Implement role authorization

This commit is contained in:
Stella Rouzi 2014-08-12 11:51:59 +03:00
parent 6755328c4c
commit e2fb434dc7
122 changed files with 1386 additions and 751 deletions

View file

@ -22,6 +22,8 @@ gem 'omniauth-google-oauth2'
# Use cancancan as authorization framework # Use cancancan as authorization framework
gem 'cancancan' gem 'cancancan'
# Use rolify to set roles
gem 'rolify'
# Use transitions as state machine # Use transitions as state machine
gem 'transitions', :require => %w( transitions active_record/transitions ) gem 'transitions', :require => %w( transitions active_record/transitions )

View file

@ -296,6 +296,7 @@ GEM
request_store (1.0.6) request_store (1.0.6)
rest-client (1.6.7) rest-client (1.6.7)
mime-types (>= 1.16) mime-types (>= 1.16)
rolify (3.4.0)
rspec (3.0.0) rspec (3.0.0)
rspec-core (~> 3.0.0) rspec-core (~> 3.0.0)
rspec-expectations (~> 3.0.0) rspec-expectations (~> 3.0.0)
@ -441,6 +442,7 @@ DEPENDENCIES
rails-observers rails-observers
rdoc-generator-fivefish rdoc-generator-fivefish
redcarpet redcarpet
rolify
rspec-activemodel-mocks rspec-activemodel-mocks
rspec-rails rspec-rails
rubocop rubocop

View file

@ -1,8 +1,10 @@
module Admin module Admin
class CallforpapersController < ApplicationController class CallforpapersController < ApplicationController
before_filter :verify_organizer load_and_authorize_resource :conference, find_by: :short_title
# load_and_authorize_resource :cfp, class: 'CallForPapers', through: :conference
def show def show
authorize! :show, CallForPapers.new(conference_id: @conference.id)
@cfp = @conference.call_for_papers @cfp = @conference.call_for_papers
if @cfp.nil? if @cfp.nil?
@cfp = CallForPapers.new @cfp = CallForPapers.new
@ -10,6 +12,7 @@ module Admin
end end
def update def update
authorize! :update, @conference.call_for_papers
@cfp = @conference.call_for_papers @cfp = @conference.call_for_papers
@cfp.assign_attributes(params[:call_for_papers]) @cfp.assign_attributes(params[:call_for_papers])
send_mail_on_schedule_public = @cfp.notify_on_schedule_public? send_mail_on_schedule_public = @cfp.notify_on_schedule_public?
@ -30,6 +33,7 @@ module Admin
end end
def create def create
authorize! :update, CallForPapers.new(conference_id: @conference.id)
@cfp = CallForPapers.new(params[:call_for_papers]) @cfp = CallForPapers.new(params[:call_for_papers])
if @cfp.valid? if @cfp.valid?
@cfp.save @cfp.save

View file

@ -1,16 +1,15 @@
module Admin module Admin
class CampaignsController < ApplicationController class CampaignsController < ApplicationController
before_filter :verify_organizer load_and_authorize_resource :conference, find_by: :short_title
load_and_authorize_resource :campaign, through: :conference
def index def index
@conference = Conference.find_by(short_title: params[:conference_id]) authorize! :show, Campaign.new(conference_id: @conference.id)
@campaigns = @conference.campaigns @campaigns = @conference.campaigns
end end
def create def create
@conference = Conference.find_by(short_title: params[:conference_id]) @campaign.attributes = params[:campaign]
@campaign = @conference.campaigns.new(params[:campaign])
@campaign.conference_id = @conference.id
if @conference.save if @conference.save
redirect_to(admin_conference_campaigns_path(conference_id: @conference.short_title), redirect_to(admin_conference_campaigns_path(conference_id: @conference.short_title),
@ -23,19 +22,12 @@ module Admin
end end
def new def new
@conference = Conference.find_by(short_title: params[:conference_id])
@campaign = @conference.campaigns.new
end end
def edit def edit
@conference = Conference.find_by(short_title: params[:conference_id])
@campaign = Campaign.find(params[:id])
end end
def update def update
@conference = Conference.find_by(short_title: params[:conference_id])
@campaign = Campaign.find(params[:id])
if @campaign.update_attributes(params[:campaign]) if @campaign.update_attributes(params[:campaign])
redirect_to(admin_conference_campaigns_path( redirect_to(admin_conference_campaigns_path(
conference_id: @conference.short_title), conference_id: @conference.short_title),
@ -50,8 +42,6 @@ module Admin
end end
def destroy def destroy
@conference = Conference.find_by(short_title: params[:conference_id])
@campaign = Campaign.find(params[:id])
if @campaign.destroy if @campaign.destroy
redirect_to(admin_conference_campaigns_path(conference_id: @conference.short_title), redirect_to(admin_conference_campaigns_path(conference_id: @conference.short_title),
notice: "Campaign '#{@campaign.name}' successfully deleted.") notice: "Campaign '#{@campaign.name}' successfully deleted.")

View file

@ -1,7 +1,7 @@
module Admin module Admin
class CommercialsController < ApplicationController class CommercialsController < ApplicationController
before_action :set_conference load_and_authorize_resource :conference, find_by: :short_title
before_action :set_commercial, only: [:edit, :update, :destroy] load_and_authorize_resource through: :conference
def index def index
@commercials = @conference.commercials @commercials = @conference.commercials
@ -43,14 +43,6 @@ module Admin
private private
def set_commercial
@commercial = @conference.commercials.find(params[:id])
end
def set_conference
@conference = Conference.find_by(short_title: params[:conference_id])
end
def commercial_params def commercial_params
#params.require(:commercial).permit(:commercial_id, :commercial_type) #params.require(:commercial).permit(:commercial_id, :commercial_type)
params[:commercial] params[:commercial]

View file

@ -1,6 +1,6 @@
module Admin module Admin
class ConferenceController < ApplicationController class ConferenceController < ApplicationController
before_filter :verify_organizer load_and_authorize_resource :conference, find_by: :short_title
def index def index
# Redirect to new form if there is no conference # Redirect to new form if there is no conference
@ -63,8 +63,11 @@ module Admin
def create def create
@conference = Conference.new(params[:conference]) @conference = Conference.new(params[:conference])
if @conference.valid? if @conference.valid?
@conference.save @conference.save
# user that creates the conference becomes organizer of that conference
current_user.add_role :organizer, @conference
redirect_to(admin_conference_path(id: @conference.short_title), redirect_to(admin_conference_path(id: @conference.short_title),
notice: 'Conference was successfully created.') notice: 'Conference was successfully created.')
else else
@ -108,6 +111,7 @@ module Admin
if @conference.update_attributes(params[:conference]) if @conference.update_attributes(params[:conference])
Mailbot.delay.conference_date_update_mail(@conference) if notify_on_conf_dates_updates Mailbot.delay.conference_date_update_mail(@conference) if notify_on_conf_dates_updates
Mailbot.delay.conference_registration_date_update_mail(@conference) if notify_on_conf_reg_dates_updates Mailbot.delay.conference_registration_date_update_mail(@conference) if notify_on_conf_reg_dates_updates
redirect_to(edit_admin_conference_path(id: @conference.short_title), redirect_to(edit_admin_conference_path(id: @conference.short_title),
notice: 'Conference was successfully updated.') notice: 'Conference was successfully updated.')
else else

View file

@ -1,33 +1,30 @@
module Admin module Admin
class ContactsController < ApplicationController class ContactsController < ApplicationController
before_action :set_conference load_and_authorize_resource :conference, find_by: :short_title
before_action :set_conference load_and_authorize_resource through: :conference, singleton: true
before_action :set_contact, only: [:edit, :update]
# GET /:conference/contact/edit # GET /:conference/contact
def edit def show; end
# GET /:conference/contact/edit
def edit; end
# PATCH/PUT /:conference/contact
def update
if @contact.update(contact_params)
redirect_to admin_conference_contact_path, notice: 'Contact details were successfully updated.'
else
render :edit
end end
end
# PATCH/PUT /:conference/contact # DELETE /:conference/contact
def update def destroy
if @contact.update(contact_params) @contact.destroy
redirect_to edit_admin_conference_contact_path, notice: 'Contact details were successfully updated.' redirect_to admin_conference_contacts_url, notice: 'Contact details were successfully destroyed.'
else end
render :edit
end
end
private
# Use callbacks to share common setup or constraints between actions.
def set_contact
@contact = @conference.contact
end
def set_conference
@conference = Conference.find_by(short_title: params[:conference_id])
end
private
# Only allow a trusted parameter "white list" through. # Only allow a trusted parameter "white list" through.
def contact_params def contact_params
# params.require(:contact).permit(:social_tag, :email, :facebook, :googleplus, :twitter, :instagram, :public) # params.require(:contact).permit(:social_tag, :email, :facebook, :googleplus, :twitter, :instagram, :public)

View file

@ -1,6 +1,7 @@
module Admin module Admin
class DietchoicesController < ApplicationController class DietchoicesController < ApplicationController
before_filter :verify_organizer load_and_authorize_resource :conference, find_by: :short_title
load_and_authorize_resource :dietary_choice, through: :conference
def show def show
render :diets_list render :diets_list
@ -9,9 +10,9 @@ module Admin
def update def update
begin begin
@conference.update_attributes!(params[:conference]) @conference.update_attributes!(params[:conference])
redirect_to(admin_conference_dietary_list_path(conference_id: @conference.short_title), notice: 'Dietary choices were successfully updated.') redirect_to(admin_conference_dietary_list_path(:conference_id => @conference.short_title), :notice => 'Dietary choices were successfully updated.')
rescue => e rescue => e
redirect_to(admin_conference_dietary_list_path(conference_id: @conference.short_title), alert: "Dietary choices update failed: #{e.message}") redirect_to(admin_conference_dietary_list_path(:conference_id => @conference.short_title), :alert => "Dietary choices update failed: #{e.message}")
end end
end end
end end

View file

@ -1,9 +1,10 @@
module Admin module Admin
class DifficultyLevelsController < ApplicationController class DifficultyLevelsController < ApplicationController
before_filter :verify_organizer load_and_authorize_resource :conference, find_by: :short_title
authorize_resource through: :conference
def index def index
@conference = Conference.find_by(short_title: params[:conference_id]) authorize! :index, DifficultyLevel.new(conference_id: @conference.id)
end end
def update def update
@ -13,18 +14,18 @@ module Admin
@conference.use_difficulty_levels = false @conference.use_difficulty_levels = false
@conference.save! @conference.save!
flash[:error] = "You cannot enable the usage of difficulty levels without having set any levels." flash[:error] = "You cannot enable the usage of difficulty levels without having set any levels."
redirect_to(admin_conference_difficulty_levels_path(conference_id: @conference.short_title)) redirect_to(admin_conference_difficulty_levels_path(:conference_id => @conference.short_title))
rescue ActiveRecord::RecordInvalid rescue ActiveRecord::RecordInvalid
flash[:error] = "Something went wrong. Difficulty Levels update failed." flash[:error] = "Something went wrong. Difficulty Levels update failed."
redirect_to(admin_conference_difficulty_levels_path(conference_id: @conference.short_title)) redirect_to(admin_conference_difficulty_levels_path(:conference_id => @conference.short_title))
end end
else else
flash[:notice] = "Difficulty Levels were successfully updated." flash[:notice] = "Difficulty Levels were successfully updated."
redirect_to(admin_conference_difficulty_levels_path(conference_id: @conference.short_title)) redirect_to(admin_conference_difficulty_levels_path(:conference_id => @conference.short_title))
end end
else else
flash[:error] = "Difficulty Levels update failed." flash[:error] = "Difficulty Levels update failed."
redirect_to(admin_conference_difficulty_levels_path(conference_id: @conference.short_title)) redirect_to(admin_conference_difficulty_levels_path(:conference_id => @conference.short_title))
end end
end end
end end

View file

@ -1,6 +1,7 @@
module Admin module Admin
class EmailsController < ApplicationController class EmailsController < ApplicationController
before_filter :verify_organizer load_and_authorize_resource :conference, find_by: :short_title
load_and_authorize_resource class: EmailSettings
def update def update
@conference.email_settings.update_attributes(params[:email_settings]) @conference.email_settings.update_attributes(params[:email_settings])
@ -10,6 +11,7 @@ module Admin
end end
def index def index
authorize! :index, @conference.email_settings
@settings = @conference.email_settings @settings = @conference.email_settings
end end
end end

View file

@ -0,0 +1,25 @@
module Admin
class EventTypesController < ApplicationController
load_and_authorize_resource :conference, find_by: :short_title
authorize_resource :event_type, through: :conference
def index
authorize! :index, EventType.new(conference_id: @conference.id)
end
def show
render :eventtypes
end
def update
@conference.update_attributes!(params[:conference])
redirect_to(admin_conference_event_types_path(
conference_id: @conference.short_title),
notice: 'Event types were successfully updated.')
rescue Exception => e
redirect_to(admin_conference_event_types_path(
conference_id: @conference.short_title),
alert: "Event types update failed: #{e.message}")
end
end
end

View file

@ -1,6 +1,7 @@
module Admin module Admin
class EventsController < ApplicationController class EventsController < ApplicationController
before_filter :verify_organizer load_and_authorize_resource :conference, find_by: :short_title
load_and_authorize_resource :event, through: :conference
before_action :get_event, except: [:index, :create] before_action :get_event, except: [:index, :create]
@ -13,6 +14,8 @@ module Admin
end end
def index def index
authorize! :index, @conference.events.build
@conference = Conference.find_by(short_title: params[:conference_id])
@events = @conference.events @events = @conference.events
@tracks = @conference.tracks @tracks = @conference.tracks
@machine_states = @events.state_machine.states.map @machine_states = @events.state_machine.states.map

View file

@ -1,16 +1,17 @@
module Admin module Admin
class LodgingsController < ApplicationController class LodgingsController < ApplicationController
before_filter :verify_organizer load_and_authorize_resource :conference, find_by: :short_title
load_and_authorize_resource :venue, through: :conference, singleton: true
authorize_resource :lodging, through: :venue
def index def index
@venue = @conference.venue authorize! :update, Lodging.new(venue_id: @venue.id)
end end
def show def show
end end
def update def update
@venue = @conference.venue
if @venue.update_attributes(params[:venue]) if @venue.update_attributes(params[:venue])
redirect_to(admin_conference_lodgings_path(conference_id: @conference.short_title), redirect_to(admin_conference_lodgings_path(conference_id: @conference.short_title),
notice: 'Lodgings were successfully updated.') notice: 'Lodgings were successfully updated.')

View file

@ -1,23 +1,24 @@
module Admin module Admin
class QuestionsController < ApplicationController class QuestionsController < ApplicationController
before_filter :verify_organizer load_and_authorize_resource :conference, find_by: :short_title
load_and_authorize_resource through: :conference, except: [:new, :create]
def index def index
@conference = Conference.find_by(short_title: params[:conference_id]) authorize! :update, Question.new(conference_id: @conference.id)
@questions = Question.where(global: true).all | Question.where(conference_id: @conference.id) @questions = Question.where(:global => true).all | Question.where(:conference_id => @conference.id)
@questions_conference = @conference.questions @questions_conference = @conference.questions
@new_question = @conference.questions.new @new_question = @conference.questions.new
end end
def new def new
@conference = Conference.find_by(short_title: params[:conference_id]) @question = Question.new(conference_id: @conference.id)
@new_question = @conference.questions.new authorize! :create, @question
end end
def create def create
@conference = Conference.find_by(short_title: params[:conference_id])
@question = @conference.questions.new(params[:question]) @question = @conference.questions.new(params[:question])
@question.conference_id = @conference.id @question.conference_id = @conference.id
authorize! :create, @question
respond_to do |format| respond_to do |format|
if @conference.save if @conference.save
@ -31,42 +32,33 @@ module Admin
# GET questions/1/edit # GET questions/1/edit
def edit def edit
@conference = Conference.find_by(short_title: params[:conference_id]) if @question.global == true && !(current_user.has_role? :organizer, @conference)
@question = Question.find(params[:id]) redirect_to(admin_conference_questions_path(:conference_id => @conference.short_title), :alert => "Sorry, you cannot edit global questions. Create a new one.")
if @question.global == true && !has_role?(current_user, "Admin")
redirect_to(admin_conference_questions_path(conference_id: @conference.short_title), alert: "Sorry, you cannot edit global questions. Create a new one.")
end end
end end
# PUT questions/1 # PUT questions/1
def update def update
@conference = Conference.find_by(short_title: params[:conference_id])
@question = Question.find(params[:id])
if @question.update_attributes(params[:question]) if @question.update_attributes(params[:question])
redirect_to(admin_conference_questions_path(conference_id: @conference.short_title), notice: "Question '#{@question.title}' for #{@conference.short_title} successfully updated.") redirect_to(admin_conference_questions_path(:conference_id => @conference.short_title), :notice => "Question '#{@question.title}' for #{@conference.short_title} successfully updated.")
else else
redirect_to(admin_conference_questions_path(conference_id: @conference.short_title), notice: "Update of questions for #{@conference.short_title} failed.") redirect_to(admin_conference_questions_path(:conference_id => @conference.short_title), :notice => "Update of questions for #{@conference.short_title} failed.")
end end
end end
# Update questions used for the conference # Update questions used for the conference
def update_conference def update_conference
@conference = Conference.find_by(short_title: params[:conference_id])
if @conference.update_attributes(params[:conference]) if @conference.update_attributes(params[:conference])
redirect_to(admin_conference_questions_path(conference_id: @conference.short_title), notice: "Questions for #{@conference.short_title} successfully updated.") redirect_to(admin_conference_questions_path(:conference_id => @conference.short_title), :notice => "Questions for #{@conference.short_title} successfully updated.")
else else
redirect_to(admin_conference_questions_path(conference_id: @conference.short_title), notice: "Update of questions for #{@conference.short_title} failed.") redirect_to(admin_conference_questions_path(:conference_id => @conference.short_title), :notice => "Update of questions for #{@conference.short_title} failed.")
end end
end end
# DELETE questions/1 # DELETE questions/1
def destroy def destroy
if has_role?(current_user, "Admin")
@question = Question.find(params[:id])
if can? :destroy, @question
# Do not delete global questions # Do not delete global questions
if @question.global == false if @question.global == false
@ -74,12 +66,12 @@ module Admin
begin begin
Question.transaction do Question.transaction do
@question.delete @question.destroy
@question.answers.each do |a| @question.answers.each do |a|
a.delete a.delete
end end
flash[:notice] = "Deleted question: #{@question.title} and its answers: #{@question.answers.map {|a| a.title}.join ','}" flash[:notice] = "Deleted question: #{@question.title} and its answers: #{@question.answers.map {|a| a.title}.join ','}"
end end
rescue ActiveRecord::RecordInvalid rescue ActiveRecord::RecordInvalid
flash[:error] = "Could not delete question." flash[:error] = "Could not delete question."
end end
@ -90,7 +82,7 @@ module Admin
flash[:error] = "You must be an admin to delete a question." flash[:error] = "You must be an admin to delete a question."
end end
@questions = Question.where(global: true).all | Question.where(conference_id: @conference.id) @questions = Question.where(:global => true).all | Question.where(:conference_id => @conference.id)
@questions_conference = @conference.questions @questions_conference = @conference.questions
end end
end end

View file

@ -1,8 +1,10 @@
module Admin module Admin
class RegistrationsController < ApplicationController class RegistrationsController < ApplicationController
before_filter :verify_organizer load_and_authorize_resource :conference, find_by: :short_title
load_and_authorize_resource through: :conference
def index def index
authorize! :show, Registration.new(conference_id: @conference.id)
session[:return_to] ||= request.referer session[:return_to] ||= request.referer
@pdf_filename = "#{@conference.title}.pdf" @pdf_filename = "#{@conference.title}.pdf"
@registrations = @conference.registrations.includes(:user) @registrations = @conference.registrations.includes(:user)
@ -12,7 +14,6 @@ module Admin
end end
def change_field def change_field
@registration = Registration.find(params[:id])
field = params[:view_field] field = params[:view_field]
if @registration.send(field.to_sym) if @registration.send(field.to_sym)
@registration.update_attribute(:"#{field}", 0) @registration.update_attribute(:"#{field}", 0)
@ -26,12 +27,10 @@ module Admin
end end
def edit def edit
@registration = @conference.registrations.where('id = ?', params[:id]).first
@user = User.where('id = ?', @registration.user_id).first @user = User.where('id = ?', @registration.user_id).first
end end
def update def update
@registration = @conference.registrations.where('id = ?', params[:id]).first
@user = User.where('id = ?', @registration.user_id).first @user = User.where('id = ?', @registration.user_id).first
begin begin
@user.update_attributes!(params[:registration][:user_attributes]) @user.update_attributes!(params[:registration][:user_attributes])
@ -55,6 +54,7 @@ module Admin
def new def new
@user = User.new @user = User.new
@registration = @user.registrations.new @registration = @user.registrations.new
@registration.conference_id = @conference.id
@supporter_registration = @conference.supporter_registrations.new @supporter_registration = @conference.supporter_registrations.new
end end
@ -97,7 +97,7 @@ module Admin
end end
def destroy def destroy
if has_role?(current_user, 'Admin') if can? :destroy, @registration
registration = @conference.registrations.where(id: params[:id]).first registration = @conference.registrations.where(id: params[:id]).first
user = User.where('id = ?', registration.user_id).first user = User.where('id = ?', registration.user_id).first

View file

@ -1,6 +1,11 @@
module Admin module Admin
class RoomsController < ApplicationController class RoomsController < ApplicationController
before_filter :verify_organizer load_and_authorize_resource :conference, find_by: :short_title
authorize_resource through: :conference
def index
authorize! :index, Room.new(conference_id: @conference.id)
end
def show def show
render :rooms_list render :rooms_list

View file

@ -1,10 +1,14 @@
module Admin module Admin
class SchedulesController < ApplicationController class SchedulesController < ApplicationController
before_filter :verify_organizer # By authorizing 'conference' resource, we can ensure there will be no unauthorized access to
# the schedule of a conference, which should not be accessed in the first place
load_and_authorize_resource :conference, find_by: :short_title
skip_before_filter :verify_authenticity_token, only: [:update] skip_before_filter :verify_authenticity_token, only: [:update]
layout 'schedule' layout 'schedule'
def show def show
authorize! :update, @conference.events.new
if @conference.nil? if @conference.nil?
redirect_to admin_conference_index_path redirect_to admin_conference_index_path
return return
@ -14,6 +18,7 @@ module Admin
end end
def update def update
authorize! :update, @conference.events.new
event = Event.where(guid: params[:event]).first event = Event.where(guid: params[:event]).first
error_message = nil error_message = nil
if event.nil? if event.nil?

View file

@ -1,6 +1,7 @@
module Admin module Admin
class SocialEventsController < ApplicationController class SocialEventsController < ApplicationController
before_filter :verify_organizer load_and_authorize_resource :conference, find_by: :short_title
authorize_resource :social_event, through: :conference
def show def show
render :social_events_list render :social_events_list
@ -8,9 +9,9 @@ module Admin
def update def update
if @conference.update_attributes(params[:conference]) if @conference.update_attributes(params[:conference])
redirect_to(admin_conference_social_events_path(conference_id: @conference.short_title), notice: 'Social events were successfully updated.') redirect_to(admin_conference_social_events_path(:conference_id => @conference.short_title), :notice => 'Social events were successfully updated.')
else else
redirect_to(admin_conference_social_events_path(conference_id: @conference.short_title), notice: 'Social events update failed.') redirect_to(admin_conference_social_events_path(:conference_id => @conference.short_title), :notice => 'Social events update failed.')
end end
end end
end end

View file

@ -1,15 +1,17 @@
module Admin module Admin
class SpeakersController < ApplicationController class SpeakersController < ApplicationController
before_filter :verify_organizer load_and_authorize_resource :conference, find_by: :short_title
load_and_authorize_resource :event
respond_to :js, :html respond_to :js, :html
def edit def edit
@event = @conference.events.find(params[:event_id]) authorize! :update, @conference.events.new
@speaker = @event.event_users.where(event_role: 'speaker').first @speaker = @event.event_users.where(event_role: 'speaker').first
end end
def update def update
@event = @conference.events.find(params[:event_id]) authorize! :update, @conference.events.new
@speaker = @event.event_users.where(event_role: 'speaker').first @speaker = @event.event_users.where(event_role: 'speaker').first
@speaker.user_id = params[:speaker][:user_id] @speaker.user_id = params[:speaker][:user_id]
@speaker.save @speaker.save

View file

@ -1,6 +1,11 @@
module Admin module Admin
class SponsorsController < ApplicationController class SponsorsController < ApplicationController
before_filter :verify_organizer load_and_authorize_resource :conference, find_by: :short_title
authorize_resource :sponsor, through: :conference
def index
authorize! :index, Sponsor.new(conference_id: @conference.id)
end
def update def update
if @conference.update_attributes(params[:conference]) if @conference.update_attributes(params[:conference])

View file

@ -1,6 +1,11 @@
module Admin module Admin
class SponsorshipLevelsController < ApplicationController class SponsorshipLevelsController < ApplicationController
before_filter :verify_organizer load_and_authorize_resource :conference, find_by: :short_title
authorize_resource through: :conference
def index
authorize! :index, SponsorshipLevel.new(conference_id: @conference.id)
end
def update def update
if @conference.update_attributes(params[:conference]) if @conference.update_attributes(params[:conference])

View file

@ -1,6 +1,7 @@
module Admin module Admin
class StatsController < ApplicationController class StatsController < ApplicationController
before_filter :verify_organizer load_and_authorize_resource
load_and_authorize_resource :conference, find_by: :short_title
def index def index
@registrations = @conference.registrations.includes(:user) @registrations = @conference.registrations.includes(:user)

View file

@ -1,6 +1,11 @@
module Admin module Admin
class SupporterLevelsController < ApplicationController class SupporterLevelsController < ApplicationController
before_filter :verify_organizer load_and_authorize_resource :conference, find_by: :short_title
authorize_resource through: :conference
def index
authorize! :update, SupporterLevel.new(conference_id: @conference.id)
end
def show def show
render :supporter_levels render :supporter_levels

View file

@ -1,6 +1,7 @@
module Admin module Admin
class SupportersController < ApplicationController class SupportersController < ApplicationController
before_filter :verify_organizer load_and_authorize_resource :conference, find_by: :short_title
load_and_authorize_resource through: :conference
def index def index
respond_to do |format| respond_to do |format|

View file

@ -1,11 +1,15 @@
module Admin module Admin
class TargetsController < ApplicationController class TargetsController < ApplicationController
before_filter :verify_organizer load_and_authorize_resource :conference, find_by: :short_title
authorize_resource through: :conference
def index def index
authorize! :index, Target.new(conference_id: @conference.id)
end end
def update def update
authorize! :update, @conference => Target
if @conference.update_attributes(params[:conference]) if @conference.update_attributes(params[:conference])
redirect_to(admin_conference_targets_path( redirect_to(admin_conference_targets_path(
conference_id: @conference.short_title), conference_id: @conference.short_title),

View file

@ -1,6 +1,11 @@
module Admin module Admin
class TracksController < ApplicationController class TracksController < ApplicationController
before_filter :verify_organizer load_and_authorize_resource :conference, find_by: :short_title
authorize_resource through: :conference
def index
authorize! :index, Track.new(conference_id: @conference.id)
end
def show def show
respond_to do |format| respond_to do |format|

View file

@ -1,6 +1,7 @@
module Admin module Admin
class UsersController < ApplicationController class UsersController < ApplicationController
before_filter :verify_admin load_and_authorize_resource
def new def new
@user = User.new @user = User.new
end end
@ -10,34 +11,37 @@ module Admin
end end
def show def show
@user = User.find(params[:id])
# Variable @show_attributes holds the attributes that are visible for the 'show' action # Variable @show_attributes holds the attributes that are visible for the 'show' action
# If you want to change the attributes that are shown in the 'show' action of users # If you want to change the attributes that are shown in the 'show' action of users
# add/remove the attributes in the following string array # add/remove the attributes in the following string array
@show_attributes = %w(name email affiliation biography registered attended created_at @show_attributes = %w(name email affiliation biography registered attended roles created_at
updated_at sign_in_count current_sign_in_at last_sign_in_at updated_at sign_in_count current_sign_in_at last_sign_in_at
current_sign_in_ip last_sign_in_ip) current_sign_in_ip last_sign_in_ip)
end end
def update def update
user = User.find(params[:id]) params[:user].delete :roles_attributes if params[:user]
user.update_attributes!(params[:user]) @user.update_attributes!(params[:user])
redirect_to admin_users_path, notice: "Updated #{user.email}" redirect_to admin_users_path, notice: "Updated #{@user.email}"
end
def add_role
role = params[:user][:roles_attributes][:"0"]
@user.add_role role['name'].parameterize.underscore.to_sym, Conference.find(role['resource_id'])
respond_to do |format|
format.html
format.js
end
end end
def edit def edit
@user = User.find(params[:id])
end
def delete
@user = User.find(params[:id])
end end
def destroy def destroy
@user = User.find(params[:id])
@user.destroy @user.destroy
redirect_to admin_users_path, notice: 'User got deleted' redirect_to admin_users_path, notice: "User #{@user.name} (#{@user.email})got deleted"
end end
end end
end end

View file

@ -1,6 +1,7 @@
module Admin module Admin
class VenueController < ApplicationController class VenueController < ApplicationController
before_filter :verify_organizer load_and_authorize_resource :conference, find_by: :short_title
load_and_authorize_resource :venue, through: :conference, singleton: true
def index def index
end end

View file

@ -1,26 +1,37 @@
module Admin module Admin
class VolunteersController < ApplicationController class VolunteersController < ApplicationController
load_and_authorize_resource :conference, find_by: :short_title
def index def index
@conference = Conference.find_by(short_title: params[:conference_id]) if (current_user.has_role? :organizer, @conference) || (current_user.has_role? :volunteer_coordinator, @conference)
render :index render :index
else
authorize! :index, :volunteer
end
end end
def show def show
@conference = Conference.find_by(short_title: params[:conference_id]) if (current_user.has_role? :organizer, @conference) || (current_user.has_role? :volunteer_coordinator, @conference)
if @conference.use_vpositions if @conference.use_vpositions
@volunteers = @conference.registrations.joins(:vchoices).uniq @volunteers = @conference.registrations.joins(:vchoices).uniq
else
@volunteers = @conference.registrations.where(:volunteer => true)
end
else else
@volunteers = @conference.registrations.where(volunteer: true) authorize! :index, :volunteer
end end
end end
def update def update
@conference = Conference.find_by(short_title: params[:conference_id]) if (current_user.has_role? :organizer, @conference) || (current_user.has_role? :volunteer_coordinator, @conference)
begin begin
@conference.update_attributes!(params[:conference]) @conference.update_attributes!(params[:conference])
redirect_to(admin_conference_volunteers_info_path(conference_id: params[:conference_id]), notice: "Volunteering options were successfully updated.") redirect_to(admin_conference_volunteers_info_path(:conference_id => params[:conference_id]), :notice => "Volunteering options were successfully updated.")
rescue => e rescue Exception => e
redirect_to(admin_conference_volunteers_info_path(conference_id: params[:conference_id]), alert: "Volunteering options update failed: #{e.message}") redirect_to(admin_conference_volunteers_info_path(:conference_id => params[:conference_id]), :alert => "Volunteering options update failed: #{e.message}")
end
else
authorize! :index, :volunteer
end end
end end
end end

View file

@ -3,14 +3,17 @@ class ApplicationController < ActionController::Base
protect_from_forgery protect_from_forgery
before_filter :get_conferences before_filter :get_conferences
before_filter :store_location before_filter :store_location
before_filter :verify_user_admin
helper_method :date_string helper_method :date_string
# Ensure every controller authorizes resource or skips authorization (skip_authorization_check)
check_authorization unless: :devise_controller?
def store_location def store_location
session[:return_to] = request.fullpath if request.get? && controller_name != "user_sessions" && controller_name != "sessions" session[:return_to] = request.fullpath if request.get? && controller_name != "user_sessions" && controller_name != "sessions"
end end
def after_sign_in_path_for(resource) def after_sign_in_path_for(resource)
if organizer_or_admin? && if (can? :view, Conference) &&
(!session[:return_to] || (!session[:return_to] ||
session[:return_to] && session[:return_to] &&
session[:return_to] == root_path) session[:return_to] == root_path)
@ -31,6 +34,16 @@ class ApplicationController < ActionController::Base
@conferences =Conference.all @conferences =Conference.all
end end
def verify_user_admin
if self.class.to_s.split('::').first == 'Admin' && verify_user
unless (current_user.has_role? :organizer, :any) || (current_user.has_role? :cfp, :any) ||
(current_user.has_role? :info_desk, :any) ||
(current_user.has_role? :volunteers_coordinator, :any) || current_user.is_admin
raise CanCan::AccessDenied.new('You are not authorized to access this area!')
end
end
end
def verify_user def verify_user
:authenticate_user! :authenticate_user!
@ -39,36 +52,17 @@ class ApplicationController < ActionController::Base
return false return false
end end
@conference = Conference.find_by(short_title: params[:conference_id])
true true
end end
def organizer_or_admin? def current_ability
has_role?(current_user, 'admin') || has_role?(current_user, 'organizer') @current_ability ||= Ability.new(current_user)
end
def verify_organizer
if !verify_user
return
end
## Todo simplify this
redirect_to root_path unless has_role?(current_user, 'admin') || has_role?(current_user, 'organizer')
end
def verify_admin
if !verify_user
return
end
redirect_to root_path unless has_role?(current_user, 'admin')
end end
rescue_from CanCan::AccessDenied do |exception| rescue_from CanCan::AccessDenied do |exception|
Rails.logger.debug("Access denied!") Rails.logger.debug("Access denied!")
redirect_to root_path, alert: exception.message redirect_to root_path, alert: exception.message
end end
helper_method :organizer_or_admin?
def not_found def not_found
raise ActionController::RoutingError.new('Not Found') raise ActionController::RoutingError.new('Not Found')

View file

@ -1,10 +1,11 @@
class CommercialsController < ApplicationController class CommercialsController < ApplicationController
before_action :set_conference load_and_authorize_resource :conference, find_by: :short_title
before_action :set_event before_action :set_event
before_action :set_commercial, only: [:edit, :update, :destroy] load_and_authorize_resource through: @event, except: [:new, :create]
def new def new
@commercial = @event.commercials.build @commercial = @event.commercials.build
authorize! :new, @commercial
end end
def edit def edit
@ -12,6 +13,7 @@ class CommercialsController < ApplicationController
def create def create
@commercial = @event.commercials.build(commercial_params) @commercial = @event.commercials.build(commercial_params)
authorize! :create, @commercial
if @commercial.save if @commercial.save
redirect_to edit_conference_proposal_path(conference_id: @conference.short_title, id: @event.id), redirect_to edit_conference_proposal_path(conference_id: @conference.short_title, id: @event.id),
@ -40,14 +42,6 @@ class CommercialsController < ApplicationController
private private
def set_commercial
@commercial = @event.commercials.find(params[:id])
end
def set_conference
@conference = Conference.find_by(short_title: params[:conference_id])
end
def set_event def set_event
@event = @conference.events.find(params[:proposal_id]) @event = @conference.events.find(params[:proposal_id])
end end

View file

@ -1,7 +1,7 @@
class ConferenceController < ApplicationController class ConferenceController < ApplicationController
load_and_authorize_resource find_by: :short_title
def show def show
@conference = Conference.find_by_short_title(params[:id])
redirect_to root_path, notice: "Conference not ready yet!!" unless @conference.make_conference_public?
end end
def subscribe def subscribe
@ -41,7 +41,7 @@ class ConferenceController < ApplicationController
end end
def gallery_photos def gallery_photos
@photos = Conference.find_by_short_title(params[:id]).photos @photos = @conference.photos
render "photos", formats: [:js] render "photos", formats: [:js]
end end
end end

View file

@ -1,9 +1,9 @@
class ConferenceRegistrationController < ApplicationController class ConferenceRegistrationController < ApplicationController
before_filter :verify_user before_filter :verify_user
load_resource :conference, find_by: :short_title
authorize_resource :conference_registration, class: Registration
def register def register
# TODO Figure out how to change the route's id from :id to :conference_id
@conference = Conference.find_by(short_title: params[:id])
@workshops = @conference.events.where('require_registration = ? AND state LIKE ?', @workshops = @conference.events.where('require_registration = ? AND state LIKE ?',
true, 'confirmed') true, 'confirmed')
@user = current_user @user = current_user
@ -23,9 +23,8 @@ class ConferenceRegistrationController < ApplicationController
# TODO this is ugly # TODO this is ugly
def update def update
conference = Conference.find_by(short_title: params[:id])
user = current_user user = current_user
registration = user.registrations.where(conference_id: conference.id).first registration = user.registrations.where(conference_id: @conference.id).first
update_registration = true update_registration = true
# First verify that the supporter code is legit # First verify that the supporter code is legit
if !params[:registration][:supporter_registration_attributes].nil? && if !params[:registration][:supporter_registration_attributes].nil? &&
@ -35,7 +34,7 @@ class ConferenceRegistrationController < ApplicationController
if regs.count != 0 if regs.count != 0
if regs.where(email: user.email).count == 0 if regs.where(email: user.email).count == 0
redirect_to(register_conference_path(id: conference.short_title), redirect_to(conference_register_path(conference_id: @conference.short_title),
alert: "This code is already in use. alert: "This code is already in use.
Please contact #{conference.contact.email} for assistance.") Please contact #{conference.contact.email} for assistance.")
return return
@ -50,7 +49,7 @@ class ConferenceRegistrationController < ApplicationController
supporter_reg = params[:registration][:supporter_registration_attributes] supporter_reg = params[:registration][:supporter_registration_attributes]
params[:registration].delete :supporter_registration_attributes params[:registration].delete :supporter_registration_attributes
registration = user.registrations.new(registration_params) registration = user.registrations.new(registration_params)
if conference.use_supporter_levels? && !supporter_reg.nil? if @conference.use_supporter_levels? && !supporter_reg.nil?
if !supporter_reg[:id].blank? if !supporter_reg[:id].blank?
# Means that their supporter registration was entered ahead of time, by an admin # Means that their supporter registration was entered ahead of time, by an admin
registration.supporter_registration = SupporterRegistration.find(supporter_reg[:id]) registration.supporter_registration = SupporterRegistration.find(supporter_reg[:id])
@ -58,12 +57,12 @@ class ConferenceRegistrationController < ApplicationController
raise 'Invalid code' raise 'Invalid code'
end end
else else
registration.supporter_registration = conference. registration.supporter_registration = @conference.
supporter_registrations.new(registration_params[:supporter_registration_attributes]) supporter_registrations.new(registration_params[:supporter_registration_attributes])
end end
end end
registration.conference_id = conference.id registration.conference_id = @conference.id
registration.save! registration.save!
if user.subscriptions.where(conference: conference).blank? if user.subscriptions.where(conference: conference).blank?
subscription = Subscription.new(conference_id: conference.id, user_id: user.id) subscription = Subscription.new(conference_id: conference.id, user_id: user.id)
@ -74,7 +73,7 @@ class ConferenceRegistrationController < ApplicationController
end end
rescue => e rescue => e
Rails.logger.debug e.backtrace.join('\n') Rails.logger.debug e.backtrace.join('\n')
redirect_to(register_conference_path(id: conference.short_title), redirect_to(conference_register_path(conference_id: @conference.short_title),
alert: 'Registration failed:' + e.message) alert: 'Registration failed:' + e.message)
return return
end end
@ -84,19 +83,18 @@ class ConferenceRegistrationController < ApplicationController
else else
# Track ahoy event # Track ahoy event
ahoy.track 'Registered', title: 'New registration' ahoy.track 'Registered', title: 'New registration'
if conference.email_settings.send_on_registration? if @conference.email_settings.send_on_registration?
Mailbot.delay.registration_mail(conference, current_user) Mailbot.delay.registration_mail(@conference, current_user)
end end
end end
redirect_to(register_conference_path(id: conference.short_title), redirect_to(conference_register_path(conference_id: @conference.short_title),
notice: redirect_message) notice: redirect_message)
end end
def unregister def unregister
conference = Conference.find_by(short_title: params[:id])
user = current_user user = current_user
registration = user.registrations.where(conference_id: conference.id).first registration = user.registrations.where(conference_id: @conference.id).first
subscription = user.subscriptions.where(conference: conference) subscription = user.subscriptions.where(conference: @conference)
unless subscription.blank? unless subscription.blank?
subscription.first.destroy subscription.first.destroy
end end

View file

@ -1,9 +1,11 @@
class EventAttachmentsController < ApplicationController class EventAttachmentsController < ApplicationController
load_and_authorize_resource :conference, find_by: :short_title
load_and_authorize_resource :proposal, class: Event
load_and_authorize_resource :upload, class: EventAttachment, through: :proposal
before_filter :verify_user before_filter :verify_user
skip_before_filter :verify_user, only: [:show] skip_before_filter :verify_user, only: [:show]
def index def index
@proposal = Event.find(params[:proposal_id])
@uploads = @proposal.event_attachments @uploads = @proposal.event_attachments
@uploads = @uploads.map{|upload| upload.to_jq_upload } @uploads = @uploads.map{|upload| upload.to_jq_upload }
@ -14,9 +16,9 @@ class EventAttachmentsController < ApplicationController
end end
def show def show
upload = EventAttachment.find(params[:id])
if upload.public? if @upload.public?
send_file upload.attachment.path send_file @upload.attachment.path
return return
end end
@ -26,7 +28,7 @@ class EventAttachmentsController < ApplicationController
end end
if organizer_or_admin? || current_user == upload.event.submitter if organizer_or_admin? || current_user == upload.event.submitter
send_file upload.attachment.path send_file @upload.attachment.path
else else
raise ActionController::RoutingError.new('Not Found') raise ActionController::RoutingError.new('Not Found')
end end
@ -42,7 +44,6 @@ class EventAttachmentsController < ApplicationController
end end
def edit def edit
@upload = EventAttachment.find(params[:id])
end end
def create def create
@ -50,7 +51,7 @@ class EventAttachmentsController < ApplicationController
params[:event_attachment][:public] = false params[:event_attachment][:public] = false
params[:event_attachment][:event_id] = params[:proposal_id] params[:event_attachment][:event_id] = params[:proposal_id]
if !organizer_or_admin? if cannot? :create, EventAttachment
begin begin
current_user.events.find(params[:proposal_id]) current_user.events.find(params[:proposal_id])
rescue rescue
@ -66,6 +67,7 @@ class EventAttachmentsController < ApplicationController
respond_to do |format| respond_to do |format|
if @upload.save if @upload.save
<<<<<<< HEAD
format.html do format.html do
render json: [@upload.to_jq_upload].to_json, render json: [@upload.to_jq_upload].to_json,
content_type: 'text/html', content_type: 'text/html',
@ -75,6 +77,15 @@ class EventAttachmentsController < ApplicationController
render json: [@upload.to_jq_upload].to_json, status: :created, render json: [@upload.to_jq_upload].to_json, status: :created,
location: conference_proposal_event_attachment_path(@upload.event.conference.short_title, @upload.event, @upload) location: conference_proposal_event_attachment_path(@upload.event.conference.short_title, @upload.event, @upload)
end end
=======
format.html {
render :json => [@upload.to_jq_upload].to_json,
:content_type => 'text/html',
:layout => false
}
format.json { render json: {files: [@upload.to_jq_upload]}, status: :created,
location: conference_proposal_event_attachment_path(@upload.event.conference.short_title, @upload.event, @upload) }
>>>>>>> authorization with cancancan
else else
format.html { render action: "new" } format.html { render action: "new" }
format.json { render json: @upload.errors, status: :unprocessable_entity } format.json { render json: @upload.errors, status: :unprocessable_entity }
@ -83,8 +94,6 @@ class EventAttachmentsController < ApplicationController
end end
def update def update
@proposal = current_user.events.find(params[:proposal_id])
@upload = @proposal.event_attachments.find(params[:proposal_id])
respond_to do |format| respond_to do |format|
if @upload.update_attributes(params[:upload]) if @upload.update_attributes(params[:upload])
@ -98,9 +107,8 @@ class EventAttachmentsController < ApplicationController
end end
def destroy def destroy
@proposal = Event.find(params[:proposal_id])
if organizer_or_admin? || current_user == @proposal.submitter if can? :destroy, @proposal
@upload = @proposal.event_attachments.find(params[:id]) @upload = @proposal.event_attachments.find(params[:id])
end end

View file

@ -1,5 +1,6 @@
class HomeController < ApplicationController class HomeController < ApplicationController
before_filter :respond_to_options before_filter :respond_to_options
skip_authorization_check
def index def index
@today = Date.current @today = Date.current

View file

@ -1,22 +1,19 @@
class ProposalController < ApplicationController class ProposalController < ApplicationController
before_filter :verify_user, except: [:show] before_filter :verify_user, except: [:show]
before_action :set_conference, only: [:show] load_resource :conference, find_by: :short_title
before_action :set_event, only: [:show, :edit, :update, :destroy, :confirm, :restart] load_and_authorize_resource :event, parent: false, through: :conference
def index def index
@events = current_user.proposals(@conference) @events = current_user.proposals(@conference)
end end
def show def show
authorize! :show, @event
# FIXME: We should show more than the first speaker # FIXME: We should show more than the first speaker
@speaker = @event.speakers.first || @event.submitter @speaker = @event.speakers.first || @event.submitter
end end
def new def new
authorize! :new, Event
@url = conference_proposal_index_path(@conference.short_title) @url = conference_proposal_index_path(@conference.short_title)
@event = Event.new
end end
def edit def edit
@ -26,7 +23,6 @@ class ProposalController < ApplicationController
end end
def create def create
authorize! :create, Event
@url = conference_proposal_index_path(@conference.short_title) @url = conference_proposal_index_path(@conference.short_title)
params[:event].delete :user params[:event].delete :user
@ -53,7 +49,7 @@ class ProposalController < ApplicationController
registration = current_user.registrations.where(conference_id: @conference.id).first registration = current_user.registrations.where(conference_id: @conference.id).first
ahoy.track 'Event submission', title: 'New submission' ahoy.track 'Event submission', title: 'New submission'
if registration.nil? if registration.nil?
redirect_to(register_conference_path(@conference.short_title), redirect_to(conference_register_path(@conference.short_title),
alert: 'Event was successfully submitted. alert: 'Event was successfully submitted.
You should register for the conference now.') You should register for the conference now.')
else else
@ -120,7 +116,7 @@ class ProposalController < ApplicationController
end end
if !@conference.user_registered?(current_user) if !@conference.user_registered?(current_user)
redirect_to(register_conference_path(@conference.short_title), redirect_to(conference_register_path(@conference.short_title),
alert: 'The proposal was confirmed. Please register to attend the conference.') alert: 'The proposal was confirmed. Please register to attend the conference.')
return return
end end
@ -149,14 +145,4 @@ class ProposalController < ApplicationController
redirect_to(conference_proposal_index_path(conference_id: @conference.short_title), redirect_to(conference_proposal_index_path(conference_id: @conference.short_title),
notice: "The proposal was re-submitted. The #{@conference.short_title} organizers will review it again.") notice: "The proposal was re-submitted. The #{@conference.short_title} organizers will review it again.")
end end
private
def set_conference
@conference = Conference.find_by(short_title: params[:conference_id])
end
def set_event
@event = Event.find(params[:id])
end
end end

View file

@ -1,4 +1,8 @@
class ScheduleController < ApplicationController class ScheduleController < ApplicationController
<<<<<<< HEAD
=======
authorize_resource class: false
>>>>>>> authorization with cancancan
layout "application" layout "application"
def index def index

View file

@ -1,6 +1,7 @@
module Users module Users
class OmniauthCallbacksController < Devise::OmniauthCallbacksController class OmniauthCallbacksController < Devise::OmniauthCallbacksController
skip_before_filter :verify_authenticity_token skip_before_filter :verify_authenticity_token
skip_authorization_check
User.omniauth_providers.each do |provider| User.omniauth_providers.each do |provider|
define_method(provider) { handle(provider) } define_method(provider) { handle(provider) }

View file

@ -137,14 +137,6 @@ module ApplicationHelper
render "shared/dynamic_association", association_name: association_name, title: title, f: form_builder, hint: options[:hint] render "shared/dynamic_association", association_name: association_name, title: title, f: form_builder, hint: options[:hint]
end end
def has_role?(current_user, role)
if current_user.nil?
return false
end
return !!current_user.role?(role.to_s.camelize)
end
# Same as redirect_to(:back) if there is a valid HTTP referer, otherwise redirect_to() # Same as redirect_to(:back) if there is a valid HTTP referer, otherwise redirect_to()
def redirect_back_or_to(options = {}, response_status = {}) def redirect_back_or_to(options = {}, response_status = {})
if request.env["HTTP_REFERER"] if request.env["HTTP_REFERER"]

View file

@ -2,16 +2,144 @@ class Ability
include CanCan::Ability include CanCan::Ability
def initialize(user) def initialize(user)
# guest user (not logged in) # The first argument to `can` is the action you are giving the user permission to do.
user ||= User.new # If you pass :manage it will apply to every action. Other common actions here are
if user.admin? || user.organizer? # :read, :create, :update and :destroy.
# An admin can manage everything #
can :manage, :all # The second argument is the resource the user can perform the action on. If you pass
# :all it will apply to every resource. Otherwise pass a Ruby class of the resource.
#
# The third argument is an optional hash of conditions to further filter the objects.
# For example, here the user can only update published articles.
#
# can :update, Article, :published => true
#
# See the wiki for details: https://github.com/ryanb/cancan/wiki/Defining-Abilities
# Order Abilities
# (Check https://github.com/CanCanCommunity/cancancan/wiki/Ability-Precedence)
# Check roles of user, using rolify. Role name is *case sensitive*
# user.is_organizer? or user.has_role? :organizer
# user.is_cfp_of? Conference or user.has_role? :cfp, Conference
# user.is_info_desk_of? Conference
# user.is_volunteer_coordinator_of? Conference
# user.is_attendee_of? Conference
# The following is wrong because a user will only have 'cfp' role for a specific conference
# user.is_cfp? # This is always false
user ||= User.new # guest user (not logged in)
if user.new_record?
guest(user)
else else
can [:update, :destroy], Event do |event| roles = Role::ACTIONABLES.map {|i| i.parameterize.underscore}
event.users.include?(user) if (user.roles.pluck(:name) & roles).empty? && !user.is_admin # User has no roles
signed_in(user)
else
user_with_roles(user)
end end
can [:create, :read], Event
end end
end end
def user_with_roles(user)
conf_ids_for_organizer = []
venue_ids_for_organizer = []
conf_ids_for_cfp = []
venue_ids_for_cfp = []
conf_ids_for_info_desk = []
conf_ids_for_volunteer_coordinator = []
# Ids of all the conferences for which the user has an 'organizer' role
conf_ids_for_organizer =
Conference.with_role(:organizer, user).pluck(:id) if user.has_role? :organizer, :any
venue_ids_for_organizer =
Conference.with_role(:organizer, user).pluck(:venue_id) if user.has_role? :organizer, :any
conf_ids_for_cfp =
Conference.with_role(:cfp, user).pluck(:id) if user.has_role? :cfp, :any
venue_ids_for_cfp =
Conference.with_role(:cfp, user).pluck(:venue_id) if user.has_role? :cfp, :any
# Ids of all the conferences for which the user has an 'info_desk' role
conf_ids_for_info_desk =
Conference.with_role(:info_desk, user).pluck(:id) if user.has_role? :info_desk, :any
# Ids of all the conferences for which the user has a 'volunteer_coordinator' role
conf_ids_for_volunteer_coordinator =
Conference.with_role(:volunteer_coordinator, user).pluck(:id) if user.has_role? :volunteer_coordinator, :any
signed_in(user) # Inherit abilities from signed user
# User with role
can :manage, User if user.is_admin # ??? || (user.has_role? :organizer, :any)
can [:new, :create], Conference if user.is_admin || (user.has_role? :organizer, :any)
can [:index, :show, :gallery_photos], Conference
can :manage, Conference, id: conf_ids_for_organizer
# can :manage, Conference do |conference|
# conference.id = conf_ids_for_organizer
# end
can :manage, Venue, id: venue_ids_for_organizer
can :index, Venue, id: venue_ids_for_cfp
can :manage, Registration, conference_id: conf_ids_for_organizer + conf_ids_for_info_desk
can :manage, Question, conference_id: conf_ids_for_organizer + conf_ids_for_info_desk
can :manage, Vposition, conference_id: conf_ids_for_organizer + conf_ids_for_volunteer_coordinator
can :manage, Vday, conference_id: conf_ids_for_organizer + conf_ids_for_volunteer_coordinator
# The ability to manage an Event means that:
# the user can also edit the schedule and that
# the user can also vote
can :manage, Event, conference_id: conf_ids_for_organizer + conf_ids_for_cfp
can :create, Event
can :manage, CallForPapers, conference_id: conf_ids_for_organizer + conf_ids_for_cfp
can :manage, EventType, conference_id: conf_ids_for_organizer + conf_ids_for_cfp
can :manage, Track, conference_id: conf_ids_for_organizer + conf_ids_for_cfp
can :manage, DifficultyLevel, conference_id: conf_ids_for_organizer + conf_ids_for_cfp
can :manage, EmailSettings, conference_id: conf_ids_for_organizer + conf_ids_for_cfp
can :manage, Campaign, conference_id: conf_ids_for_organizer
can :manage, Lodging, venue_id: venue_ids_for_organizer
can :manage, Photo, conference_id: conf_ids_for_organizer
can :manage, Room, conference_id: conf_ids_for_organizer + conf_ids_for_cfp
can :manage, Sponsor, conference_id: conf_ids_for_organizer
can :manage, SponsorshipLevel, conference_id: conf_ids_for_organizer
can :manage, SupporterLevel, conference_id: conf_ids_for_organizer
can :manage, Target, conference_id: conf_ids_for_organizer
can :manage, Commercial#, commercialable_type: 'Conference', commercialable_id: conf_ids_for_organizer
can :index, Commercial, commercialable_type: 'Conference'
# Manage commercials for events that belong to a conference of which user is organizer
can :manage, Commercial, commercialable_type: 'Event', commercialable_id: Event.where(conference_id: conf_ids_for_organizer + conf_ids_for_cfp).pluck(:id)
can :manage, Contact, conference_id: conf_ids_for_organizer
can :manage, Campaign, conference_id: conf_ids_for_organizer
end
def guest(user)
## Abilities for everyone, even guests (not logged in users)
can [:show, :gallery_photos], Conference do |conference|
conference.make_conference_public == true
end
can :show, Event do |event|
event.state == 'confirmed'
end
can :index, :schedule # show?
end
def signed_in(user)
guest(user) # Inherits abilities of guest
# Conference Registration
can :manage, Registration, user_id: user.id
## Proposals
# Users can manage their own proposals
can :manage, Event, id: user.events.pluck(:id)
# Submit proposals only for conferences that are not over yet
can :create, Event, conference_id: Conference.where('end_date >= ?', Date.today).pluck(:id)
# Users can manage their own commercials
can :manage, Commercial, commercialable_type: 'Event', commercialable_id: user.events.pluck(:id)
# View commercials of confirmed events
can :show, Commercial, commercialable_type: 'Event', commercialable_id: Event.where(state: 'confirmed').pluck(:id)
can :manage, EventAttachment do |ea|
Event.find(ea.event_id).event_users.where(user_id: user.id).present?
end
can :create, EventAttachment
end
end end

View file

@ -1,7 +1,7 @@
class CallForPapers < ActiveRecord::Base class CallForPapers < ActiveRecord::Base
attr_accessible :start_date, :end_date, attr_accessible :start_date, :end_date,
:description, :schedule_changes, :rating, :description, :schedule_changes, :rating,
:schedule_public, :include_cfp_in_splash :schedule_public, :include_cfp_in_splash, :conference_id
belongs_to :conference belongs_to :conference
validates_presence_of :start_date, :end_date validates_presence_of :start_date, :end_date

View file

@ -1,6 +1,6 @@
class Campaign < ActiveRecord::Base class Campaign < ActiveRecord::Base
attr_accessible :name, :utm_source, :utm_medium, :utm_term, attr_accessible :name, :target_ids, :conference_id,
:utm_content, :utm_campaign, :target_ids :utm_source, :utm_medium, :utm_term, :utm_content, :utm_campaign
validates :name, :utm_campaign, presence: true validates :name, :utm_campaign, presence: true

View file

@ -4,6 +4,7 @@
class Conference < ActiveRecord::Base class Conference < ActiveRecord::Base
require 'uri' require 'uri'
serialize :events_per_week, Hash serialize :events_per_week, Hash
resourcify # Needed to call 'Conference.with_role' in /models/ability.rb
attr_accessible :title, :short_title, :timezone, :html_export_path, attr_accessible :title, :short_title, :timezone, :html_export_path,
:start_date, :end_date, :rooms_attributes, :tracks_attributes, :start_date, :end_date, :rooms_attributes, :tracks_attributes,

View file

@ -1,5 +1,5 @@
class DifficultyLevel < ActiveRecord::Base class DifficultyLevel < ActiveRecord::Base
attr_accessible :title, :description, :color attr_accessible :title, :description, :color, :conference_id
belongs_to :conference belongs_to :conference
has_many :events has_many :events

View file

@ -6,6 +6,7 @@ class EventAttachment < ActiveRecord::Base
has_attached_file :attachment, path: ":rails_root/storage/:rails_env/attachments/:id/:style/:basename.:extension" has_attached_file :attachment, path: ":rails_root/storage/:rails_env/attachments/:id/:style/:basename.:extension"
include Rails.application.routes.url_helpers include Rails.application.routes.url_helpers
do_not_validate_attachment_file_type :attachment
def to_jq_upload def to_jq_upload
{ {

View file

@ -1,5 +1,6 @@
class EventType < ActiveRecord::Base class EventType < ActiveRecord::Base
attr_accessible :title, :length, :minimum_abstract_length, :maximum_abstract_length, :color attr_accessible :title, :length, :minimum_abstract_length, :maximum_abstract_length, :color,
:conference_id
belongs_to :conference belongs_to :conference

View file

@ -1,5 +1,5 @@
class Lodging < ActiveRecord::Base class Lodging < ActiveRecord::Base
attr_accessible :name, :description, :photo, :website_link attr_accessible :name, :description, :photo, :website_link, :venue_id
belongs_to :venue belongs_to :venue
has_attached_file :photo, has_attached_file :photo,
styles: { thumb: '100x100>', large: '300x300>' } styles: { thumb: '100x100>', large: '300x300>' }

View file

@ -1,5 +1,5 @@
class Question < ActiveRecord::Base class Question < ActiveRecord::Base
attr_accessible :title, :global, :answers_attributes, :answer_ids, :question_type_id attr_accessible :title, :global, :answers_attributes, :answer_ids, :question_type_id, :conference_id
belongs_to :question_type belongs_to :question_type
has_and_belongs_to_many :conferences has_and_belongs_to_many :conferences

View file

@ -1,4 +1,10 @@
class Role < ActiveRecord::Base class Role < ActiveRecord::Base
attr_accessible :name attr_accessible :name, :description
has_and_belongs_to_many :users has_and_belongs_to_many :users
belongs_to :resource, polymorphic: true
scopify
LABELS = ['Attendee', 'Volunteer', 'Speaker', 'Sponsor', 'Press', 'Keynote Speaker']
ACTIONABLES = ['Organizer', 'CfP', 'Info Desk', 'Volunteers Coordinator']
end end

View file

@ -1,5 +1,5 @@
class Room < ActiveRecord::Base class Room < ActiveRecord::Base
attr_accessible :name, :size, :public attr_accessible :name, :size, :public, :conference_id
belongs_to :conference belongs_to :conference
has_many :events has_many :events

View file

@ -1,6 +1,5 @@
class Sponsor < ActiveRecord::Base class Sponsor < ActiveRecord::Base
attr_accessible :name, :description, :website_url, :logo, attr_accessible :name, :description, :website_url, :logo, :sponsorship_level_id, :conference_id
:sponsorship_level_id
belongs_to :sponsorship_level belongs_to :sponsorship_level
belongs_to :conference belongs_to :conference
has_attached_file :logo, has_attached_file :logo,

View file

@ -1,5 +1,5 @@
class SponsorshipLevel < ActiveRecord::Base class SponsorshipLevel < ActiveRecord::Base
attr_accessible :title attr_accessible :title, :conference_id
validates_presence_of :title validates_presence_of :title
belongs_to :conference belongs_to :conference
has_many :sponsors has_many :sponsors

View file

@ -2,5 +2,5 @@ class SupporterLevel < ActiveRecord::Base
belongs_to :conference belongs_to :conference
has_many :supporter_registrations has_many :supporter_registrations
attr_accessible :conference, :title, :url, :description, :ticket_price attr_accessible :conference, :title, :url, :description, :ticket_price, :conference_id
end end

View file

@ -1,7 +1,7 @@
class Target < ActiveRecord::Base class Target < ActiveRecord::Base
include ActionView::Helpers::TextHelper include ActionView::Helpers::TextHelper
attr_accessible :due_date, :target_count, :unit attr_accessible :due_date, :target_count, :unit, :conference_id
default_scope { order('due_date ASC') } default_scope { order('due_date ASC') }

View file

@ -1,5 +1,5 @@
class Track < ActiveRecord::Base class Track < ActiveRecord::Base
attr_accessible :name, :description, :color attr_accessible :name, :description, :color, :conference_id
belongs_to :conference belongs_to :conference

View file

@ -1,7 +1,10 @@
class User < ActiveRecord::Base class User < ActiveRecord::Base
rolify
include Gravtastic include Gravtastic
gravtastic size: 32 gravtastic size: 32
before_create :setup_role
# Include default devise modules. Others available are: # Include default devise modules. Others available are:
# :token_authenticatable, :confirmable, # :token_authenticatable, :confirmable,
# :lockable, :timeoutable and :omniauthable # :lockable, :timeoutable and :omniauthable
@ -13,7 +16,7 @@ class User < ActiveRecord::Base
has_many :openids has_many :openids
attr_accessible :email, :password, :password_confirmation, :remember_me, :role_id, :role_ids, attr_accessible :email, :password, :password_confirmation, :remember_me, :role_id, :role_ids,
:name, :email_public, :biography, :nickname, :affiliation :name, :email_public, :biography, :nickname, :affiliation, :is_admin
has_many :event_users, dependent: :destroy has_many :event_users, dependent: :destroy
has_many :events, -> { uniq }, through: :event_users has_many :events, -> { uniq }, through: :event_users
@ -23,8 +26,6 @@ class User < ActiveRecord::Base
has_many :subscriptions, dependent: :destroy has_many :subscriptions, dependent: :destroy
accepts_nested_attributes_for :roles accepts_nested_attributes_for :roles
before_create :setup_role
validates :name, presence: true validates :name, presence: true
# Searches for user based on email. Returns found user or new user. # Searches for user based on email. Returns found user or new user.
@ -47,26 +48,24 @@ class User < ActiveRecord::Base
user user
end end
def role?(role)
Rails.logger.debug('Checking role in user')
!!roles.find_by_name(role.to_s.downcase.camelize)
end
def admin?
role?('Admin')
end
def organizer?
role?('Organizer')
end
def get_roles def get_roles
roles roles
end end
def setup_role def setup_role
roles << Role.where(name: 'Admin') if User.count == 0 self.is_admin = true if User.count == 0
roles << Role.where(name: 'Participant') if roles.empty? end
# Gets the roles of the user, groups them by role.name and returns the resource(s) of each role
# ====Returns
# * +Hash+ * -> e.g. 'organizer' => "(conf1, conf2)"
def show_roles
result = {}
Role::ACTIONABLES.each do |role|
resources = self.roles.where(name: role.parameterize.underscore).map{ |myrole| Conference.find(myrole.resource_id).short_title }.join ', '
result[role.parameterize.underscore] = "(#{ resources })" unless resources.blank?
end
result
end end
def self.prepare(params) def self.prepare(params)

View file

@ -14,8 +14,11 @@
= commercial.commercial_type = commercial.commercial_type
.flexvideo .flexvideo
= render partial: 'shared/media_item', locals: { commercial_type: commercial.commercial_type, commercial_id: commercial.commercial_id } = render partial: 'shared/media_item', locals: { commercial_type: commercial.commercial_type, commercial_id: commercial.commercial_id }
= link_to 'Edit', edit_admin_conference_commercial_path(@conference.short_title, commercial.id), class: 'btn btn-primary' - if can? :update, commercial
= link_to 'Delete', admin_conference_commercial_path(@conference.short_title, commercial.id), = link_to 'Edit', edit_admin_conference_commercial_path(@conference.short_title, commercial.id), class: 'btn btn-primary'
method: :delete, data: { confirm: 'Are you sure?' }, class: 'btn btn-danger' - if can? :destroy, commercial
%br = link_to 'Delete', admin_conference_commercial_path(@conference.short_title, commercial.id),
method: :delete, data: { confirm: 'Are you sure?' }, class: 'btn btn-danger'
- if can? :create, @conference.commercials.new
%br
= link_to 'New Commercial', new_admin_conference_commercial_path, class: 'btn btn-primary' = link_to 'New Commercial', new_admin_conference_commercial_path, class: 'btn btn-primary'

View file

@ -0,0 +1,29 @@
.roles{ id: 'myroles' }
- unless @role.blank?
%p.text-muted
= @role.first.description
%hr
.row
.col-md-6
= semantic_form_for(:user, url: add_user_admin_conference_path(@conference.short_title, role: @selected), remote: true) do |f|
%h4
= f.input :email, label: "Add role '#{@selected}' to user: ", placeholder: "User's email"
= f.action :submit, as: :button, label: "Add User", button_html: {value: 'Add', class: 'btn btn-primary'}
.row
.col-md-12
%h3 Users with role #{@selected}
%table.table.table-striped.table-bordered.table-hover
%thead
%th ID
%th Name
%th Email
%tbody
- @role_users[@selection].each do |user|
%tr
%td
= link_to remove_user_admin_conference_path(@conference.short_title, user: user, role: @selected), method: :delete, remote: true, title: 'Remove user' do
%i{class: 'fa fa-times'}
= user.id
%td= user.name
%td= user.email

View file

@ -8,25 +8,49 @@
= conference_progress['process'] + '%' = conference_progress['process'] + '%'
%li{'class'=>class_for_todo(conference_progress['registration'])} %li{'class'=>class_for_todo(conference_progress['registration'])}
%span{'class'=>icon_for_todo(conference_progress['registration'])} %span{'class'=>icon_for_todo(conference_progress['registration'])}
= link_to 'Set up registration period', edit_admin_conference_path(conference_progress['short_title'], :anchor => 'conference-end-datepicker') - if can? :update, @conference.registrations.build
= link_to 'Set up registration period', edit_admin_conference_path(conference_progress['short_title'], :anchor => 'conference-end-datepicker')
- else
Set up registration period
%li{'class'=>class_for_todo(conference_progress['cfp'])} %li{'class'=>class_for_todo(conference_progress['cfp'])}
%span{'class'=>icon_for_todo(conference_progress['cfp'])} %span{'class'=>icon_for_todo(conference_progress['cfp'])}
= link_to 'Set up call for papers', admin_conference_callforpapers_path(conference_progress['short_title']) - if can? :update, CallForPapers.new(conference_id: @conference.id)
= link_to 'Set up call for papers', admin_conference_callforpapers_path(conference_progress['short_title'])
- else
Set up call for papers
%li{'class'=>class_for_todo(conference_progress['venue'])} %li{'class'=>class_for_todo(conference_progress['venue'])}
%span{'class'=>icon_for_todo(conference_progress['venue'])} %span{'class'=>icon_for_todo(conference_progress['venue'])}
= link_to 'Add venue', admin_conference_venue_info_path(conference_progress['short_title']) - if can? :update, @conference.venue
= link_to 'Add venue', admin_conference_venue_info_path(conference_progress['short_title'])
- else
Add venue
%li{'class'=>class_for_todo(conference_progress['rooms'])} %li{'class'=>class_for_todo(conference_progress['rooms'])}
%span{'class'=>icon_for_todo(conference_progress['rooms'])} %span{'class'=>icon_for_todo(conference_progress['rooms'])}
= link_to 'Add rooms', admin_conference_rooms_path(conference_progress['short_title']) - if can? :update, @conference.rooms.build
= link_to 'Add rooms', admin_conference_rooms_path(conference_progress['short_title'])
- else
Add rooms
%li{'class'=>class_for_todo(conference_progress['tracks'])} %li{'class'=>class_for_todo(conference_progress['tracks'])}
%span{'class'=>icon_for_todo(conference_progress['tracks'])} %span{'class'=>icon_for_todo(conference_progress['tracks'])}
= link_to 'Add tracks', admin_conference_tracks_path(conference_progress['short_title']) - if can? :update, @conference.tracks.build
= link_to 'Add tracks', admin_conference_tracks_path(conference_progress['short_title'])
- else
Add tracks
%li{'class'=>class_for_todo(conference_progress['event_types'])} %li{'class'=>class_for_todo(conference_progress['event_types'])}
%span{'class'=>icon_for_todo(conference_progress['event_types'])} %span{'class'=>icon_for_todo(conference_progress['event_types'])}
= link_to 'Add event types', admin_conference_eventtypes_path(conference_progress['short_title']) - if can? :update, @conference.event_types.build
= link_to 'Add event types', admin_conference_event_types_path(conference_progress['short_title'])
- else
Add event types
%li{'class'=>class_for_todo(conference_progress['difficulty_levels'])} %li{'class'=>class_for_todo(conference_progress['difficulty_levels'])}
%span{'class'=>icon_for_todo(conference_progress['difficulty_levels'])} %span{'class'=>icon_for_todo(conference_progress['difficulty_levels'])}
= link_to 'Add difficulty levels', admin_conference_difficulty_levels_path(conference_progress['short_title']) - if can? :update, @conference.difficulty_levels.build
= link_to 'Add difficulty levels', admin_conference_difficulty_levels_path(conference_progress['short_title'])
- else
Add difficulty levels
%li{class: class_for_todo(conference_progress['make_conference_public'])} %li{class: class_for_todo(conference_progress['make_conference_public'])}
%span{'class'=>icon_for_todo(conference_progress['make_conference_public'])} %span{'class'=>icon_for_todo(conference_progress['make_conference_public'])}
= link_to 'Make Splash Page Public for Visitors', edit_admin_conference_path(conference_progress['short_title']) - if can? :update, @conference
= link_to 'Make Splash Page Public for Visitors', edit_admin_conference_path(conference_progress['short_title'])
- else
Make Splash Page Public for Visitors

View file

@ -0,0 +1,22 @@
.row
.col-md-6
= semantic_form_for(:user, url: roles_admin_conference_path(@conference.short_title), remote: true) do |f|
%h4
= f.input :roles, collection: @roles, label: 'Show users for role: '
= render partial: 'roles'
:javascript
$("#user_roles_input").change(function () {
var url = document.forms[0].action;
var selected_role = $(this).find('option:selected').attr('value');
$.ajax({
url: url,
type: "POST",
data: {user: { roles: selected_role } },
dataType: "script"
});
});

View file

@ -0,0 +1 @@
$('#myroles').html("<%= escape_javascript(render partial: 'roles').html_safe %>");

View file

@ -1,5 +1,5 @@
.row .row
.col-md-8 .col-md-8
= semantic_form_for(@conference, url: admin_conference_eventtypes_path(@conference.short_title, @conference.event_types)) do |f| = semantic_form_for(@conference, url: admin_conference_event_types_path(@conference.short_title, @conference.event_types)) do |f|
= dynamic_association :event_types, "Event Types", f = dynamic_association :event_types, "Event Types", f
= f.action :submit, :as => :button, :button_html => {:class => "btn btn-primary"} = f.action :submit, :as => :button, :button_html => {:class => "btn btn-primary"}

View file

@ -18,11 +18,11 @@
= ',' = ','
= label_tag dom_id(q), "Answers: #{q.answers.map {|a| a.title}.join(', ')}" = label_tag dom_id(q), "Answers: #{q.answers.map {|a| a.title}.join(', ')}"
%td= link_to 'Edit', edit_admin_conference_question_path(@conference.short_title, q), - if can? :update, q
class: 'btn btn-primary', %td= link_to 'Edit', edit_admin_conference_question_path(@conference.short_title, q),
disabled: q.global == true && !has_role?(current_user, 'Admin') class: 'btn btn-primary', disabled: q.global == true
%td= link_to 'Delete', admin_conference_question_path(@conference.short_title, q), - if can? :destroy, q
method: :delete, remote: true, class: 'btn btn-danger', %td= link_to 'Delete', admin_conference_question_path(@conference.short_title, q),
confirm: "Delete question '#{q.title}'?", method: :delete, remote: true, class: 'btn btn-danger',
disabled: q.global == true && !has_role?(current_user, "Admin") confirm: "Delete question '#{q.title}'?", disabled: q.global == true

View file

@ -7,9 +7,11 @@
= "(#{@registrations.length})" = "(#{@registrations.length})"
= " - Attended (#{@attended})" = " - Attended (#{@attended})"
.btn-group.pull-right .btn-group.pull-right
= link_to "New", new_admin_conference_registration_path(@conference.short_title), :class => "btn btn-default" - if can? :create, Registration
= link_to "Export PDF", admin_conference_registrations_path(@conference.short_title, :format => :pdf), :class => "btn btn-default" = link_to "New", new_admin_conference_registration_path(@conference.short_title), :class => "btn btn-default"
= link_to "Export XLS", {:format => :xlsx}, :class => "btn btn-default" - if can? :read, Registration
= link_to "Export PDF", admin_conference_registrations_path(@conference.short_title, :format => :pdf), :class => "btn btn-default"
= link_to "Export XLS", {:format => :xlsx}, :class => "btn btn-default"
%table.table.table-bordered.table-striped.table-hover#registrations %table.table.table-bordered.table-striped.table-hover#registrations
%thead %thead
%th %th

View file

@ -1,8 +1,14 @@
= semantic_form_for [:admin, @user] do |f| = semantic_form_for [:admin, @user] do |f|
= f.inputs "Basic Information" do = f.inputs 'Basic Information' do
= f.input :is_admin, hint: 'An admin can create a new conference, manage users and make other users admins.'
= f.input :name, :as => :string = f.input :name, :as => :string
= f.input :email = f.input :email
= f.input :affiliation, :as => :string = f.input :affiliation, as: :string
= f.input :biography, :input_html => {:rows => 10} = f.input :biography, input_html: { rows: 5, "onkeyup" => "word_count(this, 'biography-count', 150)" }
= f.actions do You have used
= f.action :submit, :button_html => {:class => "btn btn-primary"} %span#biography-count #{@user.biography_word_count}
words. Biographies are limited to 150 words.
%br
%br
= f.actions do
= f.action :submit, button_html: { class: 'btn btn-primary' }

View file

@ -5,7 +5,7 @@
- if @users - if @users
= "(#{@users.length})" = "(#{@users.length})"
= link_to "New User", new_admin_user_path, :class => "btn btn-success pull-right" = link_to "New User", new_admin_user_path, class: 'btn btn-success pull-right'
.well .well
%table.table.table-striped.table-bordered.table-hover#users %table.table.table-striped.table-bordered.table-hover#users
%thead %thead
@ -18,7 +18,7 @@
%th %th
%b Name %b Name
%th %th
%b # of Conference Registrations %b Attended Conferences
%th %th
%b Roles %b Roles
%th %th
@ -38,39 +38,24 @@
%td %td
= user.name = user.name
%td %td
= user.registrations.count = user.registrations.where(attended: true).count
%td %td
.modal.fade{:id => "user-role-selection-#{user.id}", "role" => "dialog", "aria-hidden" => "true"} - unless user.show_roles.blank?
.modal-dialog = user.show_roles.first(2).map { |x| x[0].titleize + ' ' + x[1] }.join ', '
.modal-content - if user.show_roles.count > 2
.modal-header = '...'
%button{"type"=>"button", :class=>"close", "data-dismiss"=>"modal", "aria-hidden"=>"true"} - if can? :show, user
× %td
%h3{:id => "role-selector-header-#{user.id}"} = link_to "View", admin_user_path(user), class: 'btn btn-success'
Modifying Roles - if can? :update, user
.modal-body %td
- if current_user == user = link_to "Edit", edit_admin_user_path(user), class: 'btn btn-primary'
You cannot modify your own role! - if can? :destroy, user
%br %td
%button{:class=> "btn btn-danger", "data-dismiss"=> "modal", "aria-hidden"=>"true"} - if current_user.id == user.id or user.role_ids.include? 3
Cancel =link_to 'Delete',admin_user_path(user), :method => :delete , :data => {:confirm => 'Are you sure ?'}, :disabled => true,:class => "btn btn-primary disabled btn-danger",:role => "button"
- else - else
= "Give #{user.name} (#{user.email}) the following roles:" =link_to 'Delete',admin_user_path(user), :method=> :delete , :data=> {:confirm => 'Are you sure ?'},:class => "btn btn-primary btn-danger"
= semantic_form_for(user, :url => admin_user_path(user), :method => :put) do |f|
= f.input :roles, :label => false
%button{:class=> "btn btn-danger", "data-dismiss"=> "modal", "aria-hidden"=>"true"}
Cancel
= f.action :submit, :as => :button, :button_html => {:value => "Save", :class => "btn btn-primary"}
=link_to "#{user.roles.map { |role| role.name }.join ', '}", "#", "data-toggle" => "modal", "data-target" => "#user-role-selection-#{user.id}",id: "user-modify-role-#{user.id}"
%td
= link_to "Edit", edit_admin_user_path(user)
%td
= link_to "View", admin_user_path(user)
%td
- if current_user.id == user.id or user.role_ids.include? 3
=link_to 'Delete',admin_user_path(user), :method => :delete , :data => {:confirm => 'Are you sure ?'}, :disabled => true,:class => "btn btn-primary disabled btn-danger",:role => "button"
- else
=link_to 'Delete',admin_user_path(user), :method=> :delete , :data=> {:confirm => 'Are you sure ?'},:class => "btn btn-primary btn-danger"
:javascript :javascript

View file

@ -1,7 +1,11 @@
%table.table %table.table
- @show_attributes.each do |attr| - @show_attributes.each do |attr|
%tr %tr
%td %td{style: 'width:20%'}
%b %b
= attr.capitalize.gsub('_', ' ') = attr.capitalize.gsub('_', ' ')
%td= @user.send(attr) - if attr == 'roles'
%td
= @user.show_roles.map { |x| x[0].titleize + ' ' + x[1] }.join ', '
- else
%td= @user.send(attr)

View file

@ -13,7 +13,7 @@
-else -else
%h4 Registration is Closed, it was from #{ date_string(@conference.registration_start_date, @conference.registration_end_date) } %h4 Registration is Closed, it was from #{ date_string(@conference.registration_start_date, @conference.registration_end_date) }
- if @conference.registration_open? - if @conference.registration_open?
= link_to "Register for #{@conference.short_title}", register_conference_path(@conference.short_title), :class =>"btn btn-success btn-lg", target: '_blank' = link_to "Register for #{@conference.short_title}", conference_register_path(@conference.short_title), :class =>"btn btn-success btn-lg", target: '_blank'
- if @conference.use_supporter_levels? - if @conference.use_supporter_levels?
- if @conference.include_tickets_in_splash? - if @conference.include_tickets_in_splash?
= render 'tickets' = render 'tickets'

View file

@ -1,6 +1,6 @@
.row .row
.col-md-12 .col-md-12
= semantic_form_for(@registration, :url => register_conference_path(@conference.short_title), :html => { :method => :patch }) do |f| = semantic_form_for(@registration, :url => conference_register_path(@conference.short_title), :html => { :method => :patch }) do |f|
.tabbable .tabbable
%ul.nav.nav-tabs %ul.nav.nav-tabs
%li.active %li.active
@ -16,7 +16,7 @@
= render 'conference_registration/volunteer', :f => f = render 'conference_registration/volunteer', :f => f
- if @registered - if @registered
= f.action :submit, :button_html => { :value => "Update Registration", :class => "btn btn-primary" } = f.action :submit, :button_html => { :value => "Update Registration", :class => "btn btn-primary" }
= link_to "Unregister", register_conference_path(@conference.short_title),:method => :delete, :class => "btn btn-danger", = link_to "Unregister", conference_register_path(@conference.short_title),:method => :delete, :class => "btn btn-danger",
:confirm => "Are you sure you want to unregister?" :confirm => "Are you sure you want to unregister?"
- else - else
= f.action :submit, :button_html => { :value => "Register", :class => "btn btn-primary", id: 'register' } = f.action :submit, :button_html => { :value => "Register", :class => "btn btn-primary", id: 'register' }

View file

@ -31,9 +31,9 @@
= link_to "View Conference", conference_path(conference.short_title), :class =>"btn btn-default" = link_to "View Conference", conference_path(conference.short_title), :class =>"btn btn-default"
- if conference.registration_open? - if conference.registration_open?
- if conference.user_registered?(current_user) - if conference.user_registered?(current_user)
= link_to "Modify Registration", register_conference_path(conference.short_title), :class =>"btn btn-default" = link_to "Modify Registration", conference_register_path(conference.short_title), :class =>"btn btn-default"
- else - else
= link_to "Register", register_conference_path(conference.short_title), :class =>"btn btn-success" = link_to "Register", conference_register_path(conference.short_title), :class =>"btn btn-success"
= link_to "Schedule", conference_schedule_path(conference.short_title), :class =>"btn btn-default" if conference.call_for_papers and conference.call_for_papers.schedule_public = link_to "Schedule", conference_schedule_path(conference.short_title), :class =>"btn btn-default" if conference.call_for_papers and conference.call_for_papers.schedule_public
- if !current_user.nil? && current_user.proposal_count(conference) > 0 - if !current_user.nil? && current_user.proposal_count(conference) > 0
= link_to "View My Proposals", conference_proposal_index_path(conference.short_title), :class =>"btn btn-default" = link_to "View My Proposals", conference_proposal_index_path(conference.short_title), :class =>"btn btn-default"

View file

@ -10,97 +10,129 @@
%span.glyphicon.glyphicon-home %span.glyphicon.glyphicon-home
All Conferences All Conferences
- @conferences.each do |conference| - @conferences.each do |conference|
- if can? :show, conference
%li
= link_to(admin_conference_path(conference.short_title)) do
%span.glyphicon.glyphicon-cog
Manage
= conference.short_title
- if (current_user.is_admin) || (current_user.has_role? :organizer, :any)
%li %li
= link_to(admin_conference_path(conference.short_title)) do = link_to(new_admin_conference_path) do
%span.glyphicon.glyphicon-cog %span.glyphicon.glyphicon-plus
Manage New Conference
= conference.short_title
%li
= link_to(new_admin_conference_path) do
%span.glyphicon.glyphicon-plus
New Conference
%hr %hr
%li{:class=> "#{active_nav_li(admin_conference_path(@conference.short_title))} nav-header nav-header-bigger"} - if can? :show, @conference
= link_to(admin_conference_path(@conference.short_title)) do %li{:class=> "#{active_nav_li(admin_conference_path(@conference.short_title))} nav-header nav-header-bigger"}
%span.fa.fa-tachometer = link_to(admin_conference_path(@conference.short_title)) do
Dashboard %span.fa.fa-tachometer
%li{:class=> "#{active_nav_li(edit_admin_conference_path(@conference.short_title))}"} Dashboard
= link_to(edit_admin_conference_path(@conference.short_title)) do - if can? :update, @conference
%span.fa.fa-home %li{:class=> "#{active_nav_li(edit_admin_conference_path(@conference.short_title))}"}
Basics = link_to(edit_admin_conference_path(@conference.short_title)) do
%ul %span.fa.fa-home
%li{:class=> "#{active_nav_li(edit_admin_conference_contact_path(@conference.short_title))}"} Basics
= link_to(edit_admin_conference_contact_path(@conference.short_title)) do - if can? :update, Contact.new(conference_id: @conference.id)
%span.fa.fa-envelope-o %ul
Contact %li{:class=> "#{active_nav_li(edit_admin_conference_contact_path(@conference.short_title))}"}
%li{:class=> "#{active_nav_li(admin_conference_commercials_path(@conference.short_title))}"} = link_to(edit_admin_conference_contact_path(@conference.short_title)) do
= link_to(admin_conference_commercials_path(@conference.short_title)) do %span.fa.fa-envelope-o
%span.fa.fa-film Contact
Commercials - if can? :index, @conference.commercials.build
%li{:class=> "#{active_nav_li(admin_conference_photos_path(@conference.short_title))}"} %li{:class=> "#{active_nav_li(admin_conference_commercials_path(@conference.short_title))}"}
= link_to(admin_conference_photos_path(@conference.short_title)) do = link_to(admin_conference_commercials_path(@conference.short_title)) do
%span.fa.fa-picture-o %span.fa.fa-film
Photos Commercials
%li{:class=> active_nav_li(admin_conference_events_path(@conference.short_title))} - if can? :update, @conference.photos.build
= link_to(admin_conference_events_path(@conference.short_title)) do %li{:class=> "#{active_nav_li(admin_conference_photos_path(@conference.short_title))}"}
%span.glyphicon.glyphicon-comment = link_to(admin_conference_photos_path(@conference.short_title)) do
Events %span.fa.fa-picture-o
%li{:class=> active_nav_li(admin_conference_registrations_path(@conference.short_title))} Photos
= link_to(admin_conference_registrations_path(@conference.short_title)) do - if can? :update, @conference.events.build
%span.glyphicon.glyphicon-user %li{:class=> active_nav_li(admin_conference_events_path(@conference.short_title))}
Registrations = link_to(admin_conference_events_path(@conference.short_title)) do
%li{class: active_nav_li(admin_conference_schedule_path(@conference.short_title))} %span.glyphicon.glyphicon-comment
= link_to(admin_conference_schedule_path(@conference.short_title), target: '_blank') do Events
%span.glyphicon.glyphicon-calendar - if can? :update, Registration.new(conference_id: @conference.id)
Schedule %li{:class=> active_nav_li(admin_conference_registrations_path(@conference.short_title))}
%li{class: active_nav_li(admin_conference_campaigns_path(@conference.short_title))} = link_to(admin_conference_registrations_path(@conference.short_title)) do
= link_to(admin_conference_campaigns_path(@conference.short_title)) do %span.glyphicon.glyphicon-user
%span.glyphicon.glyphicon-bullhorn Registrations
Campaigns - if can? :update, @conference.events.build
%li{class: active_nav_li(admin_conference_schedule_path(@conference.short_title))}
= link_to(admin_conference_schedule_path(@conference.short_title), target: '_blank') do
%span.glyphicon.glyphicon-calendar
Schedule
- if can? :update, @conference
%li{class: active_nav_li(admin_conference_campaigns_path(@conference.short_title))}
= link_to(admin_conference_campaigns_path(@conference.short_title)) do
%span.glyphicon.glyphicon-bullhorn
Campaigns
%hr %hr
%li{:class=> "#{active_nav_li(admin_conference_targets_path(@conference.short_title))}"} - if can? :update, @conference
= link_to(admin_conference_targets_path(@conference.short_title)) do %li{:class=> "#{active_nav_li(edit_admin_conference_path(@conference.short_title))} nav-header nav-header-bigger"}
%span.glyphicon.glyphicon-flag = link_to(edit_admin_conference_path(@conference.short_title)) do
Targets %span.glyphicon.glyphicon-cog
%li{:class=> "#{active_nav_li(admin_conference_venue_info_path(@conference.short_title))} myAccordion"} Settings
= link_to(admin_conference_venue_info_path(@conference.short_title)) do - if can? :update, @conference.targets.build
%span.glyphicon.glyphicon-road %li{:class=> "#{active_nav_li(admin_conference_targets_path(@conference.short_title))}"}
Venue = link_to(admin_conference_targets_path(@conference.short_title)) do
%span.small.glyphicon.glyphicon-chevron-right %span.glyphicon.glyphicon-flag
%ul.nav.nav-stacked.nav-pills.small.collapse.subNav Targets
%li{:class=> active_nav_li(admin_conference_rooms_path(@conference.short_title))} - if can? :index, @conference.venue
= link_to 'Rooms', admin_conference_rooms_path(@conference.short_title) %li{:class=> "#{active_nav_li(admin_conference_venue_info_path(@conference.short_title))} myAccordion"}
%li{ class: active_nav_li(admin_conference_lodgings_path(@conference.short_title)) } = link_to(admin_conference_venue_info_path(@conference.short_title)) do
= link_to 'Lodgings', admin_conference_lodgings_path(@conference.short_title) %span.glyphicon.glyphicon-road
%li{:class=> "#{active_nav_li(admin_conference_sponsorship_levels_path(@conference.short_title))} myAccordion" } Venue
= link_to(admin_conference_sponsorship_levels_path(@conference.short_title)) do %span.small.glyphicon.glyphicon-chevron-right
%span.glyphicon.glyphicon-star %ul.nav.nav-stacked.nav-pills.small.collapse.subNav
Sponsorship - if can? :update, @conference.rooms.build
%span.small.glyphicon.glyphicon-chevron-right %li{:class=> active_nav_li(admin_conference_rooms_path(@conference.short_title))}
%ul.nav.nav-stacked.nav-pills.small.collapse.subNav = link_to 'Rooms', admin_conference_rooms_path(@conference.short_title)
%li{:class=> active_nav_li(admin_conference_sponsors_path(@conference.short_title))} - if can? :update, @conference.venue.lodgings.build
= link_to 'Sponsors', admin_conference_sponsors_path(@conference.short_title) %li{ class: active_nav_li(admin_conference_lodgings_path(@conference.short_title)) }
%li{ class: active_nav_li(admin_conference_supporter_levels_path(@conference.short_title)) } = link_to 'Lodgings', admin_conference_lodgings_path(@conference.short_title)
= link_to(admin_conference_supporter_levels_path(@conference.short_title)) do - if can? :update, @conference.sponsorship_levels.build
%span.glyphicon.glyphicon-usd %li{:class=> "#{active_nav_li(admin_conference_sponsorship_levels_path(@conference.short_title))} myAccordion" }
Supporter Levels = link_to(admin_conference_sponsorship_levels_path(@conference.short_title)) do
%li{:class=> active_nav_li(admin_conference_emails_path(@conference.short_title))} %span.glyphicon.glyphicon-star
= link_to(admin_conference_emails_path(@conference.short_title)) do Sponsorship
%span.glyphicon.glyphicon-envelope %span.small.glyphicon.glyphicon-chevron-right
E-Mails %ul.nav.nav-stacked.nav-pills.small.collapse.subNav
%li{:class=> "#{active_nav_li(admin_conference_callforpapers_path(@conference.short_title))} myAccordion"} - if can? :update, @conference.sponsors.build
= link_to(admin_conference_callforpapers_path(@conference.short_title)) do %li{:class=> active_nav_li(admin_conference_sponsors_path(@conference.short_title))}
%span.glyphicon.glyphicon-comment = link_to 'Sponsors', admin_conference_sponsors_path(@conference.short_title)
Call for papers - if can? :update, @conference.supporter_levels.build
%span.small.glyphicon.glyphicon-chevron-right %li{ class: active_nav_li(admin_conference_supporter_levels_path(@conference.short_title)) }
%ul.nav.nav-stacked.nav-pills.small.collapse.subNav = link_to(admin_conference_supporter_levels_path(@conference.short_title)) do
%li{:class=> active_nav_li(admin_conference_tracks_path(@conference.short_title))} %span.glyphicon.glyphicon-usd
= link_to 'Tracks', admin_conference_tracks_path(@conference.short_title) Supporter Levels
%li{:class=> active_nav_li(admin_conference_eventtypes_path(@conference.short_title))} - if can? :update, @conference.email_settings
= link_to 'Event types', admin_conference_eventtypes_path(@conference.short_title) %li{:class=> active_nav_li(admin_conference_emails_path(@conference.short_title))}
%li{:class=> active_nav_li(admin_conference_difficulty_levels_path(@conference.short_title))} = link_to(admin_conference_emails_path(@conference.short_title)) do
= link_to 'Difficulty levels', admin_conference_difficulty_levels_path(@conference.short_title) %span.glyphicon.glyphicon-envelope
E-Mails
- if can? :update, CallForPapers.new(conference_id: @conference.id)
%li{:class=> "#{active_nav_li(admin_conference_callforpapers_path(@conference.short_title))} myAccordion"}
= link_to(admin_conference_callforpapers_path(@conference.short_title)) do
%span.glyphicon.glyphicon-comment
Call for papers
%span.small.glyphicon.glyphicon-chevron-right
%ul.nav.nav-stacked.nav-pills.small.collapse.subNav
- if can? :update, @conference.tracks.build
%li{:class=> active_nav_li(admin_conference_tracks_path(@conference.short_title))}
= link_to 'Tracks', admin_conference_tracks_path(@conference.short_title)
- if can? :update, @conference.event_types.build
%li{:class=> active_nav_li(admin_conference_event_types_path(@conference.short_title))}
= link_to 'Event types', admin_conference_event_types_path(@conference.short_title)
- if can? :update, @conference.difficulty_levels.build, conference_id: @conference.id
%li{:class=> active_nav_li(admin_conference_difficulty_levels_path(@conference.short_title))}
= link_to 'Difficulty levels', admin_conference_difficulty_levels_path(@conference.short_title)
- if can? :update, Question.new(conference_id: @conference.id)
%li{:class=> active_nav_li(admin_conference_questions_path(@conference.short_title))} %li{:class=> active_nav_li(admin_conference_questions_path(@conference.short_title))}
= link_to(admin_conference_questions_path(@conference.short_title)) do = link_to(admin_conference_questions_path(@conference.short_title)) do
%span.glyphicon.glyphicon-question-sign %span.glyphicon.glyphicon-question-sign
Questions Questions
- if can? :manage, @conference
%li{:class=> active_nav_li(roles_admin_conference_path(@conference.short_title))}
= link_to 'Roles', roles_admin_conference_path(@conference.short_title)

View file

@ -10,17 +10,20 @@
%span.glyphicon.glyphicon-home %span.glyphicon.glyphicon-home
All Conferences All Conferences
- @conferences.each do |conference| - @conferences.each do |conference|
- if can? :show, conference
%li
= link_to(admin_conference_path(conference.short_title)) do
%span.glyphicon.glyphicon-cog
Manage
= conference.short_title
- if (current_user.is_admin) || (current_user.has_role? :organizer, :any)
%li %li
= link_to(admin_conference_path(conference.short_title)) do = link_to(new_admin_conference_path) do
%span.glyphicon.glyphicon-cog %span.glyphicon.glyphicon-plus
Manage New Conference
= conference.short_title - if can? :index, User
%li %hr
= link_to(new_admin_conference_path) do %li
%span.glyphicon.glyphicon-plus = link_to(admin_users_path) do
New Conference %span.glyphicon.glyphicon-user
%hr Users
%li
= link_to(admin_users_path) do
%span.glyphicon.glyphicon-user
Users

View file

@ -11,13 +11,13 @@
= link_to(destroy_user_session_path, :method=>'delete') do = link_to(destroy_user_session_path, :method=>'delete') do
%span.glyphicon.glyphicon-minus %span.glyphicon.glyphicon-minus
Sign out Sign out
-if has_role?(current_user, "admin") || has_role?(current_user, "organizer") - if can? :index, Conference
%li.divider %li.divider
%li %li
= link_to(admin_conference_index_path()) do = link_to(admin_conference_index_path()) do
%span.glyphicon.glyphicon-home %span.glyphicon.glyphicon-home
Administration Administration
-if @conference and @conference.id -if @conference and @conference.id and can? :show, @conference
%li %li
= link_to(admin_conference_path(@conference.short_title)) do = link_to(admin_conference_path(@conference.short_title)) do
%span.glyphicon.glyphicon-cog %span.glyphicon.glyphicon-cog

View file

@ -26,11 +26,14 @@
= commercial.commercial_type = commercial.commercial_type
.flexvideo .flexvideo
= render partial: 'shared/media_item', locals: { commercial_type: commercial.commercial_type, commercial_id: commercial.commercial_id } = render partial: 'shared/media_item', locals: { commercial_type: commercial.commercial_type, commercial_id: commercial.commercial_id }
= link_to 'Edit', edit_conference_proposal_commercial_path(@conference.short_title, @event.id, commercial.id), class: 'btn btn-primary' - if can? :update, commercial
= link_to 'Delete', conference_proposal_commercial_path(@conference.short_title, @event.id, commercial.id), = link_to 'Edit', edit_conference_proposal_commercial_path(@conference.short_title, @event.id, commercial.id), class: 'btn btn-primary'
- if can? :destrooy, commercial
= link_to 'Delete', conference_proposal_commercial_path(@conference.short_title, @event.id, commercial.id),
:method => :delete, :data => { :confirm => 'Are you sure?' }, class: 'btn btn-danger' :method => :delete, :data => { :confirm => 'Are you sure?' }, class: 'btn btn-danger'
%hr - if can? :create, @event.commercials.new
= link_to 'Add Commercial', new_conference_proposal_commercial_path(@conference.short_title, @event.id), class: 'btn btn-primary' %hr
= link_to 'Add Commercial', new_conference_proposal_commercial_path(@conference.short_title, @event.id), class: 'btn btn-primary'
#attachment-content.tab-pane #attachment-content.tab-pane
= form_for EventAttachment.new, :url => conference_proposal_event_attachment_index_path(@conference.short_title, @event), :html => { :multipart => true, :id => "fileupload" } do |f| = form_for EventAttachment.new, :url => conference_proposal_event_attachment_index_path(@conference.short_title, @event), :html => { :multipart => true, :id => "fileupload" } do |f|
@ -68,7 +71,7 @@
data.formData = inputs.serializeArray(); data.formData = inputs.serializeArray();
}); });
$.getJSON($('#fileupload').prop('action'), function (files) { $.getJSON($('#fileupload').prop('action'), function (files) {
var fu = $('#fileupload').data('fileupload'), var fu = $('#fileupload').data('blueimpFileupload'),
template; template;
fu._adjustMaxNumberOfFiles(-files.length); fu._adjustMaxNumberOfFiles(-files.length);
template = fu._renderDownload(files) template = fu._renderDownload(files)

View file

@ -1,20 +1,20 @@
= semantic_form_for(@event, :url => @url) do |f| = semantic_form_for(@event, :url => @url) do |f|
%section#basic %section#basic
= f.inputs :name => "Session Information" do = f.inputs :name => "Session Information" do
- if !@conference.call_for_papers.schedule_changes && @event.state == "confirmed" && !organizer_or_admin? - if can? :update, @event or can? :create, @event
= f.input :title, :as => :string, :required => true
- else
Title: #{@event.title} Title: #{@event.title}
%br %br
%br %br
- else
= f.input :title, :as => :string, :required => true
= f.input :subtitle, :as => :string = f.input :subtitle, :as => :string
%section#details %section#details
- if (@event.state === "unconfirmed" || @event.state === "confirmed") && !organizer_or_admin? && !@conference.call_for_papers.schedule_changes - if can? :update, @event or can? :create, @event
= f.input :event_type_id,:as => :select, :collection => @conference.event_types.map {|x| ["#{x.title} - #{show_time(x.length)}", x.id]}, :include_blank => false, :label => "Session Type"
- else
Event type: #{@event.event_type.title} Event type: #{@event.event_type.title}
%br %br
%br %br
- else
= f.input :event_type_id,:as => :select, :collection => @conference.event_types.map {|x| ["#{x.title} - #{show_time(x.length)}", x.id]}, :include_blank => false, :label => "Session Type"
= f.input :difficulty_level, :as => :select, :collection => @conference.difficulty_levels, :include_blank => "(Please select)" if @conference.use_difficulty_levels = f.input :difficulty_level, :as => :select, :collection => @conference.difficulty_levels, :include_blank => "(Please select)" if @conference.use_difficulty_levels
= f.input :require_registration = f.input :require_registration
= f.input :abstract, :input_html => {:rows => 5, :class => "span11"}, = f.input :abstract, :input_html => {:rows => 5, :class => "span11"},

View file

@ -2,7 +2,7 @@
.col-md-12.page-header .col-md-12.page-header
%h1 %h1
= "My Proposals for #{@conference.title}" = "My Proposals for #{@conference.title}"
- if @conference.cfp_open? || organizer_or_admin? - if @conference.cfp_open? || (current_user.has_role? :organizer, @conference)
= link_to "New Proposal", new_conference_proposal_path(@conference.short_title), :class => "btn btn-success pull-right" = link_to "New Proposal", new_conference_proposal_path(@conference.short_title), :class => "btn btn-success pull-right"
- if current_user.proposal_count(@conference) > 0 - if current_user.proposal_count(@conference) > 0
.row .row
@ -27,7 +27,7 @@
(Pre-registered: #{pre_registered(event).count}) (Pre-registered: #{pre_registered(event).count})
- if event.confirmed? && !@conference.user_registered?(current_user) - if event.confirmed? && !@conference.user_registered?(current_user)
%br %br
= link_to "Register to attend", register_conference_path(@conference.short_title), :style => "font-size:10px;" = link_to "Register to attend", conference_register_path(@conference.short_title), :style => "font-size:10px;"
%td %td
.pull-right .pull-right
- if event.transition_possible? :confirm - if event.transition_possible? :confirm

View file

@ -1,6 +1,6 @@
.row .row
.col-md-12 .col-md-12
= simple_format(@conference.call_for_papers.description) = simple_format(@conference.call_for_papers.description) if @conference.call_for_papers
.row .row
.col-md-12 .col-md-12
= render 'proposal_form' = render 'proposal_form'

View file

@ -7,7 +7,7 @@
%small %small
= @event.subtitle = @event.subtitle
= link_to "Schedule", conference_schedule_path(@conference.short_title), :class =>"btn btn-success pull-right" = link_to "Schedule", conference_schedule_path(@conference.short_title), :class =>"btn btn-success pull-right"
- if has_role?(current_user, "admin") - if can? :edit, @event
= link_to "Edit", edit_admin_conference_event_path(@conference.short_title, @event), :class => "btn btn-mini btn-primary pull-right" = link_to "Edit", edit_admin_conference_event_path(@conference.short_title, @event), :class => "btn btn-mini btn-primary pull-right"
.row .row
.col-md-3 .col-md-3
@ -37,7 +37,7 @@
%span.label{:style =>"background-color: #{@event.difficulty_level.color};"} %span.label{:style =>"background-color: #{@event.difficulty_level.color};"}
= @event.difficulty_level.title = @event.difficulty_level.title
- if @event.require_registration - if @event.require_registration
= link_to "Registration required!", register_conference_path(@conference.short_title), :class => "btn btn-xs btn-warning" = link_to "Registration required!", conference_register_path(@conference.short_title), :class => "btn btn-xs btn-warning"
.col-md-9 .col-md-9
.row .row
.col-md-12 .col-md-12

View file

@ -0,0 +1,8 @@
Rolify.configure do |config|
# By default ORM adapter is ActiveRecord. uncomment to use mongoid
# config.use_mongoid
# Dynamic shortcuts for User class (user.is_admin? like methods). Default is: false
# Enable this feature _after_ running rake db:migrate as it relies on the roles table
config.use_dynamic_shortcuts
end

View file

@ -8,8 +8,13 @@ Osem::Application.routes.draw do
resources :users resources :users
resources :people resources :people
resources :conference do resources :conference do
resource :contact, except: [:index, :new, :create, :show, :destroy] member do
resources :photos, except: [:show] get :roles
post :roles
post :add_user
delete :remove_user
end
resource :contact, except: [:index, :new, :create]
resource :schedule, only: [:show, :update] resource :schedule, only: [:show, :update]
resources :commercials, except: [:show] resources :commercials, except: [:show]
get '/stats' => 'stats#index' get '/stats' => 'stats#index'
@ -40,7 +45,7 @@ Osem::Application.routes.draw do
resources :campaigns resources :campaigns
resources :eventtypes, only: [:show, :index] do resources :event_types, only: [:show, :index] do
collection do collection do
patch :update patch :update
end end
@ -92,10 +97,10 @@ Osem::Application.routes.draw do
resource :schedule, only: [] do resource :schedule, only: [] do
get "/" => "schedule#index" get "/" => "schedule#index"
end end
get "/register" => "conference_registration#register"
patch "/register" => "conference_registration#update"
delete "/register" => "conference_registration#unregister"
member do member do
get "/register" => "conference_registration#register"
patch "/register" => "conference_registration#update"
delete "/register" => "conference_registration#unregister"
get "gallery_photos" get "gallery_photos"
patch "subscription" => "conference#subscribe" patch "subscription" => "conference#subscribe"
delete "subscription" => "conference#unsubscribe" delete "subscription" => "conference#unsubscribe"

View file

@ -0,0 +1,10 @@
class AddDescriptionAndResourceToRoles < ActiveRecord::Migration
def change
add_column :roles, :description, :string
add_reference :roles, :resource, polymorphic: true
add_index(:roles, :name)
add_index(:roles, [:name, :resource_type, :resource_id])
add_index(:roles_users, [:user_id, :role_id])
end
end

View file

@ -0,0 +1,5 @@
class AddIsAdminToUsers < ActiveRecord::Migration
def change
add_column :users, :is_admin, :boolean
end
end

View file

@ -363,15 +363,23 @@ ActiveRecord::Schema.define(version: 20140801170430) do
create_table "roles", force: true do |t| create_table "roles", force: true do |t|
t.string "name" t.string "name"
t.string "description"
t.integer "resource_id"
t.string "resource_type"
t.datetime "created_at" t.datetime "created_at"
t.datetime "updated_at" t.datetime "updated_at"
end end
add_index "roles", ["name", "resource_type", "resource_id"], name: "index_roles_on_name_and_resource_type_and_resource_id"
add_index "roles", ["name"], name: "index_roles_on_name"
create_table "roles_users", id: false, force: true do |t| create_table "roles_users", id: false, force: true do |t|
t.integer "role_id" t.integer "role_id"
t.integer "user_id" t.integer "user_id"
end end
add_index "roles_users", ["user_id", "role_id"], name: "index_roles_users_on_user_id_and_role_id"
create_table "rooms", force: true do |t| create_table "rooms", force: true do |t|
t.string "guid", null: false t.string "guid", null: false
t.integer "conference_id" t.integer "conference_id"
@ -484,6 +492,7 @@ ActiveRecord::Schema.define(version: 20140801170430) do
t.string "tshirt" t.string "tshirt"
t.string "languages" t.string "languages"
t.text "volunteer_experience" t.text "volunteer_experience"
t.boolean "is_admin"
end end
add_index "users", ["confirmation_token"], name: "index_users_on_confirmation_token", unique: true add_index "users", ["confirmation_token"], name: "index_users_on_confirmation_token", unique: true

View file

@ -5,18 +5,18 @@
# #
# cities = City.create([{ name: 'Chicago' }, { name: 'Copenhagen' }]) # cities = City.create([{ name: 'Chicago' }, { name: 'Copenhagen' }])
# Mayor.create(name: 'Emanuel', city: cities.first) # Mayor.create(name: 'Emanuel', city: cities.first)
Role.create(name: "Participant")
Role.create(name: "Organizer")
Role.create(name: "Admin")
qtype_yesno = QuestionType.create(title: "Yes/No") # Questions
QuestionType.create(title: "Single Choice") qtype_yesno = QuestionType.create(title: 'Yes/No')
QuestionType.create(title: "Multiple Choice") qtype_single = QuestionType.create(title: 'Single Choice')
qtype_multiple = QuestionType.create(title: 'Multiple Choice')
answer_yes = Answer.create(title: "Yes") answer_yes = Answer.create(title: 'Yes')
answer_no = Answer.create(title: "No") answer_no = Answer.create(title: 'No')
questions_yes_no = ["Do you need handicapped access to the venue?", "Are you attending with partner?", "Will you attend the social event(s)?", "Will you stay at suggested hotel?"] questions_yes_no = ['Do you need handicapped access to the venue?',
'Are you attending with partner?', 'Will you attend the social event(s)?',
'Will you stay at suggested hotel?']
questions_yes_no.each do |i| questions_yes_no.each do |i|
q = Question.create(title: i, question_type_id: qtype_yesno.id, global: true) q = Question.create(title: i, question_type_id: qtype_yesno.id, global: true)

View file

@ -3,16 +3,15 @@ require 'spec_helper'
describe Admin::ConferenceController do describe Admin::ConferenceController do
# It is necessary to use bang version of let to build roles before user # It is necessary to use bang version of let to build roles before user
let!(:organizer_role) { create(:organizer_role) }
let!(:participant_role) { create(:participant_role) }
let!(:admin_role) { create(:admin_role) }
let(:conference) { create(:conference) } let(:conference) { create(:conference) }
let(:admin) { create(:admin) } let!(:first_user) { create(:user) }
let(:organizer) { create(:organizer) } let!(:participant_role) { create(:participant_role) }
let!(:organizer_role) { create(:role, name: 'organizer', resource: conference) }
let(:organizer) { create(:user, role_ids: organizer_role.id, is_admin: true) }
let(:participant) { create(:participant) } let(:participant) { create(:participant) }
shared_examples 'access as administration or organizer' do shared_examples 'access as administration' do
describe 'PATCH #update' do describe 'PATCH #update' do
@ -45,8 +44,7 @@ describe Admin::ConferenceController do
mailer = double mailer = double
allow(mailer).to receive(:deliver) allow(mailer).to receive(:deliver)
conference.email_settings = create(:email_settings) conference.email_settings = create(:email_settings)
patch :update, id: conference.short_title, conference: patch :update, id: conference.short_title#, conference: attributes_for(:conference, start_date: Date.today + 2.days, end_date: Date.today + 4.days)
attributes_for(:conference, start_date: Date.today + 2.days, end_date: Date.today + 4.days)
conference.reload conference.reload
allow(Mailbot).to receive(:conference_date_update_mail).and_return(mailer) allow(Mailbot).to receive(:conference_date_update_mail).and_return(mailer)
end end
@ -193,8 +191,12 @@ describe Admin::ConferenceController do
context 'no conferences' do context 'no conferences' do
it 'redirect to new conference' do it 'redirect to new conference' do
Conference.all.each do |c|
c.destroy
end
sign_in create(:admin)
get :index get :index
expect(response).to redirect_to(redirect_to new_admin_conference_path) expect(response).to redirect_to new_admin_conference_path
end end
end end
end end
@ -215,59 +217,64 @@ describe Admin::ConferenceController do
describe 'administrator access' do describe 'administrator access' do
before do before do
sign_in(admin)
end
it_behaves_like 'access as administration or organizer'
end
describe 'organizer access' do
before(:each) do
sign_in(organizer) sign_in(organizer)
end end
it_behaves_like 'access as administration or organizer' it_behaves_like 'access as administration'
end end
shared_examples 'access as participant or guest' do |success_path| shared_examples 'access as participant or guest' do |path, message|
describe 'GET #show' do describe 'GET #show' do
it 'requires admin privileges' do it 'requires organizer privileges' do
get :show, id: conference.short_title get :show, id: conference.short_title
expect(response).to redirect_to(send(success_path)) expect(response).to redirect_to(send(path))
if message
expect(flash[:alert]).to match(/#{message}/)
end
end end
end end
describe 'GET #index' do describe 'GET #index' do
it 'requires admin privileges' do it 'requires organizer privileges' do
get :index get :index
expect(response).to redirect_to(send(success_path)) expect(response).to redirect_to(send(path))
if message
expect(flash[:alert]).to match(/#{message}/)
end
end end
end end
describe 'GET #new' do describe 'GET #new' do
it 'requires admin privileges' do it 'requires organizer privileges' do
get :new get :new
expect(response).to redirect_to(send(success_path)) expect(response).to redirect_to(send(path))
if message
expect(flash[:alert]).to match(/#{message}/)
end
end end
end end
describe 'POST #create' do describe 'POST #create' do
it 'requires admin privileges' do it 'requires organizer privileges' do
post :create, conference: attributes_for(:conference, post :create, conference: attributes_for(:conference,
short_title: 'ExCon') short_title: 'ExCon')
expect(response).to redirect_to(send(success_path)) expect(response).to redirect_to(send(path))
if message
expect(flash[:alert]).to match(/#{message}/)
end
end end
end end
describe 'PATCH #update' do describe 'PATCH #update' do
it 'requires admin privileges' do it 'requires organizer privileges' do
patch :update, id: conference.short_title, patch :update, id: conference.short_title,
conference: attributes_for(:conference, conference: attributes_for(:conference,
short_title: 'ExCon') short_title: 'ExCon')
expect(response).to redirect_to(send(success_path)) expect(response).to redirect_to(send(path))
if message
expect(flash[:alert]).to match(/#{message}/)
end
end end
end end
end end
@ -277,7 +284,7 @@ describe Admin::ConferenceController do
sign_in(participant) sign_in(participant)
end end
it_behaves_like 'access as participant or guest', :root_path it_behaves_like 'access as participant or guest', :root_path, 'You are not authorized to access this area!'
end end

View file

@ -1,7 +1,5 @@
require 'spec_helper' require 'spec_helper'
describe Admin::UsersController do describe Admin::UsersController do
let!(:admin_role) { create(:admin_role) }
let!(:participant_role) { create(:participant_role) }
let(:admin) { create(:admin) } let(:admin) { create(:admin) }
let(:user) { create(:user) } let(:user) { create(:user) }
before(:each) do before(:each) do
@ -31,7 +29,7 @@ describe Admin::UsersController do
:user, email: 'example@incoherent.de', id: user.id).email). :user, email: 'example@incoherent.de', id: user.id).email).
to eq('example@incoherent.de') to eq('example@incoherent.de')
end end
it "redirects to the updated user" do it 'redirects to the updated user' do
patch :update, id: user.id patch :update, id: user.id
expect(response).to redirect_to admin_users_path expect(response).to redirect_to admin_users_path
end end

View file

@ -1,7 +1,8 @@
require 'spec_helper' require 'spec_helper'
describe ConferenceController do describe ConferenceController do
let(:conference) { create(:conference) } let(:conference) { create(:conference, make_conference_public: true) }
describe 'GET #show' do describe 'GET #show' do
context 'conference made public' do context 'conference made public' do
it 'assigns the requested conference to conference' do it 'assigns the requested conference to conference' do
@ -24,7 +25,7 @@ describe ConferenceController do
it 'renders flash saying conference not ready' do it 'renders flash saying conference not ready' do
get :show, id: conference.short_title get :show, id: conference.short_title
expect(flash[:notice]).to eq("Conference not ready yet!!") expect(flash[:alert]).to eq('You are not authorized to access this page.')
end end
end end
context 'gallery photos for splash' do context 'gallery photos for splash' do

View file

@ -0,0 +1,8 @@
# Read about factories at https://github.com/thoughtbot/factory_girl
FactoryGirl.define do
factory :commercial do
commercial_type 'YouTube'
commercial_id 'test'
end
end

View file

@ -1,16 +1,18 @@
FactoryGirl.define do FactoryGirl.define do
factory :role do factory :role do
factory :admin_role do factory :participant_role do
name 'Admin' name 'participant'
end end
factory :organizer_role do factory :organizer_role do
name 'Organizer' name 'organizer'
end end
factory :participant_role do factory :organizer_conference_1_role do
name 'Participant' name 'organizer'
resource_type 'Conference'
resource_id 1
end end
end end
end end

View file

@ -19,12 +19,12 @@ FactoryGirl.define do
after(:create) { |user| user.role_ids = create(:participant_role).id } after(:create) { |user| user.role_ids = create(:participant_role).id }
end end
factory :admin do factory :organizer_conference_1 do
after(:create) { |user| user.role_ids = create(:admin_role).id } after(:create) { |user| user.role_ids = create(:organizer_conference_1_role).id }
end end
factory :organizer do factory :admin do
after(:create) { |user| user.role_ids = create(:organizer_role).id } is_admin true
end end
end end
end end

View file

@ -0,0 +1,266 @@
require 'spec_helper'
feature 'Has correct abilities' do
# It is necessary to use bang version of let to build roles before user
let(:conference1) { create(:conference) } # user is organizer
let(:conference2) { create(:conference) } # user is cfp
let(:conference3) { create(:conference) } # user is info_desk
let(:conference4) { create(:conference) } # user is volunteer coordinator
let(:conference5) { create(:conference) } # user has no role
let(:role_organizer) { create(:role, name: 'organizer', resource: conference1) }
let(:role_cfp) { create(:role, name: 'cfp', resource: conference2) }
let(:role_info_desk) { create(:role, name: 'info_desk', resource: conference3) }
let(:role_volunteer_coordinator) { create(:role, name: 'volunteer_coordinator', resource: conference4) }
let(:user) { create(:user, role_ids: [role_organizer.id, role_cfp.id, role_info_desk.id, role_volunteer_coordinator.id]) }
scenario 'when user is organizer' do
sign_in user
visit admin_conference_path(conference1.short_title)
expect(page.has_content?('Settings')).to be true
expect(page.has_content?('Manage')).to be true
expect(page.has_content?('Registrations')).to be true
expect(page.has_content?('Events')).to be true
expect(page.has_content?('Schedule')).to be true
expect(page.has_content?('Campaigns')).to be true
expect(page.has_content?('Targets')).to be true
expect(page.has_content?('Venue')).to be true
expect(page.has_content?('Sponsorship')).to be true
expect(page.has_content?('Supporter Levels')).to be true
expect(page.has_content?('E-Mails')).to be true
expect(page.has_content?('Call for papers')).to be true
expect(page.has_content?('Questions')).to be true
expect(page.has_content?('Commercials')).to be true
visit edit_admin_conference_path(conference1.short_title)
expect(current_path).to eq(edit_admin_conference_path(conference1.short_title))
visit admin_conference_path(conference1.short_title)
expect(current_path).to eq(admin_conference_path(conference1.short_title))
visit admin_conference_registrations_path(conference1.short_title)
expect(current_path).to eq(admin_conference_registrations_path(conference1.short_title))
visit admin_conference_events_path(conference1.short_title)
expect(current_path).to eq(admin_conference_events_path(conference1.short_title))
visit admin_conference_schedule_path(conference1.short_title)
expect(current_path).to eq(admin_conference_schedule_path(conference1.short_title))
visit admin_conference_campaigns_path(conference1.short_title)
expect(current_path).to eq(admin_conference_campaigns_path(conference1.short_title))
visit admin_conference_targets_path(conference1.short_title)
expect(current_path).to eq(admin_conference_targets_path(conference1.short_title))
visit admin_conference_venue_info_path(conference1.short_title)
expect(current_path).to eq(admin_conference_venue_info_path(conference1.short_title))
visit admin_conference_sponsorship_levels_path(conference1.short_title)
expect(current_path).to eq(admin_conference_sponsorship_levels_path(conference1.short_title))
visit admin_conference_supporter_levels_path(conference1.short_title)
expect(current_path).to eq(admin_conference_supporter_levels_path(conference1.short_title))
visit admin_conference_emails_path(conference1.short_title)
expect(current_path).to eq(admin_conference_emails_path(conference1.short_title))
visit admin_conference_callforpapers_path(conference1.short_title)
expect(current_path).to eq(admin_conference_callforpapers_path(conference1.short_title))
visit admin_conference_questions_path(conference1.short_title)
expect(current_path).to eq(admin_conference_questions_path(conference1.short_title))
visit admin_conference_commercials_path(conference1.short_title)
expect(current_path).to eq(admin_conference_commercials_path(conference1.short_title))
end
scenario 'when user is cfp' do
sign_in user
visit admin_conference_path(conference2.short_title)
expect(page.has_content?('Settings')).to be false
expect(page.has_content?('Manage')).to be true
# expect(page.has_content?('Registrations')).to be false
expect(page.has_content?('Events')).to be true
expect(page.has_content?('Schedule')).to be true
# expect(page.has_content?('Campaigns')).to be false
expect(page.has_content?('Targets')).to be false
expect(page.has_content?('Venue')).to be true
expect(page.has_content?('Sponsorship')).to be false
expect(page.has_content?('Supporter Levels')).to be false
expect(page.has_content?('E-Mails')).to be true
expect(page.has_content?('Call for papers')).to be true
expect(page.has_content?('Questions')).to be false
expect(page.has_content?('Commercials')).to be true
visit edit_admin_conference_path(conference2.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_path(conference2.short_title)
expect(current_path).to eq(admin_conference_path(conference2.short_title))
visit admin_conference_registrations_path(conference2.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_events_path(conference2.short_title)
expect(current_path).to eq(admin_conference_events_path(conference2.short_title))
visit admin_conference_schedule_path(conference2.short_title)
expect(current_path).to eq(admin_conference_schedule_path(conference2.short_title))
visit admin_conference_campaigns_path(conference2.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_targets_path(conference2.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_venue_info_path(conference2.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_sponsorship_levels_path(conference2.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_supporter_levels_path(conference2.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_emails_path(conference2.short_title)
expect(current_path).to eq(admin_conference_emails_path(conference2.short_title))
visit admin_conference_callforpapers_path(conference2.short_title)
expect(current_path).to eq(admin_conference_callforpapers_path(conference2.short_title))
visit admin_conference_questions_path(conference2.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_commercials_path(conference3.short_title)
expect(current_path).to eq(admin_conference_commercials_path(conference3.short_title))
end
scenario 'when user is info desk' do
sign_in user
visit admin_conference_path(conference3.short_title)
expect(page.has_content?('Settings')).to be false
expect(page.has_content?('Manage')).to be true
expect(page.has_content?('Registrations')).to be true
expect(page.has_content?('Events')).to be false
expect(page.has_content?('Schedule')).to be false
# expect(page.has_content?('Campaigns')).to be false
expect(page.has_content?('Targets')).to be false
expect(page.has_content?('Venue')).to be false
expect(page.has_content?('Sponsorship')).to be false
expect(page.has_content?('Supporter Levels')).to be false
expect(page.has_content?('E-Mails')).to be false
expect(page.has_content?('Call for papers')).to be false
expect(page.has_content?('Questions')).to be true
expect(page.has_content?('Commercials')).to be true
visit edit_admin_conference_path(conference3.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_path(conference3.short_title)
expect(current_path).to eq(admin_conference_path(conference3.short_title))
visit admin_conference_registrations_path(conference3.short_title)
expect(current_path).to eq(admin_conference_registrations_path(conference3.short_title))
visit admin_conference_events_path(conference3.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_schedule_path(conference3.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_campaigns_path(conference3.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_targets_path(conference3.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_venue_info_path(conference3.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_sponsorship_levels_path(conference3.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_supporter_levels_path(conference3.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_emails_path(conference3.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_callforpapers_path(conference3.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_questions_path(conference3.short_title)
expect(current_path).to eq(admin_conference_questions_path(conference3.short_title))
visit admin_conference_commercials_path(conference3.short_title)
expect(current_path).to eq(admin_conference_commercials_path(conference3.short_title))
end
scenario 'when user is volunteer coordinator' do
sign_in user
visit admin_conference_path(conference4.short_title)
expect(page.has_content?('Settings')).to be false
expect(page.has_content?('Manage')).to be true
# expect(page.has_content?('Registrations')).to be false
expect(page.has_content?('Events')).to be false
expect(page.has_content?('Schedule')).to be false
# expect(page.has_content?('Campaigns')).to be false
expect(page.has_content?('Targets')).to be false
expect(page.has_content?('Venue')).to be false
expect(page.has_content?('Sponsorship')).to be false
expect(page.has_content?('Supporter Levels')).to be false
expect(page.has_content?('E-Mails')).to be false
expect(page.has_content?('Call for papers')).to be false
expect(page.has_content?('Questions')).to be false
expect(page.has_content?('Commercials')).to be true
visit edit_admin_conference_path(conference4.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_path(conference4.short_title)
expect(current_path).to eq(admin_conference_path(conference4.short_title))
visit admin_conference_registrations_path(conference4.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_events_path(conference4.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_schedule_path(conference4.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_campaigns_path(conference4.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_targets_path(conference4.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_venue_info_path(conference4.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_sponsorship_levels_path(conference4.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_supporter_levels_path(conference4.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_emails_path(conference4.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_callforpapers_path(conference4.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_questions_path(conference4.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_commercials_path(conference3.short_title)
expect(current_path).to eq(admin_conference_commercials_path(conference3.short_title))
end
end

View file

@ -3,9 +3,8 @@ require 'spec_helper'
feature Campaign do feature Campaign do
# It is necessary to use bang version of let to build roles before user # It is necessary to use bang version of let to build roles before user
let!(:organizer_role) { create(:organizer_role) }
let!(:participant_role) { create(:participant_role) } let!(:participant_role) { create(:participant_role) }
let!(:admin_role) { create(:admin_role) } let!(:organizer_conference_1_role) { create(:organizer_conference_1_role) }
shared_examples 'add and update campaign' do |user| shared_examples 'add and update campaign' do |user|
scenario 'adds and update a campaign', feature: true, js: true do scenario 'adds and update a campaign', feature: true, js: true do
@ -42,7 +41,7 @@ feature Campaign do
expect(Campaign.count).to eq(expected_count) expect(Campaign.count).to eq(expected_count)
campaign = Campaign.where('name'=> 'Test Campaign').first campaign = Campaign.where('name' => 'Test Campaign').first
visit edit_admin_conference_campaign_path(conference.short_title, campaign.id) visit edit_admin_conference_campaign_path(conference.short_title, campaign.id)
fill_in 'campaign_name', with: 'Test Campaign 42' fill_in 'campaign_name', with: 'Test Campaign 42'
@ -52,8 +51,7 @@ feature Campaign do
end end
end end
describe 'admin' do describe 'organizer' do
it_behaves_like 'add and update campaign', :admin it_behaves_like 'add and update campaign', :organizer_conference_1
it_behaves_like 'add and update campaign', :organizer
end end
end end

View file

@ -3,9 +3,8 @@ require 'spec_helper'
feature Conference do feature Conference do
# It is necessary to use bang version of let to build roles before user # It is necessary to use bang version of let to build roles before user
let!(:organizer_role) { create(:organizer_role) }
let!(:participant_role) { create(:participant_role) } let!(:participant_role) { create(:participant_role) }
let!(:admin_role) { create(:admin_role) } let!(:organizer_conference_1_role) { create(:organizer_conference_1_role) }
shared_examples 'add and update cfp' do |user| shared_examples 'add and update cfp' do |user|
scenario 'adds a new cfp', feature: true, js: true do scenario 'adds a new cfp', feature: true, js: true do
@ -87,8 +86,7 @@ feature Conference do
end end
end end
describe 'admin' do describe 'organizer' do
it_behaves_like 'add and update cfp', :admin it_behaves_like 'add and update cfp', :organizer_conference_1
it_behaves_like 'add and update cfp', :organizer
end end
end end

View file

@ -2,18 +2,17 @@ require 'spec_helper'
feature Commercial do feature Commercial do
# It is necessary to use bang version of let to build roles before user # It is necessary to use bang version of let to build roles before user
let!(:organizer_role) { create(:organizer_role) } let!(:conference) { create(:conference) }
let!(:participant_role) { create(:participant_role) } let!(:organizer_role) { create(:role, name: 'organizer', resource: conference) }
let!(:admin_role) { create(:admin_role) } let!(:organizer) { create(:user, role_ids: [organizer_role.id]) }
shared_examples 'adds and updates a commercial' do |user| shared_examples 'adds and updates a commercial' do
scenario 'of a conference', scenario 'of a conference',
feature: true, js: true do feature: true, js: true do
conference = create(:conference)
expected_count = conference.commercials.count + 1 expected_count = conference.commercials.count + 1
sign_in create(user) sign_in organizer
visit admin_conference_commercials_path(conference.short_title) visit admin_conference_commercials_path(conference.short_title)
@ -61,11 +60,7 @@ feature Commercial do
end end
end end
describe 'admin' do
it_behaves_like 'adds and updates a commercial', :admin
end
describe 'organizer' do describe 'organizer' do
it_behaves_like 'adds and updates a commercial', :organizer it_behaves_like 'adds and updates a commercial'
end end
end end

View file

@ -3,9 +3,8 @@ require 'spec_helper'
feature Conference do feature Conference do
# It is necessary to use bang version of let to build roles before user # It is necessary to use bang version of let to build roles before user
let!(:organizer_role) { create(:organizer_role) }
let!(:participant_role) { create(:participant_role) } let!(:participant_role) { create(:participant_role) }
let!(:admin_role) { create(:admin_role) } let!(:organizer_conference_1_role) { create(:organizer_conference_1_role) }
shared_examples 'add and update conference' do |user| shared_examples 'add and update conference' do |user|
scenario 'adds a new conference', feature: true, js: true do scenario 'adds a new conference', feature: true, js: true do
@ -36,7 +35,7 @@ feature Conference do
scenario 'update conference', feature: true, js: true do scenario 'update conference', feature: true, js: true do
conference = create(:conference) conference = create(:conference)
expected_count = Conference.count expected_count = Conference.count
sign_in create(user) sign_in create(:organizer_conference_1)
visit edit_admin_conference_path(conference.short_title) visit edit_admin_conference_path(conference.short_title)
click_link 'Edit' click_link 'Edit'
@ -65,9 +64,4 @@ feature Conference do
describe 'admin' do describe 'admin' do
it_behaves_like 'add and update conference', :admin it_behaves_like 'add and update conference', :admin
end end
describe 'organizer' do
it_behaves_like 'add and update conference', :organizer
end
end end

View file

@ -2,9 +2,8 @@ require 'spec_helper'
feature DifficultyLevel do feature DifficultyLevel do
# It is necessary to use bang version of let to build roles before user # It is necessary to use bang version of let to build roles before user
let!(:organizer_role) { create(:organizer_role) }
let!(:participant_role) { create(:participant_role) } let!(:participant_role) { create(:participant_role) }
let!(:admin_role) { create(:admin_role) } let!(:organizer_conference_1_role) { create(:organizer_conference_1_role) }
shared_examples 'difficulty levels' do |user| shared_examples 'difficulty levels' do |user|
scenario 'adds and updates difficulty level', feature: true, js: true do scenario 'adds and updates difficulty level', feature: true, js: true do
@ -50,11 +49,7 @@ feature DifficultyLevel do
end end
end end
describe 'admin' do
it_behaves_like 'difficulty levels', :admin
end
describe 'organizer' do describe 'organizer' do
it_behaves_like 'difficulty levels', :organizer it_behaves_like 'difficulty levels', :organizer_conference_1
end end
end end

View file

@ -2,9 +2,8 @@ require 'spec_helper'
feature EmailSettings do feature EmailSettings do
# It is necessary to use bang version of let to build roles before user # It is necessary to use bang version of let to build roles before user
let!(:organizer_role) { create(:organizer_role) }
let!(:participant_role) { create(:participant_role) } let!(:participant_role) { create(:participant_role) }
let!(:admin_role) { create(:admin_role) } let!(:organizer_conference_1_role) { create(:organizer_conference_1_role) }
shared_examples 'email settings' do |user| shared_examples 'email settings' do |user|
scenario 'updates email settings', scenario 'updates email settings',
@ -91,11 +90,7 @@ feature EmailSettings do
end end
end end
describe 'admin' do
it_behaves_like 'email settings', :admin
end
describe 'organizer' do describe 'organizer' do
it_behaves_like 'email settings', :organizer it_behaves_like 'email settings', :organizer_conference_1
end end
end end

View file

@ -2,15 +2,14 @@ require 'spec_helper'
feature EventType do feature EventType do
# It is necessary to use bang version of let to build roles before user # It is necessary to use bang version of let to build roles before user
let!(:organizer_role) { create(:organizer_role) }
let!(:participant_role) { create(:participant_role) } let!(:participant_role) { create(:participant_role) }
let!(:admin_role) { create(:admin_role) } let!(:organizer_conference_1_role) { create(:organizer_conference_1_role) }
shared_examples 'event types' do |user| shared_examples 'event types' do |user|
scenario 'adds and updates event type', feature: true, js: true do scenario 'adds and updates event type', feature: true, js: true do
conference = create(:conference) conference = create(:conference)
sign_in create(user) sign_in create(user)
visit admin_conference_eventtypes_path( visit admin_conference_event_types_path(
conference_id: conference.short_title) conference_id: conference.short_title)
expect(page.all('div.nested-fields').count == 2).to be true expect(page.all('div.nested-fields').count == 2).to be true
@ -55,11 +54,7 @@ feature EventType do
end end
end end
describe 'admin' do
it_behaves_like 'event types', :admin
end
describe 'organizer' do describe 'organizer' do
it_behaves_like 'event types', :organizer it_behaves_like 'event types', :organizer_conference_1
end end
end end

View file

@ -2,9 +2,8 @@ require 'spec_helper'
feature Lodging do feature Lodging do
# It is necessary to use bang version of let to build roles before user # It is necessary to use bang version of let to build roles before user
let!(:organizer_role) { create(:organizer_role) }
let!(:participant_role) { create(:participant_role) } let!(:participant_role) { create(:participant_role) }
let!(:admin_role) { create(:admin_role) } let!(:organizer_conference_1_role) { create(:organizer_conference_1_role) }
shared_examples 'lodgings' do |user| shared_examples 'lodgings' do |user|
scenario 'adds and updates lodgings', feature: true, js: true do scenario 'adds and updates lodgings', feature: true, js: true do
@ -56,11 +55,7 @@ feature Lodging do
end end
end end
describe 'admin' do
it_behaves_like 'lodgings', :admin
end
describe 'organizer' do describe 'organizer' do
it_behaves_like 'lodgings', :organizer it_behaves_like 'lodgings', :organizer_conference_1
end end
end end

Some files were not shown because too many files have changed in this diff Show more