Refactored proposal. Enabled cancancan

This commit is contained in:
Henne Vogelsang 2014-07-23 16:24:05 +02:00
parent 0ae7991943
commit c982cbb88a
13 changed files with 204 additions and 231 deletions

View file

@ -1,28 +1,17 @@
class Ability
include CanCan::Ability
def initialize(user) # rubocop:disable Lint/UnusedMethodArgument
# Define abilities for the passed in user here. For example:
#
# user ||= User.new # guest user (not logged in)
# if user.admin?
# can :manage, :all
# else
# can :read, :all
# end
#
# The first argument to `can` is the action you are giving the user permission to do.
# If you pass :manage it will apply to every action. Other common actions here are
# :read, :create, :update and :destroy.
#
# The second argument is the resource the user can perform the action on. If you pass
# :all it will apply to every resource. Otherwise pass a Ruby class of the resource.
#
# The third argument is an optional hash of conditions to further filter the objects.
# For example, here the user can only update published articles.
#
# can :update, Article, :published => true
#
# See the wiki for details: https://github.com/ryanb/cancan/wiki/Defining-Abilities
def initialize(user)
# guest user (not logged in)
user ||= User.new
if user.admin? || user.organizer?
# An admin can manage everything
can :manage, :all
else
can [:update, :destroy], Event do |event|
event.users.include?(user)
end
can [:create, :read], Event
end
end
end

View file

@ -1,17 +0,0 @@
class AdminAbility
include CanCan::Ability
def initialize(user)
@user = user || User.new # for guest
@user.get_roles.each { |role| send(role.name.downcase) }
end
def organizer
can :manage, Event
end
def admin
organizer
can :manage, :all
end
end

View file

@ -31,10 +31,11 @@ class Event < ActiveRecord::Base
validate :abstract_limit
validate :before_end_of_conference
validate :biography_exists
validate :name_and_biography_exists
validates :title, presence: true
validates :abstract, presence: true
validates :event_type, presence: true
validates :conference, presence: true
validates :media_type, inclusion: { in: Conference.media_types.values }, allow_blank: true
scope :confirmed, -> { where(state: 'confirmed') }
@ -218,8 +219,9 @@ class Event < ActiveRecord::Base
errors.add(:abstract, "cannot have more than #{max_words} words") if len > max_words
end
def biography_exists
errors.add(:user_biography, 'must be filled out') if submitter.biography_word_count == 0
def name_and_biography_exists
errors.add(:biography, "cant' be blank") if submitter.biography.blank?
errors.add(:username, " can't be blank") if submitter.name.blank?
end
# TODO: create a module to be mixed into model to perform same operation

View file

@ -52,6 +52,14 @@ class User < ActiveRecord::Base
!!roles.find_by_name(role.to_s.downcase.camelize)
end
def admin?
role?('Admin')
end
def organizer?
role?('Organizer')
end
def get_roles
roles
end