ability rework
This commit is contained in:
@@ -2,21 +2,113 @@
|
|||||||
class Ability
|
class Ability
|
||||||
include CanCan::Ability
|
include CanCan::Ability
|
||||||
def initialize(user)
|
def initialize(user)
|
||||||
|
loggedin=!(user.nil?)
|
||||||
user ||= User.new # guest user (not logged in)
|
user ||= User.new # guest user (not logged in)
|
||||||
|
#-----------------------------------------------------
|
||||||
# Rechteverwaltung fuer Studien Modul
|
# Rechteverwaltung fuer Studien Modul
|
||||||
can [:show, :index], Studium
|
can [:show, :index], Studium
|
||||||
can [:show, :index], Modulgruppe
|
can [:show, :index], Modulgruppe
|
||||||
can [:show, :index], Modul
|
can [:show, :index], Modul
|
||||||
can [:show, :index], Lva
|
can [:show, :index], Lva
|
||||||
can [:create, :show], Beispiel
|
can [:create, :show], Beispiel
|
||||||
|
if loggedin
|
||||||
|
can :like, Beispiel
|
||||||
|
can :dislike, Beispiel
|
||||||
|
end
|
||||||
|
if( user.has_role?("fetuser") || user.has_role?("fetadmin"))
|
||||||
|
can :manage, Modulgruppe
|
||||||
|
can :manage, Modul
|
||||||
|
can :manage, Lva
|
||||||
|
can :manage, Studium
|
||||||
|
end
|
||||||
|
unless user.has_role?("fetadmin")
|
||||||
|
cannot :delete, Studium
|
||||||
|
cannot :delete, Modulgruppe
|
||||||
|
cannot :delete, Modul
|
||||||
|
end
|
||||||
|
|
||||||
|
#-----------------------------------------------------
|
||||||
|
# Rechteverwaltung fuer Informationen
|
||||||
|
can [:show, :index,:faqs], Themengruppe, :public=>true
|
||||||
|
can [:show], Thema, :isdraft=>false
|
||||||
|
can :show, Frage
|
||||||
|
if loggedin
|
||||||
|
end
|
||||||
|
if( user.has_role?("fetuser") || user.has_role?("fetadmin"))
|
||||||
|
can :manage, Frage
|
||||||
|
can :showdraft , Thema
|
||||||
|
can :showintern, Thema
|
||||||
|
can :manage, Thema
|
||||||
|
can :manage, Themengruppe
|
||||||
|
end
|
||||||
|
unless user.has_role?("fetadmin")
|
||||||
|
cannot :delete, Themengruppe
|
||||||
|
cannot :delete, Thema
|
||||||
|
end
|
||||||
|
|
||||||
|
#-----------------------------------------------------
|
||||||
|
# Rechteverwaltung fuer Fotos
|
||||||
|
|
||||||
can [:show,:index], Gallery
|
can [:show,:index], Gallery
|
||||||
can [:show, :index,:faqs], Themengruppe
|
if loggedin
|
||||||
can [:show], Thema, :isdraft=>false
|
end
|
||||||
|
if( user.has_role?("fetuser") || user.has_role?("fetadmin"))
|
||||||
|
can :manage, Gallery
|
||||||
|
end
|
||||||
|
unless user.has_role?("fetadmin")
|
||||||
|
cannot :delete, Gallery
|
||||||
|
end
|
||||||
|
|
||||||
|
#-----------------------------------------------------
|
||||||
|
# Rechteverwaltung fuer Mitarbeiter
|
||||||
can [:show, :index], Fetprofile
|
can [:show, :index], Fetprofile
|
||||||
can [:show, :index],Gremium
|
can [:show, :index],Gremium
|
||||||
|
if loggedin
|
||||||
|
end
|
||||||
|
if( user.has_role?("fetuser") || user.has_role?("fetadmin"))
|
||||||
|
can :manage, Fetprofile
|
||||||
|
can :manage, Gremium
|
||||||
|
can :manage, Membership
|
||||||
|
end
|
||||||
|
unless user.has_role?("fetadmin")
|
||||||
|
cannot :delete, Fetprofile
|
||||||
|
cannot :delete ,Gremium
|
||||||
|
end
|
||||||
|
|
||||||
|
#-----------------------------------------------------
|
||||||
|
# Rechteverwaltung fuer Neuigkeiten
|
||||||
|
can [:show,:index], Rubrik, :public=>true
|
||||||
|
can :show, Neuigkeit, :rubrik=>{:public=>true}
|
||||||
|
|
||||||
|
if loggedin
|
||||||
|
end
|
||||||
|
if( user.has_role?("fetuser") || user.has_role?("fetadmin"))
|
||||||
|
can :showintern, Neuigkeit
|
||||||
|
can :showintern, Rubrik
|
||||||
|
can :seeintern, User
|
||||||
|
can :shownonpublic, Rubrik
|
||||||
|
|
||||||
|
end
|
||||||
|
if user.has_role?("newsadmin") || user.has_role?("fetadmin")
|
||||||
|
can :addmoderator, Rubrik
|
||||||
|
end
|
||||||
|
if user.has_role?("fetadmin")
|
||||||
|
can :addfetuser, User
|
||||||
|
can :addfetadmin, User
|
||||||
|
end
|
||||||
|
|
||||||
|
if user.has_role?("newsadmin") || user.has_role?( "fetadmin") || user.has_role?( "fetuser")
|
||||||
|
can :manage, Rubrik
|
||||||
|
can :manage, Neuigkeit
|
||||||
|
can :showunpublished, Neuigkeit
|
||||||
|
end
|
||||||
|
unless user.has_role?("fetadmin")
|
||||||
|
cannot :delete, Rubrik
|
||||||
|
cannot :delete, Neuigkeit
|
||||||
|
|
||||||
|
end
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
# Rechteverwaltung Kalender
|
# Rechteverwaltung Kalender
|
||||||
can [:show, :index], Calendar, :public => true
|
can [:show, :index], Calendar, :public => true
|
||||||
@@ -24,12 +116,8 @@ class Ability
|
|||||||
can [:show], Calentry
|
can [:show], Calentry
|
||||||
|
|
||||||
if( user.has_role?("fetuser") || user.has_role?("fetadmin"))
|
if( user.has_role?("fetuser") || user.has_role?("fetadmin"))
|
||||||
can :manage,:all
|
|
||||||
can :manage, Modulgruppe
|
|
||||||
can :showdraft , Thema
|
|
||||||
can :showintern, Thema
|
|
||||||
can :showintern, Neuigkeit
|
|
||||||
can :showintern, Rubrik
|
|
||||||
can [:show,:index], Calendar
|
can [:show,:index], Calendar
|
||||||
can [:edit, :update,:new,:create,:verwalten], Calendar
|
can [:edit, :update,:new,:create,:verwalten], Calendar
|
||||||
can [:edit, :update,:new,:create,:verwalten], Calentry
|
can [:edit, :update,:new,:create,:verwalten], Calentry
|
||||||
@@ -39,39 +127,9 @@ class Ability
|
|||||||
can [:delete],Calentry
|
can [:delete],Calentry
|
||||||
can :doadmin, User
|
can :doadmin, User
|
||||||
end
|
end
|
||||||
|
|
||||||
unless user.has_role?("fetadmin")
|
unless user.has_role?("fetadmin")
|
||||||
cannot :delete, Modulgruppe
|
|
||||||
cannot :delete, Rubrik
|
|
||||||
cannot :delete, Themengruppe
|
|
||||||
cannot :delete, Fetprofile
|
|
||||||
cannot :delete, Studium
|
|
||||||
cannot :delete, Modul
|
|
||||||
cannot :delete ,Gremium
|
|
||||||
end
|
end
|
||||||
# Rechteverwaltung fuer Neuigkeiten
|
|
||||||
|
|
||||||
# can :write, Neuigkeit if user.has_role?("newsmoderator", Neuigkeit.rubrik)
|
|
||||||
|
|
||||||
if user.has_role?("newsadmin") || user.has_role?("fetadmin")
|
|
||||||
can :addmoderator, Rubrik
|
|
||||||
end
|
|
||||||
can [:show,:index], Rubrik, :public=>true
|
|
||||||
|
|
||||||
can :show, Neuigkeit, :rubrik=>{:public=>true}
|
|
||||||
if user.has_role?("fetadmin")
|
|
||||||
can :addfetuser, User
|
|
||||||
can :addfetadmin, User
|
|
||||||
end
|
|
||||||
|
|
||||||
if user.has_role?("newsadmin") || user.has_role?( "fetadmin") || user.has_role?( "fetuser")
|
|
||||||
can :manage, Rubrik
|
|
||||||
can :manage, Neuigkeit
|
|
||||||
can :shownonpublic, Rubrik
|
|
||||||
can :showunpublished, Neuigkeit
|
|
||||||
can :seeintern, User
|
|
||||||
|
|
||||||
end
|
|
||||||
|
|
||||||
|
|
||||||
end
|
end
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -30,7 +30,7 @@ class User < ActiveRecord::Base
|
|||||||
# :token_authenticatable, :confirmable,
|
# :token_authenticatable, :confirmable,
|
||||||
# :lockable, :timeoutable and :omniauthable
|
# :lockable, :timeoutable and :omniauthable
|
||||||
devise :database_authenticatable, :recoverable, :rememberable, :trackable, :validatable,:omniauthable, :omniauth_providers => [:facebook,:ldap]
|
devise :database_authenticatable, :recoverable, :rememberable, :trackable, :validatable,:omniauthable, :omniauth_providers => [:facebook,:ldap]
|
||||||
|
acts_as_voter
|
||||||
# Setup accessible (or protected) attributes for your model
|
# Setup accessible (or protected) attributes for your model
|
||||||
attr_accessible :email, :password, :password_confirmation, :remember_me, :provider, :uid, :name
|
attr_accessible :email, :password, :password_confirmation, :remember_me, :provider, :uid, :name
|
||||||
belongs_to :fetprofile
|
belongs_to :fetprofile
|
||||||
@@ -63,14 +63,6 @@ logger.debug auth.to_s
|
|||||||
password:Devise.friendly_token[0,20])
|
password:Devise.friendly_token[0,20])
|
||||||
user.add_role("fetuser")
|
user.add_role("fetuser")
|
||||||
logger.debug(auth.extra.raw_info.to_s)
|
logger.debug(auth.extra.raw_info.to_s)
|
||||||
end
|
|
||||||
unless user
|
|
||||||
# user=User.create(name:"fail",
|
|
||||||
# provider:"ldap",
|
|
||||||
# uid:"sdf",
|
|
||||||
# email:"sdf@fet.at",
|
|
||||||
# password:Devise.friendly_token[0,20])
|
|
||||||
|
|
||||||
end
|
end
|
||||||
user
|
user
|
||||||
end
|
end
|
||||||
|
|||||||
Reference in New Issue
Block a user