conference_id: conference.short_title) check('Enable Volunteering') @@ -54,7 +53,7 @@ feature Conference do end scenario 'adds and updates vpositions', feature: true, js: true do - sign_in(admin) + sign_in(organizer) visit admin_conference_volunteers_info_path( conference_id: conference.short_title) @@ -119,10 +118,6 @@ feature Conference do end end - describe 'admin' do - it_behaves_like 'volunteer', :admin - end - describe 'organizer' do it_behaves_like 'volunteer', :organizer end diff --git a/spec/models/ability_spec.rb b/spec/models/ability_spec.rb index e8a801f2..7d289917 100644 --- a/spec/models/ability_spec.rb +++ b/spec/models/ability_spec.rb @@ -1,26 +1,67 @@ require 'spec_helper' -require "cancan/matchers" +require 'cancan/matchers' -describe "User" do - describe "abilities" do +describe 'User' do + describe 'Abilities' do subject(:ability){ Ability.new(user) } let(:user){ nil } + let(:conference_not_public) { create(:conference, make_conference_public: false) } + let(:conference_public) { create(:conference, make_conference_public: true) } + let(:event_confirmed) { create(:event, state: 'confirmed') } + let(:someevent) { create(:event) } - context "when is an admin" do - let!(:user) { create(:admin) } + context 'when is a guest' do # Test abilities for guest users - it{ should be_able_to(:manage, Event.new) } + it{ should be_able_to(:show, conference_public)} + it{ should_not be_able_to(:show, conference_not_public)} + + it{ should be_able_to(:show, event_confirmed)} + it{ should_not be_able_to(:show, someevent)} + + it{ should be_able_to(:index, :schedule)} + + it{ should_not be_able_to(:create, Event)} + it{ should_not be_able_to(:manage, Event)} + it{ should_not be_able_to(:manage, Conference)} + it{ should_not be_able_to(:manage, :any)} end - context "when is an participant" do - let(:user) { build(:participant) } + context 'when is a Signed In User' do # Test abilities for signed in users (without any role) + let(:user) { create(:participant) } + let(:someuser) { create(:participant) } + let(:registration1) { create(:registration, conference: conference_public, user: user) } + let(:registration2) { create(:registration, conference: conference_not_public, user: someuser) } - it{ should_not be_able_to(:manage, Event.new) } - it{ should be_able_to(:create, Event.new) } - it{ should be_able_to(:read, Event.new) } + it{ should be_able_to(:create, Event) } # Can create a new proposal + it{ should be_able_to(:index, Event) } # Can access proposal index page + it{ should_not be_able_to(:manage, Event.new) } # Cannot manage events that are not theirs + it{ should be_able_to(:show, event_confirmed) } # Can only view confirmed events + it{ should_not be_able_to(:show, someevent) } + + # Can register for a conference + it{ should be_able_to(:register, registration1) } + it{ should be_able_to(:update, registration1) } + it{ should be_able_to(:unregister, registration1) } + # Cannot change the registration of other people + it{ should_not be_able_to(:register, registration2) } + it{ should_not be_able_to(:update, registration2) } + it{ should_not be_able_to(:unregister, registration2) } + + # Can see the conference splash page only if conference is public + it{ should be_able_to(:show, conference_public)} + it{ should_not be_able_to(:show, conference_not_public)} + + # Cannot manage a conference + it{ should_not be_able_to(:manage, conference_public) } end - context "when is an event owner" do + context '#is_admin?' do + let(:user) { create(:admin) } + + it{ should be_able_to(:manage, User) } + end + + context 'signed in users can manage their events' do let(:user) { create(:participant) } let(:user2) { create(:participant) } let(:myevent) { create(:event, users: [user]) } @@ -29,11 +70,47 @@ describe "User" do # Users are able to update and destroy their own events it{ should be_able_to(:update, myevent) } it{ should be_able_to(:destroy, myevent) } + it{ should be_able_to(:manage, myevent) } # Users are not able to update and destroy other users events it{ should_not be_able_to(:update, someevent) } it{ should_not be_able_to(:destroy, someevent) } end + context 'when is an organizer' do + let!(:conference1) { create(:conference) } + let!(:conference2) { create(:conference) } + let(:role) { create(:role, name: 'organizer', resource: conference1) } + let(:user) { create(:user, role_ids: role.id) } + let(:someuser) { create(:user) } + let(:registration1) { create(:registration, user: someuser, conference_id: conference1.id) } + + it{ should be_able_to(:manage, conference1) } + it{ should_not be_able_to(:manage, conference2) } + it{ should be_able_to(:manage, registration1) } + it{ should be_able_to(:create, Registration) } + end + + context 'when is part of cfp' do + let!(:conference1) { create(:conference) } + let!(:conference2) { create(:conference) } + let(:role) { create(:role, name: 'cfp', resource: conference1) } + let(:user) { create(:user, role_ids: role.id) } + let(:event) { create(:event, conference_id: conference1.id) } + let(:someevent) { create(:event, conference_id: conference2.id) } + let(:cfp) { create(:call_for_papers, conference: conference1) } + + it{ should_not be_able_to(:manage, conference1) } + it{ should_not be_able_to(:manage, conference2) } + it{ should be_able_to(:index, conference1) } + it{ should be_able_to(:show, conference1) } + + it{ should be_able_to(:manage, event) } + it{ should_not be_able_to(:manage, someevent) } + + it{ should be_able_to(:manage, cfp) } + it{ should be_able_to(:manage, create(:event_type, conference: conference1)) } +# it{ should_not be_able_to(:create, Registration) } + end end end diff --git a/spec/models/campaign_spec.rb b/spec/models/campaign_spec.rb index e836d3ba..c1ae1049 100644 --- a/spec/models/campaign_spec.rb +++ b/spec/models/campaign_spec.rb @@ -15,7 +15,8 @@ describe Campaign do describe '#url_parameters' do it 'returns the parameters in the correct format' do campaign = create(:campaign, utm_source: 'google+', utm_medium: 'advertisement', - utm_term: 'opensource', utm_content: 'content', utm_campaign: '20percent') + utm_term: 'opensource', utm_content: 'content', + utm_campaign: '20percent') campaign.conference = create(:conference) result = '?utm_source=google+&utm_medium=advertisement&utm_term=opensource&utm_content=content&utm_campaign=20percent' @@ -32,17 +33,19 @@ describe Campaign do describe '#visits' do it 'returns one if there is one visit' do campaign = create(:campaign, utm_source: 'google+', utm_medium: 'advertisement', - utm_term: 'opensource', utm_content: 'content', utm_campaign: '20percent') + utm_term: 'opensource', utm_content: 'content', + utm_campaign: '20percent') campaign.conference = build(:conference) - create(:visit, utm_source: 'google+', utm_medium: 'advertisement', - utm_term: 'opensource', utm_content: 'content', utm_campaign: '20percent', started_at: Time.now) + create(:visit, utm_source: 'google+', utm_medium: 'advertisement', utm_term: 'opensource', + utm_content: 'content', utm_campaign: '20percent', started_at: Time.now) expect(campaign.visits_count).to eq(1) end it 'returns zero if there are no visits' do campaign = create(:campaign, utm_source: 'google+', utm_medium: 'advertisement', - utm_term: 'opensource', utm_content: 'content', utm_campaign: '20percent') + utm_term: 'opensource', utm_content: 'content', + utm_campaign: '20percent') campaign.conference = create(:conference) expect(campaign.visits_count).to eq(0) @@ -52,7 +55,8 @@ describe Campaign do describe '#registrations' do it 'returns zero if there are no registration' do campaign = build(:campaign, utm_source: 'google+', utm_medium: 'advertisement', - utm_term: 'opensource', utm_content: 'content', utm_campaign: '20percent') + utm_term: 'opensource', utm_content: 'content', + utm_campaign: '20percent') campaign.conference = build(:conference) expect(campaign.registrations_count).to eq(0) @@ -62,7 +66,8 @@ describe Campaign do describe '#submissions' do it 'returns zero if there are no submissions' do campaign = build(:campaign, utm_source: 'google+', utm_medium: 'advertisement', - utm_term: 'opensource', utm_content: 'content', utm_campaign: '20percent') + utm_term: 'opensource', utm_content: 'content', + utm_campaign: '20percent') campaign.conference = build(:conference) expect(campaign.submissions_count).to eq(0) diff --git a/spec/models/conference_spec.rb b/spec/models/conference_spec.rb index 885ba09c..325c70d8 100644 --- a/spec/models/conference_spec.rb +++ b/spec/models/conference_spec.rb @@ -274,9 +274,8 @@ describe Conference do describe '#get_top_submitter' do # It is necessary to use bang version of let to build roles before user - let!(:organizer_role) { create(:organizer_role) } let!(:participant_role) { create(:participant_role) } - let!(:admin_role) { create(:admin_role) } + let!(:organizer_role) { create(:organizer_role) } it 'calculates correct hash with top submitters' do event = create(:event, conference: subject) @@ -307,7 +306,7 @@ describe Conference do target = build(:target, target_count: 10, unit: Target.units[:registrations]) subject.targets = [target] result = { - "10 Registrations by #{target.due_date}" => '0' + "10 Registrations by #{target.due_date}" => '0' } expect(subject.get_targets(Target.units[:registrations])).to eq(result) end @@ -317,7 +316,7 @@ describe Conference do subject.targets = [target] subject.registrations = [create(:registration)] result = { - "10 Registrations by #{target.due_date}" => '10' + "10 Registrations by #{target.due_date}" => '10' } expect(subject.get_targets(Target.units[:registrations])).to eq(result) end @@ -330,7 +329,7 @@ describe Conference do target = build(:target, target_count: 10, unit: Target.units[:submissions]) subject.targets = [target] result = { - "10 Submissions by #{target.due_date}" => '0' + "10 Submissions by #{target.due_date}" => '0' } expect(subject.get_targets(Target.units[:submissions])).to eq(result) end @@ -340,7 +339,7 @@ describe Conference do subject.targets = [target] subject.events = [create(:event)] result = { - "10 Submissions by #{target.due_date}" => '10' + "10 Submissions by #{target.due_date}" => '10' } expect(subject.get_targets(Target.units[:submissions])).to eq(result) end @@ -349,7 +348,7 @@ describe Conference do target = build(:target, target_count: 300, unit: Target.units[:program_minutes]) subject.targets = [target] result = { - "300 Program minutes by #{target.due_date}" => '0' + "300 Program minutes by #{target.due_date}" => '0' } expect(subject.get_targets(Target.units[:program_minutes])).to eq(result) end @@ -359,7 +358,7 @@ describe Conference do subject.targets = [target] subject.events = [create(:event)] result = { - "300 Program minutes by #{target.due_date}" => '10' + "300 Program minutes by #{target.due_date}" => '10' } expect(subject.get_targets(Target.units[:program_minutes])).to eq(result) end @@ -897,9 +896,8 @@ describe Conference do describe 'self#event_distribution' do # It is necessary to use bang version of let to build roles before user - let!(:organizer_role) { create(:organizer_role) } let!(:participant_role) { create(:participant_role) } - let!(:admin_role) { create(:admin_role) } + let!(:organizer_role) { create(:organizer_role) } it 'self#event_distribution calculates correct values with user' do create(:user, last_sign_in_at: Date.today - 3.months) # active @@ -1426,9 +1424,8 @@ describe Conference do describe '#user_registered?' do # It is necessary to use bang version of let to build roles before user - let!(:organizer_role) { create(:organizer_role) } let!(:participant_role) { create(:participant_role) } - let!(:admin_role) { create(:admin_role) } + let!(:organizer_role) { create(:organizer_role) } let(:user) { create(:user) } diff --git a/spec/models/user_spec.rb b/spec/models/user_spec.rb index ffbcb1c4..103d5d8f 100644 --- a/spec/models/user_spec.rb +++ b/spec/models/user_spec.rb @@ -3,53 +3,49 @@ require 'spec_helper' describe User do # It is necessary to use bang version of let to build roles before user - let!(:organizer_role) { create(:organizer_role) } let!(:participant_role) { create(:participant_role) } - let!(:admin_role) { create(:admin_role) } - let!(:admin) { create(:user) } + let!(:organizer_conference_1_role ) { create(:organizer_conference_1_role ) } + let!(:organizer) { create(:organizer_conference_1 ) } it 'returns the correct role' do participant = create(:user, email: 'participant@example.de') - expect(admin.roles.first).to eq(admin_role) - expect(participant.roles.first).to eq(participant_role) + expect(organizer.roles.first).to eq(organizer_conference_1_role) + expect(participant.roles.first).to eq(organizer_conference_1_role) end it 'returns the correct roles' do - roles = [organizer_role.id, participant_role.id, admin_role.id] + roles = [participant_role.id, organizer_conference_1_role.id] user_with_all_roles = create(:user, email: 'participant@example.de') user_with_all_roles.role_ids = roles user_with_all_roles.save - expect(user_with_all_roles.roles.length).to eq(3) + expect(user_with_all_roles.roles.length).to eq(2) expect(user_with_all_roles.roles[0]).to eq(participant_role) - expect(user_with_all_roles.roles[1]).to eq(organizer_role) - expect(user_with_all_roles.roles[2]).to eq(admin_role) + expect(user_with_all_roles.roles[1]).to eq(organizer_conference_1_role ) end describe '#role?' do shared_examples '#role?' do |user, role, expected| it "returns #{expected} for #{role}" do user_obj = create(user, email: 'e@example.com') - expect(user_obj.role?(role)).to be expected - expect(user_obj.role?(role.downcase)).to be expected - expect(user_obj.role?(role.upcase)).to be expected - expect(user_obj.role?(role.downcase.capitalize)).to be expected + expect(user_obj.has_role?(role)).to be expected + expect(user_obj.has_role?(role.downcase)).to be expected + expect(user_obj.has_role?(role.upcase)).to be expected + expect(user_obj.has_role?(role.downcase.capitalize)).to be expected end end - context 'admin' do - it_behaves_like '#role?', :admin, 'orgAnizer', false - it_behaves_like '#role?', :admin, 'adMin', true - it_behaves_like '#role?', :admin, 'partiCipant', false + context 'organizer' do + it_behaves_like '#role?', :organizer_conference_1_role, 'oRganIzeR', true + it_behaves_like '#role?', :organizer_conference_1_role, 'partiCipant', false - it 'assigns first user admin role' do - expect(admin.role?('Admin')).to be true - expect(admin.role_ids).to match_array([admin_role.id]) + it 'assigns first user organizer role' do + expect(organizer.has_role?('organizer', Conference.first)).to be true + expect(organizer.role_ids).to match_array([organizer_conference_1_role.id]) end end context 'participant' do - it_behaves_like '#role?', :participant, 'orgAnizer', false it_behaves_like '#role?', :participant, 'adMin', false it_behaves_like '#role?', :participant, 'partiCipant', true @@ -58,11 +54,5 @@ describe User do expect(participant.role_ids).to match_array([participant_role.id]) end end - - context 'organizer' do - it_behaves_like '#role?', :organizer, 'orgAnizer', true - it_behaves_like '#role?', :organizer, 'adMin', false - it_behaves_like '#role?', :organizer, 'partiCipant', false - end end end diff --git a/spec/support/database_cleaner.rb b/spec/support/database_cleaner.rb index 4fb7551f..e0dbc9aa 100644 --- a/spec/support/database_cleaner.rb +++ b/spec/support/database_cleaner.rb @@ -6,7 +6,7 @@ RSpec.configure do |config| config.before(:each) do DatabaseCleaner.strategy = :transaction end - + config.before(:each, js: true) do DatabaseCleaner.strategy = :truncation end diff --git a/spec/support/sidebar.rb b/spec/support/sidebar.rb index 4c730a97..cfa0285e 100644 --- a/spec/support/sidebar.rb +++ b/spec/support/sidebar.rb @@ -2,7 +2,7 @@ module Sidebar def sidebar @conference = create(:conference) assign :conference, @conference - render + render expect(view).to render_template('admin/conference/_sidebar') end end diff --git a/spec/views/admin/conference/edit.html.haml_spec.rb b/spec/views/admin/conference/edit.html.haml_spec.rb index d9b20a42..42e213bb 100644 --- a/spec/views/admin/conference/edit.html.haml_spec.rb +++ b/spec/views/admin/conference/edit.html.haml_spec.rb @@ -3,10 +3,10 @@ require 'spec_helper' describe 'admin/conference/edit' do it 'renders conference details which are editable' do - @conference = create(:conference, title: 'OpenSUSE') + @conference = create(:conference, title: 'openSUSE') assign :conference, @conference render template: 'admin/conference/edit.html.haml' - expect(rendered).to include('OpenSUSE') + expect(rendered).to include('openSUSE') expect(rendered).to include("#{@conference.contact_email}") end end diff --git a/spec/views/admin/conference/index.html.haml_spec.rb b/spec/views/admin/conference/index.html.haml_spec.rb index 0d237a7c..99280fd0 100644 --- a/spec/views/admin/conference/index.html.haml_spec.rb +++ b/spec/views/admin/conference/index.html.haml_spec.rb @@ -2,9 +2,9 @@ require 'spec_helper' describe 'admin/conference/index' do it 'renders all conference names with links' do - assign(:conferences, [create(:conference, title: 'OpenSUSE'), create(:conference)]) + assign(:conferences, [create(:conference, title: 'openSUSE'), create(:conference)]) render - expect(rendered).to include('OpenSUSE') - expect(rendered).to include("The dog and pony show") + expect(rendered).to include('openSUSE') + expect(rendered).to include('The dog and pony show') end end diff --git a/spec/views/admin/conference/show.html.haml_spec.rb b/spec/views/admin/conference/show.html.haml_spec.rb index fa747370..383af195 100644 --- a/spec/views/admin/conference/show.html.haml_spec.rb +++ b/spec/views/admin/conference/show.html.haml_spec.rb @@ -3,7 +3,7 @@ require 'spec_helper' describe 'admin/conference/show' do it 'renders conference dashboard' do - conference = create(:conference, title: 'OpenSUSE') + conference = create(:conference, title: 'openSUSE') assign :conference, conference assign :conference_progress, conference.get_status render diff --git a/spec/views/admin/eventtypes/index.html.haml_spec.rb b/spec/views/admin/event_types/index.html.haml_spec.rb similarity index 89% rename from spec/views/admin/eventtypes/index.html.haml_spec.rb rename to spec/views/admin/event_types/index.html.haml_spec.rb index 095ebf93..661f7156 100644 --- a/spec/views/admin/eventtypes/index.html.haml_spec.rb +++ b/spec/views/admin/event_types/index.html.haml_spec.rb @@ -1,6 +1,6 @@ require 'spec_helper' -describe 'admin/eventtypes/index' do +describe 'admin/event_types/index' do it 'renders event types' do @event_type = create(:event_type) diff --git a/spec/views/admin/social_events/index.html.haml_spec.rb b/spec/views/admin/social_events/index.html.haml_spec.rb index 650828a2..a95ec30e 100644 --- a/spec/views/admin/social_events/index.html.haml_spec.rb +++ b/spec/views/admin/social_events/index.html.haml_spec.rb @@ -2,7 +2,7 @@ require 'spec_helper' describe 'admin/social_events/index' do - it 'renders social events' do + it 'renders social events' do @social_event = create(:social_event) assign :conference, @social_event.conference render diff --git a/spec/views/admin/volunteers/show.html.haml_spec.rb b/spec/views/admin/volunteers/show.html.haml_spec.rb index 25646308..b322f996 100644 --- a/spec/views/admin/volunteers/show.html.haml_spec.rb +++ b/spec/views/admin/volunteers/show.html.haml_spec.rb @@ -1,5 +1,5 @@ require 'spec_helper' -describe "admin/volunteers/show" do +describe 'admin/volunteers/show' do pending "add some examples to (or delete) #{__FILE__}" end diff --git a/spec/views/conference/show.html.haml_spec.rb b/spec/views/conference/show.html.haml_spec.rb index 28bab522..951ac1cc 100644 --- a/spec/views/conference/show.html.haml_spec.rb +++ b/spec/views/conference/show.html.haml_spec.rb @@ -10,8 +10,8 @@ describe 'conference/show.html.haml' do sponsor_email: 'example@example.com', facebook_url: 'http://www.fbexample.com', google_url: 'http://www.google-example.com', - instagram_url: "http://instagram.com", - twitter_url: "http://twitter.com", + instagram_url: 'http://instagram.com', + twitter_url: 'http://twitter.com', include_registrations_in_splash: true, include_program_in_splash: true, include_sponsors_in_splash: true, @@ -65,8 +65,8 @@ describe 'conference/show.html.haml' do expect(view).to render_template('conference/_social_media') expect(view.content_for(:splash)).to include('http://www.fbexample.com') expect(view.content_for(:splash)).to include('http://www.google-example.com') - expect(view.content_for(:splash)).to include("http://instagram.com") - expect(view.content_for(:splash)).to include("http://twitter.com") + expect(view.content_for(:splash)).to include('http://instagram.com') + expect(view.content_for(:splash)).to include('http://twitter.com') end it 'renders location partial' do