diff --git a/app/controllers/admin/callforpapers_controller.rb b/app/controllers/admin/callforpapers_controller.rb index b97bebb0..c18e6018 100644 --- a/app/controllers/admin/callforpapers_controller.rb +++ b/app/controllers/admin/callforpapers_controller.rb @@ -1,52 +1,55 @@ -class Admin::CallforpapersController < ApplicationController - before_filter :verify_organizer +module Admin + class CallforpapersController < ApplicationController + load_and_authorize_resource :conference, find_by: :short_title +# load_and_authorize_resource :call_for_paper, class: 'CallForPapers', through: :conference - def show - @cfp = @conference.call_for_papers - if @cfp.nil? - @cfp = CallForPapers.new + def show + @cfp = @conference.call_for_papers + if @cfp.nil? + @cfp = CallForPapers.new + end end - end - def update - @cfp = @conference.call_for_papers - @cfp.assign_attributes(params[:call_for_papers]) - notify_on_schedule_public = @cfp.schedule_public_changed? && @cfp.schedule_public\ - && @conference.email_settings.send_on_call_for_papers_schedule_public\ - && !@conference.email_settings.call_for_papers_schedule_public_subject.blank?\ - && !@conference.email_settings.call_for_papers_schedule_public_template.blank? + def update + @cfp = @conference.call_for_papers + @cfp.assign_attributes(params[:call_for_papers]) + notify_on_schedule_public = @cfp.schedule_public_changed? && @cfp.schedule_public\ + && @conference.email_settings.send_on_call_for_papers_schedule_public\ + && !@conference.email_settings.call_for_papers_schedule_public_subject.blank?\ + && !@conference.email_settings.call_for_papers_schedule_public_template.blank? - notify_on_cfp_date_update = !@cfp.end_date.blank? && !@cfp.start_date.blank?\ - && (@cfp.start_date_changed? || @cfp.end_date_changed?)\ - && @conference.email_settings.send_on_call_for_papers_dates_updates\ - && !@conference.email_settings.call_for_papers_dates_updates_subject.blank?\ - && !@conference.email_settings.call_for_papers_dates_updates_template.blank? + notify_on_cfp_date_update = !@cfp.end_date.blank? && !@cfp.start_date.blank?\ + && (@cfp.start_date_changed? || @cfp.end_date_changed?)\ + && @conference.email_settings.send_on_call_for_papers_dates_updates\ + && !@conference.email_settings.call_for_papers_dates_updates_subject.blank?\ + && !@conference.email_settings.call_for_papers_dates_updates_template.blank? - if @cfp.update_attributes(params[:call_for_papers]) - Mailbot.delay.send_on_call_for_papers_dates_updates(@conference) if notify_on_cfp_date_update - Mailbot.delay.send_on_schedule_public(@conference) if notify_on_schedule_public - redirect_to(admin_conference_callforpapers_path( - id: @conference.short_title), - notice: 'Call for Papers was successfully updated.') - else - redirect_to(admin_conference_callforpapers_path( - id: @conference.short_title), - alert: "Updating call for papers failed. #{@cfp.errors.to_a.join(". ")}.") + if @cfp.update_attributes(params[:call_for_papers]) + Mailbot.delay.send_on_call_for_papers_dates_updates(@conference) if notify_on_cfp_date_update + Mailbot.delay.send_on_schedule_public(@conference) if notify_on_schedule_public + redirect_to(admin_conference_callforpapers_path( + id: @conference.short_title), + notice: 'Call for Papers was successfully updated.') + else + redirect_to(admin_conference_callforpapers_path( + id: @conference.short_title), + alert: "Updating call for papers failed. #{@cfp.errors.to_a.join(". ")}.") + end end - end - def create - @cfp = CallForPapers.new(params[:call_for_papers]) - if @cfp.valid? - @cfp.save - @conference.call_for_papers = @cfp - redirect_to(admin_conference_callforpapers_path( - id: @conference.short_title), - notice: 'Call for Papers was successfully created.') - else - redirect_to(admin_conference_callforpapers_path( - id: @conference.short_title), - alert: "Creating the call for papers failed. #{@cfp.errors.to_a.join(". ")}.") + def create + @cfp = CallForPapers.new(params[:call_for_papers]) + if @cfp.valid? + @cfp.save + @conference.call_for_papers = @cfp + redirect_to(admin_conference_callforpapers_path( + id: @conference.short_title), + notice: 'Call for Papers was successfully created.') + else + redirect_to(admin_conference_callforpapers_path( + id: @conference.short_title), + alert: "Creating the call for papers failed. #{@cfp.errors.to_a.join(". ")}.") + end end end end diff --git a/app/controllers/admin/campaigns_controller.rb b/app/controllers/admin/campaigns_controller.rb index 68c4521d..a51ee16e 100644 --- a/app/controllers/admin/campaigns_controller.rb +++ b/app/controllers/admin/campaigns_controller.rb @@ -1,6 +1,7 @@ module Admin class CampaignsController < ApplicationController - before_filter :verify_organizer + load_and_authorize_resource :conference, find_by: :short_title + load_and_authorize_resource :campaign, through: :conference def index @conference = Conference.find_by(short_title: params[:conference_id]) diff --git a/app/controllers/admin/conference_controller.rb b/app/controllers/admin/conference_controller.rb index 7b1867e5..25e04343 100644 --- a/app/controllers/admin/conference_controller.rb +++ b/app/controllers/admin/conference_controller.rb @@ -1,133 +1,136 @@ -class Admin::ConferenceController < ApplicationController - before_filter :verify_organizer +module Admin + class ConferenceController < ApplicationController + load_and_authorize_resource :conference, find_by: :short_title - def index - # Redirect to new form if there is no conference - if Conference.count == 0 - redirect_to new_admin_conference_path - return + def index + # Redirect to new form if there is no conference + if Conference.count == 0 + redirect_to new_admin_conference_path + return + end + + @total_user = User.count + @new_user = User.where('created_at > ?', current_user.last_sign_in_at).count + + @total_reg = Registration.count + @new_reg = Registration.where('created_at > ?', current_user.last_sign_in_at).count + + @total_submissions = Event.count + @new_submissions = Event.where('created_at > ?', current_user.last_sign_in_at).count + + @active_conferences = Conference.get_active_conferences_for_dashboard # pending or the last two + @deactive_conferences = Conference. + get_conferences_without_active_for_dashboard(@active_conferences) # conferences without active + @conferences = @active_conferences + @deactive_conferences + + @recent_users = User.limit(5).order(created_at: :desc) + @recent_events = Event.limit(5).order(created_at: :desc) + @recent_registrations = Registration.limit(5).order(created_at: :desc) + + @top_submitter = Conference.get_top_submitter + + @submissions = {} + @cfp_weeks = [0] + + @registrations = {} + @registration_weeks = [0] + + @conferences.each do |c| + # Event submissions over time chart + @submissions[c.short_title] = c.get_submissions_per_week + @cfp_weeks.push(@submissions[c.short_title].length) + + # Conference registrations over time chart + @registrations[c.short_title] = c.get_registrations_per_week + @registration_weeks.push(@registrations[c.short_title].length) + end + + @cfp_weeks = @cfp_weeks.max + @submissions = normalize_array_length(@submissions, @cfp_weeks) + @cfp_weeks = @cfp_weeks > 0 ? (1..@cfp_weeks).to_a : 1 + + @registration_weeks = @registration_weeks.max + @registrations = normalize_array_length(@registrations, @registration_weeks) + @registration_weeks = @registration_weeks > 0 ? (1..@registration_weeks).to_a : 1 + + @event_distribution = Conference.event_distribution + @user_distribution = Conference.user_distribution end - @total_user = User.count - @new_user = User.where('created_at > ?', current_user.last_sign_in_at).count - - @total_reg = Registration.count - @new_reg = Registration.where('created_at > ?', current_user.last_sign_in_at).count - - @total_submissions = Event.count - @new_submissions = Event.where('created_at > ?', current_user.last_sign_in_at).count - - @active_conferences = Conference.get_active_conferences_for_dashboard # pending or the last two - @deactive_conferences = Conference. - get_conferences_without_active_for_dashboard(@active_conferences) # conferences without active - @conferences = @active_conferences + @deactive_conferences - - @recent_users = User.limit(5).order(created_at: :desc) - @recent_events = Event.limit(5).order(created_at: :desc) - @recent_registrations = Registration.limit(5).order(created_at: :desc) - - @top_submitter = Conference.get_top_submitter - - @submissions = {} - @cfp_weeks = [0] - - @registrations = {} - @registration_weeks = [0] - - @conferences.each do |c| - # Event submissions over time chart - @submissions[c.short_title] = c.get_submissions_per_week - @cfp_weeks.push(@submissions[c.short_title].length) - - # Conference registrations over time chart - @registrations[c.short_title] = c.get_registrations_per_week - @registration_weeks.push(@registrations[c.short_title].length) + def new + @conference = Conference.new end - @cfp_weeks = @cfp_weeks.max - @submissions = normalize_array_length(@submissions, @cfp_weeks) - @cfp_weeks = @cfp_weeks > 0 ? (1..@cfp_weeks).to_a : 1 + def create + @conference = Conference.new(params[:conference]) - @registration_weeks = @registration_weeks.max - @registrations = normalize_array_length(@registrations, @registration_weeks) - @registration_weeks = @registration_weeks > 0 ? (1..@registration_weeks).to_a : 1 - - @event_distribution = Conference.event_distribution - @user_distribution = Conference.user_distribution - end - - def new - @conference = Conference.new - end - - def create - @conference = Conference.new(params[:conference]) - if @conference.valid? - @conference.save - redirect_to(admin_conference_path(id: @conference.short_title), - notice: 'Conference was successfully created.') - else - render action: 'new' - end - end - - def update - @conference = Conference.find_by(short_title: params[:id]) - short_title = @conference.short_title - @conference.assign_attributes(params[:conference]) - if @conference.start_date_changed? || @conference.end_date_changed? - if @conference.email_settings.send_on_updated_conference_dates && - !@conference.email_settings.updated_conference_dates_subject.blank? && - @conference.email_settings.updated_conference_dates_template - Mailbot.conference_date_update_mail(@conference).deliver + if @conference.valid? + @conference.save + # user that creates the conference becomes organizer of that conference + current_user.add_role :organizer, @conference + redirect_to(admin_conference_path(id: @conference.short_title), + notice: 'Conference was successfully created.') + else + render action: 'new' end end - if @conference.registration_start_date_changed? || @conference.registration_end_date_changed? - if @conference.email_settings.send_on_updated_conference_registration_dates && - !@conference.email_settings.updated_conference_registration_dates_subject.blank? && - @conference.email_settings.updated_conference_registration_dates_template - Mailbot.conference_registration_date_update_mail(@conference).deliver + def update + short_title = @conference.short_title + @conference.assign_attributes(params[:conference]) + if @conference.start_date_changed? || @conference.end_date_changed? + if @conference.email_settings.send_on_updated_conference_dates && + !@conference.email_settings.updated_conference_dates_subject.blank? && + @conference.email_settings.updated_conference_dates_template + Mailbot.conference_date_update_mail(@conference).deliver + end + end + + if @conference.registration_start_date_changed? || @conference.registration_end_date_changed? + if @conference.email_settings.send_on_updated_conference_registration_dates && + !@conference.email_settings.updated_conference_registration_dates_subject.blank? && + @conference.email_settings.updated_conference_registration_dates_template + Mailbot.conference_registration_date_update_mail(@conference).deliver + end + + if @conference.update_attributes(params[:conference]) + redirect_to(edit_admin_conference_path(id: @conference.short_title), + notice: 'Conference was successfully updated.') + else + redirect_to(edit_admin_conference_path(id: short_title), + alert: 'Updating conference failed. ' \ + "#{@conference.errors.full_messages.join('. ')}.") + end end end - if @conference.update_attributes(params[:conference]) - redirect_to(edit_admin_conference_path(id: @conference.short_title), - notice: 'Conference was successfully updated.') - else - redirect_to(edit_admin_conference_path(id: short_title), - alert: 'Updating conference failed. ' \ - "#{@conference.errors.full_messages.join('. ')}.") - end - end + def show + @conference = Conference.find_by(short_title: params[:id]) - def show - @conference = Conference.find_by(short_title: params[:id]) + # Overview and since last login information + @total_reg = @conference.registrations.count + @new_reg = @conference.registrations.where('created_at > ?', current_user.last_sign_in_at).count - # Overview and since last login information - @total_reg = @conference.registrations.count - @new_reg = @conference.registrations.where('created_at > ?', current_user.last_sign_in_at).count + @total_submissions = @conference.events.count + @new_submissions = @conference.events. + where('created_at > ?', current_user.last_sign_in_at).count - @total_submissions = @conference.events.count - @new_submissions = @conference.events. - where('created_at > ?', current_user.last_sign_in_at).count + @program_length = @conference.current_program_hours + @new_program_length = @conference.new_program_hours(current_user.last_sign_in_at) - @program_length = @conference.current_program_hours - @new_program_length = @conference.new_program_hours(current_user.last_sign_in_at) + # Step by step list + @conference_progress = @conference.get_status - # Step by step list - @conference_progress = @conference.get_status + # Line charts + @registrations = { @conference.short_title => @conference.get_registrations_per_week } + @registration_weeks = [0] + @registration_weeks.push(@registrations[@conference.short_title].length) - # Line charts - @registrations = { @conference.short_title => @conference.get_registrations_per_week } - @registration_weeks = [0] - @registration_weeks.push(@registrations[@conference.short_title].length) + @registration_weeks = @registration_weeks.max + @registrations = normalize_array_length(@registrations, @registration_weeks) + @registration_weeks = @registration_weeks > 0 ? (1..@registration_weeks).to_a : 1 - @registration_weeks = @registration_weeks.max - @registrations = normalize_array_length(@registrations, @registration_weeks) - @registration_weeks = @registration_weeks > 0 ? (1..@registration_weeks).to_a : 1 - - @submissions = Conference.get_event_state_line_colors + @submissions = Conference.get_event_state_line_colors @submissions_data = {} @submissions_data = @conference.get_submissions_data @@ -137,43 +140,44 @@ class Admin::ConferenceController < ApplicationController @submissions_data = @submissions_data.except('Weeks') end - # Doughnut charts - @event_type_distribution = @conference.event_type_distribution - @event_type_distribution_confirmed = @conference.event_type_distribution(:confirmed) + # Doughnut charts + @event_type_distribution = @conference.event_type_distribution + @event_type_distribution_confirmed = @conference.event_type_distribution(:confirmed) - @difficulty_levels_distribution = @conference.difficulty_levels_distribution - @difficulty_levels_distribution_confirmed = @conference. - difficulty_levels_distribution(:confirmed) + @difficulty_levels_distribution = @conference.difficulty_levels_distribution + @difficulty_levels_distribution_confirmed = @conference. + difficulty_levels_distribution(:confirmed) - @tracks_distribution = @conference.tracks_distribution - @tracks_distribution_confirmed = @conference.tracks_distribution(:confirmed) + @tracks_distribution = @conference.tracks_distribution + @tracks_distribution_confirmed = @conference.tracks_distribution(:confirmed) - # Recent actions information - @recent_events = @conference.events.limit(5).order(created_at: :desc) - @recent_registrations = @conference.registrations.limit(5).order(created_at: :desc) + # Recent actions information + @recent_events = @conference.events.limit(5).order(created_at: :desc) + @recent_registrations = @conference.registrations.limit(5).order(created_at: :desc) - @top_submitter = @conference.get_top_submitter + @top_submitter = @conference.get_top_submitter - # get targets - @registration_targets = @conference.get_targets(Target.units[:registrations]) - @submission_targets = @conference.get_targets(Target.units[:submissions]) - @program_minutes_targets = @conference.get_targets(Target.units[:program_minutes]) + # get targets + @registration_targets = @conference.get_targets(Target.units[:registrations]) + @submission_targets = @conference.get_targets(Target.units[:submissions]) + @program_minutes_targets = @conference.get_targets(Target.units[:program_minutes]) - # get campaigns - @campaigns = @conference.get_campaigns + # get campaigns + @campaigns = @conference.get_campaigns - respond_to do |format| - format.html - format.json { render json: @conference.to_json } + respond_to do |format| + format.html + format.json { render json: @conference.to_json } + end end - end - def edit - @conferences = Conference.all - @conference = Conference.find_by(short_title: params[:id]) - respond_to do |format| - format.html - format.json { render json: @conference.to_json } + def edit + @conferences = Conference.all + @conference = Conference.find_by(short_title: params[:id]) + respond_to do |format| + format.html + format.json { render json: @conference.to_json } + end end end end diff --git a/app/controllers/admin/dietchoices_controller.rb b/app/controllers/admin/dietchoices_controller.rb index cf315a40..bf1ffdf5 100644 --- a/app/controllers/admin/dietchoices_controller.rb +++ b/app/controllers/admin/dietchoices_controller.rb @@ -1,16 +1,19 @@ -class Admin::DietchoicesController < ApplicationController - before_filter :verify_organizer +module Admin + class DietchoicesController < ApplicationController + load_and_authorize_resource :conference, find_by: :short_title + load_and_authorize_resource :dietary_choice, through: :conference - def show - render :diets_list - end + def show + render :diets_list + end - def update - begin - @conference.update_attributes!(params[:conference]) - redirect_to(admin_conference_dietary_list_path(conference_id: @conference.short_title), notice: 'Dietary choices were successfully updated.') - rescue => e - redirect_to(admin_conference_dietary_list_path(conference_id: @conference.short_title), alert: "Dietary choices update failed: #{e.message}") + def update + begin + @conference.update_attributes!(params[:conference]) + redirect_to(admin_conference_dietary_list_path(conference_id: @conference.short_title), notice: 'Dietary choices were successfully updated.') + rescue => e + redirect_to(admin_conference_dietary_list_path(conference_id: @conference.short_title), alert: "Dietary choices update failed: #{e.message}") + end end end end diff --git a/app/controllers/admin/difficulty_levels_controller.rb b/app/controllers/admin/difficulty_levels_controller.rb index 51aacd7f..af652b40 100644 --- a/app/controllers/admin/difficulty_levels_controller.rb +++ b/app/controllers/admin/difficulty_levels_controller.rb @@ -1,29 +1,32 @@ -class Admin::DifficultyLevelsController < ApplicationController - before_filter :verify_organizer - - def index - @conference = Conference.find_by(short_title: params[:conference_id]) - end +module Admin + class DifficultyLevelsController < ApplicationController + load_and_authorize_resource :conference, find_by: :short_title + authorize_resource :difficulty_level, through: :conference - def update - if @conference.update_attributes(params[:conference]) - if !(@conference.difficulty_levels.count > 0) && @conference.use_difficulty_levels == true - begin - @conference.use_difficulty_levels = false - @conference.save! - flash[:error] = "You cannot enable the usage of difficulty levels without having set any levels." + def index + @conference = Conference.find_by(short_title: params[:conference_id]) + end + + def update + if @conference.update_attributes(params[:conference]) + if !(@conference.difficulty_levels.count > 0) && @conference.use_difficulty_levels == true + begin + @conference.use_difficulty_levels = false + @conference.save! + flash[:error] = "You cannot enable the usage of difficulty levels without having set any levels." + redirect_to(admin_conference_difficulty_levels_path(conference_id: @conference.short_title)) + rescue ActiveRecord::RecordInvalid + flash[:error] = "Something went wrong. Difficulty Levels update failed." + redirect_to(admin_conference_difficulty_levels_path(conference_id: @conference.short_title)) + end + else + flash[:notice] = "Difficulty Levels were successfully updated." redirect_to(admin_conference_difficulty_levels_path(conference_id: @conference.short_title)) - rescue ActiveRecord::RecordInvalid - flash[:error] = "Something went wrong. Difficulty Levels update failed." - redirect_to(admin_conference_difficulty_levels_path(conference_id: @conference.short_title)) end else - flash[:notice] = "Difficulty Levels were successfully updated." + flash[:error] = "Difficulty Levels update failed." redirect_to(admin_conference_difficulty_levels_path(conference_id: @conference.short_title)) end - else - flash[:error] = "Difficulty Levels update failed." - redirect_to(admin_conference_difficulty_levels_path(conference_id: @conference.short_title)) end end end diff --git a/app/controllers/admin/emails_controller.rb b/app/controllers/admin/emails_controller.rb index dbdfc44d..92c0b8bf 100644 --- a/app/controllers/admin/emails_controller.rb +++ b/app/controllers/admin/emails_controller.rb @@ -1,14 +1,17 @@ -class Admin::EmailsController < ApplicationController - before_filter :verify_organizer +module Admin + class EmailsController < ApplicationController + load_and_authorize_resource :conference, find_by: :short_title + load_and_authorize_resource :emails, class: EmailSettings - def update - @conference.email_settings.update_attributes(params[:email_settings]) - redirect_to(admin_conference_emails_path( - @conference.short_title), - notice: 'Settings have been successfully updated.') - end + def update + @conference.email_settings.update_attributes(params[:email_settings]) + redirect_to(admin_conference_emails_path( + @conference.short_title), + notice: 'Settings have been successfully updated.') + end - def index - @settings = @conference.email_settings + def index + @settings = @conference.email_settings + end end end diff --git a/app/controllers/admin/event_types_controller.rb b/app/controllers/admin/event_types_controller.rb index 91e629e2..e8d76491 100644 --- a/app/controllers/admin/event_types_controller.rb +++ b/app/controllers/admin/event_types_controller.rb @@ -1,7 +1,7 @@ module Admin - class EventTypesController < Admin::BaseController - authorize_resource + class EventTypesController < ApplicationController load_and_authorize_resource :conference, find_by: :short_title + authorize_resource :event_type, through: :conference def show render :eventtypes diff --git a/app/controllers/admin/events_controller.rb b/app/controllers/admin/events_controller.rb index 99dbfbc2..a5085883 100644 --- a/app/controllers/admin/events_controller.rb +++ b/app/controllers/admin/events_controller.rb @@ -1,6 +1,7 @@ module Admin class EventsController < ApplicationController - before_filter :verify_organizer + load_and_authorize_resource :conference, find_by: :short_title + load_and_authorize_resource :event, through: :conference before_action :get_event, except: [:index, :create] @@ -13,6 +14,7 @@ module Admin end def index + @conference = Conference.find_by(short_title: params[:conference_id]) @events = @conference.events @tracks = @conference.tracks @machine_states = @events.state_machine.states.map diff --git a/app/controllers/admin/lodgings_controller.rb b/app/controllers/admin/lodgings_controller.rb index 34dfa628..35e36939 100644 --- a/app/controllers/admin/lodgings_controller.rb +++ b/app/controllers/admin/lodgings_controller.rb @@ -1,6 +1,7 @@ module Admin class LodgingsController < ApplicationController - before_filter :verify_organizer + load_and_authorize_resource :conference, find_by: :short_title + authorize_resource :lodging, through: :conference def index @venue = @conference.venue diff --git a/app/controllers/admin/questions_controller.rb b/app/controllers/admin/questions_controller.rb index 1e9e4551..101e720e 100644 --- a/app/controllers/admin/questions_controller.rb +++ b/app/controllers/admin/questions_controller.rb @@ -1,94 +1,88 @@ -class Admin::QuestionsController < ApplicationController - before_filter :verify_organizer +module Admin + class QuestionsController < ApplicationController + load_and_authorize_resource :conference, find_by: :short_title + authorize_resource :question, through: :conference - def index - @conference = Conference.find_by(short_title: params[:conference_id]) - @questions = Question.where(global: true).all | Question.where(conference_id: @conference.id) - @questions_conference = @conference.questions - @new_question = @conference.questions.new - end + def index + @questions = Question.where(global: true).all | Question.where(conference_id: @conference.id) + @questions_conference = @conference.questions + @new_question = @conference.questions.new + end - def new - @conference = Conference.find_by(short_title: params[:conference_id]) - @new_question = @conference.questions.new - end + def new + @new_question = @conference.questions.new + end - def create - @conference = Conference.find_by(short_title: params[:conference_id]) - @question = @conference.questions.new(params[:question]) - @question.conference_id = @conference.id + def create + @question = @conference.questions.new(params[:question]) + @question.conference_id = @conference.id - respond_to do |format| - if @conference.save - format.html { redirect_to admin_conference_questions_path, notice: 'Question was successfully created.' } - else - flash[:error] = "Oops, couldn't save. Question and answer(s) have titles?" - format.html { redirect_to admin_conference_questions_path } + respond_to do |format| + if @conference.save + format.html { redirect_to admin_conference_questions_path, notice: 'Question was successfully created.' } + else + flash[:error] = "Oops, couldn't save. Question and answer(s) have titles?" + format.html { redirect_to admin_conference_questions_path } + end end - end - end - - # GET questions/1/edit - def edit - @conference = Conference.find_by(short_title: params[:conference_id]) - @question = Question.find(params[:id]) - - if @question.global == true && !has_role?(current_user, "Admin") - redirect_to(admin_conference_questions_path(conference_id: @conference.short_title), alert: "Sorry, you cannot edit global questions. Create a new one.") end - end - # PUT questions/1 - def update - - @conference = Conference.find_by(short_title: params[:conference_id]) - @question = Question.find(params[:id]) + # GET questions/1/edit + def edit - if @question.update_attributes(params[:question]) - redirect_to(admin_conference_questions_path(conference_id: @conference.short_title), notice: "Question '#{@question.title}' for #{@conference.short_title} successfully updated.") - else - redirect_to(admin_conference_questions_path(conference_id: @conference.short_title), notice: "Update of questions for #{@conference.short_title} failed.") - end - end - - # Update questions used for the conference - def update_conference - @conference = Conference.find_by(short_title: params[:conference_id]) - - if @conference.update_attributes(params[:conference]) - redirect_to(admin_conference_questions_path(conference_id: @conference.short_title), notice: "Questions for #{@conference.short_title} successfully updated.") - else - redirect_to(admin_conference_questions_path(conference_id: @conference.short_title), notice: "Update of questions for #{@conference.short_title} failed.") - end - end - - # DELETE questions/1 - def destroy - if has_role?(current_user, "Admin") @question = Question.find(params[:id]) - # Do not delete global questions - if @question.global == false + if @question.global == true && !(current_user.has_role? :organizer, @conference) + redirect_to(admin_conference_questions_path(conference_id: @conference.short_title), alert: "Sorry, you cannot edit global questions. Create a new one.") + end + end - # Delete question and its answers - begin - Question.transaction do + # PUT questions/1 + def update + @question = Question.find(params[:id]) - @question.delete - @question.answers.each do |a| - a.delete - end - flash[:notice] = "Deleted question: #{@question.title} and its answers: #{@question.answers.map {|a| a.title}.join ','}" + if @conference.update_attributes(params[:conference]) + redirect_to(admin_conference_questions_path(conference_id: @conference.short_title), notice: "Questions for #{@conference.short_title} successfully updated.") + else + redirect_to(admin_conference_questions_path(conference_id: @conference.short_title), notice: "Update of questions for #{@conference.short_title} failed.") + end + end + + # Update questions used for the conference + def update_conference + if @conference.update_attributes(params[:conference]) + redirect_to(admin_conference_questions_path(:conference_id => @conference.short_title), :notice => "Questions for #{@conference.short_title} successfully updated.") + else + redirect_to(admin_conference_questions_path(:conference_id => @conference.short_title), :notice => "Update of questions for #{@conference.short_title} failed.") + end + end + + # DELETE questions/1 + def destroy + if can? :destroy, @question + + # Do not delete global questions + if @question.global == false + + # Delete question and its answers + begin + Question.transaction do + + @question.delete + @question.answers.each do |a| + a.delete + end + flash[:notice] = "Deleted question: #{@question.title} and its answers: #{@question.answers.map {|a| a.title}.join ','}" end - rescue ActiveRecord::RecordInvalid - flash[:error] = "Could not delete question." + rescue ActiveRecord::RecordInvalid + flash[:error] = "Could not delete question." + end + else + flash[:error] = "You cannot delete global questions." end else - flash[:error] = "You cannot delete global questions." + flash[:error] = "You must be an admin to delete a question." end - else - flash[:error] = "You must be an admin to delete a question." - end @questions = Question.where(global: true).all | Question.where(conference_id: @conference.id) @questions_conference = @conference.questions diff --git a/app/controllers/admin/registrations_controller.rb b/app/controllers/admin/registrations_controller.rb index 6ebe3db0..9b67f454 100644 --- a/app/controllers/admin/registrations_controller.rb +++ b/app/controllers/admin/registrations_controller.rb @@ -1,6 +1,7 @@ module Admin class RegistrationsController < ApplicationController - before_filter :verify_organizer + load_and_authorize_resource :conference, find_by: :short_title + load_and_authorize_resource through: :conference def index session[:return_to] ||= request.referer @@ -12,7 +13,6 @@ module Admin end def change_field - @registration = Registration.find(params[:id]) field = params[:view_field] if @registration.send(field.to_sym) @registration.update_attribute(:"#{field}", 0) @@ -26,12 +26,10 @@ module Admin end def edit - @registration = @conference.registrations.where('id = ?', params[:id]).first @user = User.where('id = ?', @registration.user_id).first end def update - @registration = @conference.registrations.where('id = ?', params[:id]).first @user = User.where('id = ?', @registration.user_id).first begin @user.update_attributes!(params[:registration][:user_attributes]) @@ -55,6 +53,7 @@ module Admin def new @user = User.new @registration = @user.registrations.new + @registration.conference_id = @conference.id @supporter_registration = @conference.supporter_registrations.new end @@ -97,7 +96,7 @@ module Admin end def destroy - if has_role?(current_user, 'Admin') + if can? :destroy, @registration registration = @conference.registrations.where(id: params[:id]).first user = User.where('id = ?', registration.user_id).first diff --git a/app/controllers/admin/rooms_controller.rb b/app/controllers/admin/rooms_controller.rb index 00342258..fae3adab 100644 --- a/app/controllers/admin/rooms_controller.rb +++ b/app/controllers/admin/rooms_controller.rb @@ -1,19 +1,22 @@ -class Admin::RoomsController < ApplicationController - before_filter :verify_organizer +module Admin + class RoomsController < ApplicationController + load_and_authorize_resource :conference, find_by: :short_title + authorize_resource :room, through: :conference - def show - render :rooms_list - end + def show + render :rooms_list + end - def update - if @conference.update_attributes(params[:conference]) - redirect_to(admin_conference_rooms_path( - conference_id: @conference.short_title), - notice: 'Rooms were successfully updated.') - else - redirect_to(admin_conference_rooms_path( - conference_id: @conference.short_title), - notice: 'Room update failed.') + def update + if @conference.update_attributes(params[:conference]) + redirect_to(admin_conference_rooms_path( + conference_id: @conference.short_title), + notice: 'Rooms were successfully updated.') + else + redirect_to(admin_conference_rooms_path( + conference_id: @conference.short_title), + notice: 'Room update failed.') + end end end end diff --git a/app/controllers/admin/schedules_controller.rb b/app/controllers/admin/schedules_controller.rb index cd7fff2b..dfdbe676 100644 --- a/app/controllers/admin/schedules_controller.rb +++ b/app/controllers/admin/schedules_controller.rb @@ -1,6 +1,10 @@ module Admin class SchedulesController < ApplicationController - before_filter :verify_organizer + # By authorizing 'conference' resource, we can ensure there will be no unauthorized access to + # the schedule of a conference, which should not be accessed in the first place + load_and_authorize_resource :conference, find_by: :short_title + authorize_resource class: false + skip_before_filter :verify_authenticity_token, only: [:update] layout 'schedule' diff --git a/app/controllers/admin/social_events_controller.rb b/app/controllers/admin/social_events_controller.rb index b11b38f4..47bbeceb 100644 --- a/app/controllers/admin/social_events_controller.rb +++ b/app/controllers/admin/social_events_controller.rb @@ -1,15 +1,18 @@ -class Admin::SocialEventsController < ApplicationController - before_filter :verify_organizer +module Admin + class SocialEventsController < ApplicationController + load_and_authorize_resource :conference, find_by: :short_title + authorize_resource :social_event, through: :conference - def show - render :social_events_list - end + def show + render :social_events_list + end - def update - if @conference.update_attributes(params[:conference]) - redirect_to(admin_conference_social_events_path(conference_id: @conference.short_title), notice: 'Social events were successfully updated.') - else - redirect_to(admin_conference_social_events_path(conference_id: @conference.short_title), notice: 'Social events update failed.') + def update + if @conference.update_attributes(params[:conference]) + redirect_to(admin_conference_social_events_path(conference_id: @conference.short_title), notice: 'Social events were successfully updated.') + else + redirect_to(admin_conference_social_events_path(conference_id: @conference.short_title), notice: 'Social events update failed.') + end end end end diff --git a/app/controllers/admin/speakers_controller.rb b/app/controllers/admin/speakers_controller.rb index 76fd40ce..0b204037 100644 --- a/app/controllers/admin/speakers_controller.rb +++ b/app/controllers/admin/speakers_controller.rb @@ -1,6 +1,8 @@ module Admin class SpeakersController < ApplicationController - before_filter :verify_organizer + load_and_authorize_resource :conference, find_by: :short_title + load_and_authorize_resource :speaker, through: :conference + respond_to :js, :html def edit diff --git a/app/controllers/admin/sponsors_controller.rb b/app/controllers/admin/sponsors_controller.rb index d37c1cb4..7ee8d7f4 100644 --- a/app/controllers/admin/sponsors_controller.rb +++ b/app/controllers/admin/sponsors_controller.rb @@ -1,6 +1,7 @@ module Admin class SponsorsController < ApplicationController - before_filter :verify_organizer + load_and_authorize_resource :conference, find_by: :short_title + authorize_resource :sponsor, through: :conference def update if @conference.update_attributes(params[:conference]) diff --git a/app/controllers/admin/sponsorship_levels_controller.rb b/app/controllers/admin/sponsorship_levels_controller.rb index 1d0a61bc..9661f416 100644 --- a/app/controllers/admin/sponsorship_levels_controller.rb +++ b/app/controllers/admin/sponsorship_levels_controller.rb @@ -1,6 +1,7 @@ module Admin class SponsorshipLevelsController < ApplicationController - before_filter :verify_organizer + load_and_authorize_resource :conference, find_by: :short_title + authorize_resource :sponsorship_level, through: :conference def update if @conference.update_attributes(params[:conference]) diff --git a/app/controllers/admin/stats_controller.rb b/app/controllers/admin/stats_controller.rb index b5685bff..35ec18dd 100644 --- a/app/controllers/admin/stats_controller.rb +++ b/app/controllers/admin/stats_controller.rb @@ -1,6 +1,7 @@ module Admin class StatsController < ApplicationController - before_filter :verify_organizer + load_and_authorize_resource + load_and_authorize_resource :conference, find_by: :short_title def index @registrations = @conference.registrations.includes(:user) diff --git a/app/controllers/admin/supporter_levels_controller.rb b/app/controllers/admin/supporter_levels_controller.rb index 33218920..7b422d11 100644 --- a/app/controllers/admin/supporter_levels_controller.rb +++ b/app/controllers/admin/supporter_levels_controller.rb @@ -1,12 +1,13 @@ -class Admin::SupporterLevelsController < ApplicationController - before_filter :verify_organizer +module Admin + class Admin::SupporterLevelsController < ApplicationController + load_and_authorize_resource :conference, find_by: :short_title + authorize_resource :supporter_level, through: :conference - def show - render :supporter_levels - end + def show + render :supporter_levels + end - def update - begin + def update @conference.update_attributes!(params[:conference]) redirect_to(admin_conference_supporter_levels_path(conference_id: @conference.short_title), notice: 'Supporter levels were successfully updated.') rescue => e diff --git a/app/controllers/admin/supporters_controller.rb b/app/controllers/admin/supporters_controller.rb index a114daca..c9f6f0e0 100644 --- a/app/controllers/admin/supporters_controller.rb +++ b/app/controllers/admin/supporters_controller.rb @@ -1,16 +1,21 @@ -class Admin::SupportersController < ApplicationController - before_filter :verify_organizer +module Admin + class Admin::SupportersController < ApplicationController + load_and_authorize_resource :conference, find_by: :short_title + load_and_authorize_resource :supporter, through: :conference - def index - respond_to do |format| - format.html - format.json { render json: DatatableSupporters.new(@conference.supporter_registrations, view_context) } + def index + respond_to do |format| + format.html + format.json { render json: DatatableSupporters. + new(@conference.supporter_registrations, view_context) } + end + end + + def create + params[:supporter_registration][:conference_id] = @conference.id + supporter = SupporterRegistration.create!(params[:supporter_registration]) + redirect_to(admin_conference_supporters_path(conference_id: @conference.short_title), + notice: 'Supporter added') end end - - def create - params[:supporter_registration][:conference_id] = @conference.id - SupporterRegistration.create!(params[:supporter_registration]) - redirect_to(admin_conference_supporters_path(conference_id: @conference.short_title), notice: "Supporter added") - end end diff --git a/app/controllers/admin/targets_controller.rb b/app/controllers/admin/targets_controller.rb index 94562de3..eadc2737 100644 --- a/app/controllers/admin/targets_controller.rb +++ b/app/controllers/admin/targets_controller.rb @@ -1,6 +1,7 @@ module Admin class TargetsController < ApplicationController - before_filter :verify_organizer + load_and_authorize_resource :conference, find_by: :short_title + authorize_resource :target, through: :conference def index end diff --git a/app/controllers/admin/tracks_controller.rb b/app/controllers/admin/tracks_controller.rb index 102cdd68..ea360b88 100644 --- a/app/controllers/admin/tracks_controller.rb +++ b/app/controllers/admin/tracks_controller.rb @@ -1,22 +1,25 @@ -class Admin::TracksController < ApplicationController - before_filter :verify_organizer +module Admin + class TracksController < ApplicationController + load_and_authorize_resource :conference, find_by: :short_title + authorize_resource through: :conference - def show - respond_to do |format| - format.html { render :tracks_list } - format.json { render json: @conference.tracks.to_json } + def show + respond_to do |format| + format.html { render :tracks_list } + format.json { render json: @conference.tracks.to_json } + end end - end - def update - if @conference.update_attributes(params[:conference]) - redirect_to(admin_conference_tracks_path( - conference_id: @conference.short_title), - notice: 'Tracks were successfully updated.') - else - redirect_to(admin_conference_tracks_path( - conference_id: @conference.short_title), - notice: 'Tracks update failed.') + def update + if @conference.update_attributes(params[:conference]) + redirect_to(admin_conference_tracks_path( + conference_id: @conference.short_title), + notice: 'Tracks were successfully updated.') + else + redirect_to(admin_conference_tracks_path( + conference_id: @conference.short_title), + notice: 'Tracks update failed.') + end end end end diff --git a/app/controllers/admin/users_controller.rb b/app/controllers/admin/users_controller.rb index b6966822..178f3ae5 100644 --- a/app/controllers/admin/users_controller.rb +++ b/app/controllers/admin/users_controller.rb @@ -1,14 +1,12 @@ module Admin class UsersController < ApplicationController - before_filter :verify_admin + load_and_authorize_resource :user def index @users = User.all end def show - @user = User.find(params[:id]) - # Variable @show_attributes holds the attributes that are visible for the 'show' action # If you want to change the attributes that are shown in the 'show' action of users # add/remove the attributes in the following string array @@ -18,23 +16,16 @@ module Admin end def update - user = User.find(params[:id]) - user.update_attributes!(params[:user]) - redirect_to admin_users_path, notice: "Updated #{user.email}" + @user.update_attributes!(params[:user]) + redirect_to admin_users_path, notice: "Updated #{@user.email}" end def edit - @user = User.find(params[:id]) - end - - def delete - @user = User.find(params[:id]) end def destroy - @user = User.find(params[:id]) @user.destroy - redirect_to admin_users_path, notice: 'User got deleted' + redirect_to admin_users_path, notice: "User #{@user.name} (#{@user.email})got deleted" end end end diff --git a/app/controllers/admin/venue_controller.rb b/app/controllers/admin/venue_controller.rb index 5f511971..e277b9d6 100644 --- a/app/controllers/admin/venue_controller.rb +++ b/app/controllers/admin/venue_controller.rb @@ -1,34 +1,37 @@ -class Admin::VenueController < ApplicationController - before_filter :verify_organizer +module Admin + class VenueController < ApplicationController + load_and_authorize_resource :conference, find_by: :short_title + load_and_authorize_resource :venue, through: :conference, singleton: true - def index - end + def index + end - def update - @venue = @conference.venue - @venue.assign_attributes(params[:venue]) - unless @venue.name.blank? || @venue.address.blank? || @conference.registrations.blank? - if (@venue.name_changed? || - @venue.address_changed?) && - (@conference.email_settings.send_on_venue_update && - !@conference.email_settings.venue_update_subject.blank? && - @conference.email_settings.venue_update_template) - venue_notify = Mailbot.send_email_on_venue_update(@conference) + def update + @venue = @conference.venue + @venue.assign_attributes(params[:venue]) + unless @venue.name.blank? || @venue.address.blank? || @conference.registrations.blank? + if (@venue.name_changed? || + @venue.address_changed?) && + (@conference.email_settings.send_on_venue_update && + !@conference.email_settings.venue_update_subject.blank? && + @conference.email_settings.venue_update_template) + venue_notify = Mailbot.send_email_on_venue_update(@conference) + end + end + + if @venue.update_attributes(params[:venue]) + venue_notify.deliver unless venue_notify.blank? + redirect_to(admin_conference_venue_info_path(conference_id: @conference.short_title), + notice: 'Venue was successfully updated.') + else + redirect_to(admin_conference_venue_info_path(conference_id: @conference.short_title), + notice: 'Venue Updation Failed!') end end - if @venue.update_attributes(params[:venue]) - venue_notify.deliver unless venue_notify.blank? - redirect_to(admin_conference_venue_info_path(conference_id: @conference.short_title), - notice: 'Venue was successfully updated.') - else - redirect_to(admin_conference_venue_info_path(conference_id: @conference.short_title), - notice: 'Venue Updation Failed!') + def show + @venue = @conference.venue + render :venue_info end end - - def show - @venue = @conference.venue - render :venue_info - end end diff --git a/app/controllers/admin/volunteers_controller.rb b/app/controllers/admin/volunteers_controller.rb index afc688c9..e2253fc1 100644 --- a/app/controllers/admin/volunteers_controller.rb +++ b/app/controllers/admin/volunteers_controller.rb @@ -1,25 +1,28 @@ -class Admin::VolunteersController < ApplicationController - def index - @conference = Conference.find_by(short_title: params[:conference_id]) - render :index - end - - def show - @conference = Conference.find_by(short_title: params[:conference_id]) - if @conference.use_vpositions - @volunteers = @conference.registrations.joins(:vchoices).uniq - else - @volunteers = @conference.registrations.where(volunteer: true) - end - end +module Admin + class VolunteersController < ApplicationController + load_and_authorize_resource :conference, find_by: :short_title + authorize_resource class: false, through: :conference - def update - @conference = Conference.find_by(short_title: params[:conference_id]) - begin - @conference.update_attributes!(params[:conference]) - redirect_to(admin_conference_volunteers_info_path(conference_id: params[:conference_id]), notice: "Volunteering options were successfully updated.") - rescue => e - redirect_to(admin_conference_volunteers_info_path(conference_id: params[:conference_id]), alert: "Volunteering options update failed: #{e.message}") + def index + render :index + end + + def show + if @conference.use_vpositions + @volunteers = @conference.registrations.joins(:vchoices).uniq + else + @volunteers = @conference.registrations.where(volunteer: true) + end + end + + def update + @conference = Conference.find_by(short_title: params[:conference_id]) + begin + @conference.update_attributes!(params[:conference]) + redirect_to(admin_conference_volunteers_info_path(conference_id: params[:conference_id]), notice: "Volunteering options were successfully updated.") + rescue => e + redirect_to(admin_conference_volunteers_info_path(conference_id: params[:conference_id]), alert: "Volunteering options update failed: #{e.message}") + end end end end diff --git a/app/controllers/application_controller.rb b/app/controllers/application_controller.rb index 2a27b803..86e29c90 100644 --- a/app/controllers/application_controller.rb +++ b/app/controllers/application_controller.rb @@ -4,13 +4,15 @@ class ApplicationController < ActionController::Base before_filter :get_conferences before_filter :store_location helper_method :date_string + # Ensure every controller authorizes resource or skips authorization (skip_authorization_check) + check_authorization unless: :devise_controller? def store_location session[:return_to] = request.fullpath if request.get? and controller_name != "user_sessions" and controller_name != "sessions" end def after_sign_in_path_for(resource) - if organizer_or_admin? && + if can? :view, Conference && (!session[:return_to] || session[:return_to] && session[:return_to] == root_path) @@ -39,36 +41,21 @@ class ApplicationController < ActionController::Base return false end - @conference = Conference.find_by(short_title: params[:conference_id]) true end - def organizer_or_admin? - has_role?(current_user, 'admin') || has_role?(current_user, 'organizer') - end - - def verify_organizer - if !verify_user - return + def current_ability + if self.class.to_s.split('::').first == 'Admin' + @current_ability ||= AdminAbility.new(current_user) + else + @current_ability ||= Ability.new(current_user) end - - ## Todo simplify this - redirect_to root_path unless has_role?(current_user, 'admin') || has_role?(current_user, 'organizer') - end - - def verify_admin - if !verify_user - return - end - - redirect_to root_path unless has_role?(current_user, 'admin') end rescue_from CanCan::AccessDenied do |exception| Rails.logger.debug("Access denied!") redirect_to root_path, alert: exception.message end - helper_method :organizer_or_admin? def not_found raise ActionController::RoutingError.new('Not Found') diff --git a/app/controllers/conference_controller.rb b/app/controllers/conference_controller.rb index b3f6dae2..57dd0014 100644 --- a/app/controllers/conference_controller.rb +++ b/app/controllers/conference_controller.rb @@ -1,11 +1,12 @@ class ConferenceController < ApplicationController + load_and_authorize_resource find_by: :short_title + def show - @conference = Conference.find_by_short_title(params[:id]) not_found unless @conference.make_conference_public? end def gallery_photos - @photos = Conference.find_by_short_title(params[:id]).photos + @photos = @conference.photos render "photos", formats: [:js] end end diff --git a/app/controllers/event_attachments_controller.rb b/app/controllers/event_attachments_controller.rb index a54fc2a4..c5904482 100644 --- a/app/controllers/event_attachments_controller.rb +++ b/app/controllers/event_attachments_controller.rb @@ -1,9 +1,11 @@ class EventAttachmentsController < ApplicationController + load_and_authorize_resource :conference, find_by: :short_title + load_and_authorize_resource :proposal, class: Event + load_and_authorize_resource :upload, class: EventAttachment, through: :proposal before_filter :verify_user skip_before_filter :verify_user, only: [:show] def index - @proposal = Event.find(params[:proposal_id]) @uploads = @proposal.event_attachments @uploads = @uploads.map{|upload| upload.to_jq_upload } @@ -14,9 +16,9 @@ class EventAttachmentsController < ApplicationController end def show - upload = EventAttachment.find(params[:id]) - if upload.public? - send_file upload.attachment.path + + if @upload.public? + send_file @upload.attachment.path return end @@ -26,7 +28,7 @@ class EventAttachmentsController < ApplicationController end if organizer_or_admin? || current_user == upload.event.submitter - send_file upload.attachment.path + send_file @upload.attachment.path else raise ActionController::RoutingError.new('Not Found') end @@ -42,7 +44,6 @@ class EventAttachmentsController < ApplicationController end def edit - @upload = EventAttachment.find(params[:id]) end def create @@ -50,7 +51,7 @@ class EventAttachmentsController < ApplicationController params[:event_attachment][:public] = false params[:event_attachment][:event_id] = params[:proposal_id] - if !organizer_or_admin? + if cannot? :create, EventAttachment begin current_user.events.find(params[:proposal_id]) rescue @@ -83,8 +84,6 @@ class EventAttachmentsController < ApplicationController end def update - @proposal = current_user.events.find(params[:proposal_id]) - @upload = @proposal.event_attachments.find(params[:proposal_id]) respond_to do |format| if @upload.update_attributes(params[:upload]) @@ -98,14 +97,13 @@ class EventAttachmentsController < ApplicationController end def destroy - @proposal = Event.find(params[:proposal_id]) - - if organizer_or_admin? || current_user == @proposal.submitter + + if can? :destroy, @proposal @upload = @proposal.event_attachments.find(params[:id]) end - + @upload.destroy if !@upload.nil? - + respond_to do |format| format.html { redirect_back_or_to conference_proposal_index_path(@conference.short_title), notice: "Deleted successfully attachment '#{@upload.title}' for proposal '#{@proposal.title}'" } diff --git a/app/controllers/home_controller.rb b/app/controllers/home_controller.rb index 1b6a0373..8da4883f 100644 --- a/app/controllers/home_controller.rb +++ b/app/controllers/home_controller.rb @@ -1,5 +1,6 @@ class HomeController < ApplicationController before_filter :respond_to_options + skip_authorization_check def index @today = Date.current diff --git a/app/controllers/proposal_controller.rb b/app/controllers/proposal_controller.rb index dd2bf657..3a338091 100644 --- a/app/controllers/proposal_controller.rb +++ b/app/controllers/proposal_controller.rb @@ -1,32 +1,35 @@ class ProposalController < ApplicationController + load_and_authorize_resource :conference, find_by: :short_title + load_and_authorize_resource :event, parent: false before_filter :verify_user, except: [:show] - before_action :set_conference, only: [:show] - before_action :set_event, only: [:show, :edit, :update, :destroy, :confirm, :restart] + before_filter :setup + + def setup + @user = current_user if current_user + @url = conference_proposal_index_path(@conference.short_title) + @event_types = @conference.event_types + end def index @events = current_user.proposals(@conference) end def show - authorize! :show, @event # FIXME: We should show more than the first speaker @speaker = @event.speakers.first || @event.submitter end def new - authorize! :new, Event @url = conference_proposal_index_path(@conference.short_title) @event = Event.new end def edit - authorize! :edit, @event @url = conference_proposal_path(@conference.short_title, params[:id]) @attachments = @event.event_attachments end def create - authorize! :create, Event @url = conference_proposal_index_path(@conference.short_title) params[:event].delete :user @@ -63,7 +66,6 @@ class ProposalController < ApplicationController end def update - authorize! :update, @event @url = conference_proposal_path(@conference.short_title, params[:id]) # First, update the submitter's info, if they've changed anything @@ -129,12 +131,12 @@ class ProposalController < ApplicationController end def restart - authorize! :update, @event @url = conference_proposal_path(@conference.short_title, params[:id]) - + begin @event.restart rescue Transitions::InvalidTransition + redirect_to(conference_proposal_index_path(conference_id: @conference.short_title), error: "The proposal can't be re-submitted.") return @@ -149,14 +151,4 @@ class ProposalController < ApplicationController redirect_to(conference_proposal_index_path(conference_id: @conference.short_title), notice: "The proposal was re-submitted. The #{@conference.short_title} organizers will review it again.") end - - private - - def set_conference - @conference = Conference.find_by(short_title: params[:conference_id]) - end - - def set_event - @event = Event.find(params[:id]) - end end diff --git a/app/controllers/schedule_controller.rb b/app/controllers/schedule_controller.rb index 365d8bf2..df534eac 100644 --- a/app/controllers/schedule_controller.rb +++ b/app/controllers/schedule_controller.rb @@ -1,6 +1,7 @@ class ScheduleController < ApplicationController + authorize_resource class: false layout "application" - + def index @conference = Conference.includes(:rooms, {events: [:speakers, :track, :event_type]}).where("conferences.short_title" => params[:conference_id]).first @rooms = @conference.rooms diff --git a/app/controllers/users/omniauth_callbacks_controller.rb b/app/controllers/users/omniauth_callbacks_controller.rb index aca14642..4412a8ae 100644 --- a/app/controllers/users/omniauth_callbacks_controller.rb +++ b/app/controllers/users/omniauth_callbacks_controller.rb @@ -1,6 +1,7 @@ module Users class OmniauthCallbacksController < Devise::OmniauthCallbacksController skip_before_filter :verify_authenticity_token + skip_authorization_check User.omniauth_providers.each do |provider| define_method(provider) { handle(provider) } diff --git a/app/models/ability.rb b/app/models/ability.rb index 8c09734e..4fbc3135 100644 --- a/app/models/ability.rb +++ b/app/models/ability.rb @@ -2,16 +2,27 @@ class Ability include CanCan::Ability def initialize(user) - # guest user (not logged in) - user ||= User.new - if user.admin? || user.organizer? - # An admin can manage everything - can :manage, :all - else - can [:update, :destroy], Event do |event| - event.users.include?(user) - end - can [:create, :read], Event - end + # Define abilities for the passed in user here. For example: + # + user ||= User.new # guest user (not logged in) + # if user.admin? + # can :manage, :all + # else + # can :read, :all + # end + # + # The first argument to `can` is the action you are giving the user permission to do. + # If you pass :manage it will apply to every action. Other common actions here are + # :read, :create, :update and :destroy. + # + # The second argument is the resource the user can perform the action on. If you pass + # :all it will apply to every resource. Otherwise pass a Ruby class of the resource. + # + # The third argument is an optional hash of conditions to further filter the objects. + # For example, here the user can only update published articles. + # + # can :update, Article, :published => true + # + # See the wiki for details: https://github.com/ryanb/cancan/wiki/Defining-Abilities end end diff --git a/app/models/admin_ability.rb b/app/models/admin_ability.rb new file mode 100644 index 00000000..d90e01e9 --- /dev/null +++ b/app/models/admin_ability.rb @@ -0,0 +1,11 @@ +class AdminAbility + include CanCan::Ability + + def initialize(user) + user ||= User.new # for guest + if user.role?('Conference Admin') + can :manage, :all + end + + end +end