Implement role authorization

This commit is contained in:
Stella Rouzi 2014-08-12 11:51:59 +03:00
parent 6755328c4c
commit e2fb434dc7
122 changed files with 1386 additions and 751 deletions

View file

@ -1,9 +1,11 @@
class EventAttachmentsController < ApplicationController
load_and_authorize_resource :conference, find_by: :short_title
load_and_authorize_resource :proposal, class: Event
load_and_authorize_resource :upload, class: EventAttachment, through: :proposal
before_filter :verify_user
skip_before_filter :verify_user, only: [:show]
def index
@proposal = Event.find(params[:proposal_id])
@uploads = @proposal.event_attachments
@uploads = @uploads.map{|upload| upload.to_jq_upload }
@ -14,9 +16,9 @@ class EventAttachmentsController < ApplicationController
end
def show
upload = EventAttachment.find(params[:id])
if upload.public?
send_file upload.attachment.path
if @upload.public?
send_file @upload.attachment.path
return
end
@ -26,7 +28,7 @@ class EventAttachmentsController < ApplicationController
end
if organizer_or_admin? || current_user == upload.event.submitter
send_file upload.attachment.path
send_file @upload.attachment.path
else
raise ActionController::RoutingError.new('Not Found')
end
@ -42,7 +44,6 @@ class EventAttachmentsController < ApplicationController
end
def edit
@upload = EventAttachment.find(params[:id])
end
def create
@ -50,7 +51,7 @@ class EventAttachmentsController < ApplicationController
params[:event_attachment][:public] = false
params[:event_attachment][:event_id] = params[:proposal_id]
if !organizer_or_admin?
if cannot? :create, EventAttachment
begin
current_user.events.find(params[:proposal_id])
rescue
@ -66,6 +67,7 @@ class EventAttachmentsController < ApplicationController
respond_to do |format|
if @upload.save
<<<<<<< HEAD
format.html do
render json: [@upload.to_jq_upload].to_json,
content_type: 'text/html',
@ -75,6 +77,15 @@ class EventAttachmentsController < ApplicationController
render json: [@upload.to_jq_upload].to_json, status: :created,
location: conference_proposal_event_attachment_path(@upload.event.conference.short_title, @upload.event, @upload)
end
=======
format.html {
render :json => [@upload.to_jq_upload].to_json,
:content_type => 'text/html',
:layout => false
}
format.json { render json: {files: [@upload.to_jq_upload]}, status: :created,
location: conference_proposal_event_attachment_path(@upload.event.conference.short_title, @upload.event, @upload) }
>>>>>>> authorization with cancancan
else
format.html { render action: "new" }
format.json { render json: @upload.errors, status: :unprocessable_entity }
@ -83,8 +94,6 @@ class EventAttachmentsController < ApplicationController
end
def update
@proposal = current_user.events.find(params[:proposal_id])
@upload = @proposal.event_attachments.find(params[:proposal_id])
respond_to do |format|
if @upload.update_attributes(params[:upload])
@ -98,14 +107,13 @@ class EventAttachmentsController < ApplicationController
end
def destroy
@proposal = Event.find(params[:proposal_id])
if organizer_or_admin? || current_user == @proposal.submitter
if can? :destroy, @proposal
@upload = @proposal.event_attachments.find(params[:id])
end
@upload.destroy if !@upload.nil?
respond_to do |format|
format.html { redirect_back_or_to conference_proposal_index_path(@conference.short_title), notice: "Deleted successfully attachment '#{@upload.title}' for proposal '#{@proposal.title}'" }