debian-mirror-gitlab/app/models/ability.rb

439 lines
11 KiB
Ruby
Raw Normal View History

2014-09-02 18:07:02 +05:30
class Ability
class << self
def allowed(user, subject)
2015-11-26 14:37:03 +05:30
return anonymous_abilities(user, subject) if user.nil?
return [] unless user.is_a?(User)
2014-09-02 18:07:02 +05:30
return [] if user.blocked?
2016-04-02 18:10:28 +05:30
case subject
when CommitStatus then commit_status_abilities(user, subject)
when Project then project_abilities(user, subject)
when Issue then issue_abilities(user, subject)
when Note then note_abilities(user, subject)
when ProjectSnippet then project_snippet_abilities(user, subject)
when PersonalSnippet then personal_snippet_abilities(user, subject)
when MergeRequest then merge_request_abilities(user, subject)
when Group then group_abilities(user, subject)
when Namespace then namespace_abilities(user, subject)
when GroupMember then group_member_abilities(user, subject)
when ProjectMember then project_member_abilities(user, subject)
2014-09-02 18:07:02 +05:30
else []
end.concat(global_abilities(user))
end
2015-11-26 14:37:03 +05:30
# List of possible abilities for anonymous user
def anonymous_abilities(user, subject)
case true
when subject.is_a?(PersonalSnippet)
anonymous_personal_snippet_abilities(subject)
2016-04-02 18:10:28 +05:30
when subject.is_a?(CommitStatus)
anonymous_commit_status_abilities(subject)
2015-11-26 14:37:03 +05:30
when subject.is_a?(Project) || subject.respond_to?(:project)
anonymous_project_abilities(subject)
when subject.is_a?(Group) || subject.respond_to?(:group)
anonymous_group_abilities(subject)
else
[]
end
end
def anonymous_project_abilities(subject)
project = if subject.is_a?(Project)
2014-09-02 18:07:02 +05:30
subject
else
2015-11-26 14:37:03 +05:30
subject.project
2014-09-02 18:07:02 +05:30
end
if project && project.public?
2015-09-11 14:41:01 +05:30
rules = [
2014-09-02 18:07:02 +05:30
:read_project,
:read_wiki,
:read_issue,
2015-09-11 14:41:01 +05:30
:read_label,
2014-09-02 18:07:02 +05:30
:read_milestone,
:read_project_snippet,
2015-04-26 12:48:37 +05:30
:read_project_member,
2014-09-02 18:07:02 +05:30
:read_merge_request,
:read_note,
2016-04-02 18:10:28 +05:30
:read_commit_status,
2014-09-02 18:07:02 +05:30
:download_code
]
2015-09-11 14:41:01 +05:30
2016-04-02 18:10:28 +05:30
# Allow to read builds by anonymous user if guests are allowed
rules << :read_build if project.public_builds?
2015-09-11 14:41:01 +05:30
rules - project_disabled_features_rules(project)
2014-09-02 18:07:02 +05:30
else
2015-11-26 14:37:03 +05:30
[]
end
end
2014-09-02 18:07:02 +05:30
2016-04-02 18:10:28 +05:30
def anonymous_commit_status_abilities(subject)
rules = anonymous_project_abilities(subject.project)
# If subject is Ci::Build which inherits from CommitStatus filter the abilities
rules = filter_build_abilities(rules) if subject.is_a?(Ci::Build)
rules
end
2015-11-26 14:37:03 +05:30
def anonymous_group_abilities(subject)
group = if subject.is_a?(Group)
subject
else
subject.group
end
if group && group.projects.public_only.any?
2015-11-26 14:37:03 +05:30
[:read_group]
else
[]
end
end
def anonymous_personal_snippet_abilities(snippet)
if snippet.public?
[:read_personal_snippet]
else
[]
2014-09-02 18:07:02 +05:30
end
end
def global_abilities(user)
rules = []
rules << :create_group if user.can_create_group
rules
end
def project_abilities(user, project)
rules = []
key = "/user/#{user.id}/project/#{project.id}"
2015-09-11 14:41:01 +05:30
2014-09-02 18:07:02 +05:30
RequestStore.store[key] ||= begin
team = project.team
# Rules based on role in project
if team.master?(user)
2015-04-26 12:48:37 +05:30
rules.push(*project_master_rules)
2014-09-02 18:07:02 +05:30
elsif team.developer?(user)
2015-04-26 12:48:37 +05:30
rules.push(*project_dev_rules)
2014-09-02 18:07:02 +05:30
elsif team.reporter?(user)
2015-04-26 12:48:37 +05:30
rules.push(*project_report_rules)
2014-09-02 18:07:02 +05:30
elsif team.guest?(user)
2015-04-26 12:48:37 +05:30
rules.push(*project_guest_rules)
2014-09-02 18:07:02 +05:30
end
if project.public? || project.internal?
2015-04-26 12:48:37 +05:30
rules.push(*public_project_rules)
2016-04-02 18:10:28 +05:30
# Allow to read builds for internal projects
rules << :read_build if project.public_builds?
2014-09-02 18:07:02 +05:30
end
if project.owner == user || user.admin?
2015-04-26 12:48:37 +05:30
rules.push(*project_admin_rules)
2014-09-02 18:07:02 +05:30
end
if project.group && project.group.has_owner?(user)
2015-04-26 12:48:37 +05:30
rules.push(*project_admin_rules)
2014-09-02 18:07:02 +05:30
end
if project.archived?
rules -= project_archived_rules
end
2015-09-11 14:41:01 +05:30
rules - project_disabled_features_rules(project)
2014-09-02 18:07:02 +05:30
end
end
def public_project_rules
@public_project_rules ||= project_guest_rules + [
2014-09-02 18:07:02 +05:30
:download_code,
2016-04-02 18:10:28 +05:30
:fork_project,
:read_commit_status,
2014-09-02 18:07:02 +05:30
]
end
def project_guest_rules
@project_guest_rules ||= [
2014-09-02 18:07:02 +05:30
:read_project,
:read_wiki,
:read_issue,
2015-09-11 14:41:01 +05:30
:read_label,
2014-09-02 18:07:02 +05:30
:read_milestone,
:read_project_snippet,
2015-04-26 12:48:37 +05:30
:read_project_member,
2014-09-02 18:07:02 +05:30
:read_merge_request,
:read_note,
2015-09-11 14:41:01 +05:30
:create_project,
:create_issue,
:create_note
2014-09-02 18:07:02 +05:30
]
end
def project_report_rules
@project_report_rules ||= project_guest_rules + [
2014-09-02 18:07:02 +05:30
:download_code,
:fork_project,
2015-09-11 14:41:01 +05:30
:create_project_snippet,
:update_issue,
:admin_issue,
2016-04-02 18:10:28 +05:30
:admin_label,
:read_commit_status,
:read_build,
2014-09-02 18:07:02 +05:30
]
end
def project_dev_rules
@project_dev_rules ||= project_report_rules + [
2015-09-11 14:41:01 +05:30
:admin_merge_request,
2016-04-02 18:10:28 +05:30
:create_commit_status,
:update_commit_status,
:create_build,
:update_build,
2015-09-11 14:41:01 +05:30
:create_merge_request,
:create_wiki,
2014-09-02 18:07:02 +05:30
:push_code
]
end
def project_archived_rules
@project_archived_rules ||= [
2015-09-11 14:41:01 +05:30
:create_merge_request,
2014-09-02 18:07:02 +05:30
:push_code,
:push_code_to_protected_branches,
2015-09-11 14:41:01 +05:30
:update_merge_request,
2014-09-02 18:07:02 +05:30
:admin_merge_request
]
end
def project_master_rules
@project_master_rules ||= project_dev_rules + [
2014-09-02 18:07:02 +05:30
:push_code_to_protected_branches,
2015-09-11 14:41:01 +05:30
:update_project_snippet,
:update_merge_request,
2014-09-02 18:07:02 +05:30
:admin_milestone,
:admin_project_snippet,
2015-04-26 12:48:37 +05:30
:admin_project_member,
2014-09-02 18:07:02 +05:30
:admin_merge_request,
:admin_note,
:admin_wiki,
2016-04-02 18:10:28 +05:30
:admin_project,
:admin_commit_status,
:admin_build
2014-09-02 18:07:02 +05:30
]
end
def project_admin_rules
@project_admin_rules ||= project_master_rules + [
2014-09-02 18:07:02 +05:30
:change_namespace,
:change_visibility_level,
:rename_project,
:remove_project,
2015-11-26 14:37:03 +05:30
:archive_project,
:remove_fork_project
2014-09-02 18:07:02 +05:30
]
end
2015-09-11 14:41:01 +05:30
def project_disabled_features_rules(project)
rules = []
unless project.issues_enabled
rules += named_abilities('issue')
end
unless project.merge_requests_enabled
rules += named_abilities('merge_request')
end
unless project.issues_enabled or project.merge_requests_enabled
rules += named_abilities('label')
rules += named_abilities('milestone')
end
unless project.snippets_enabled
rules += named_abilities('project_snippet')
end
unless project.wiki_enabled
rules += named_abilities('wiki')
end
2016-04-02 18:10:28 +05:30
unless project.builds_enabled
rules += named_abilities('build')
end
2015-09-11 14:41:01 +05:30
rules
end
2015-04-26 12:48:37 +05:30
def group_abilities(user, group)
2014-09-02 18:07:02 +05:30
rules = []
if user.admin? || group.users.include?(user) || ProjectsFinder.new.execute(user, group: group).any?
rules << :read_group
end
# Only group masters and group owners can create new projects in group
if group.has_master?(user) || group.has_owner?(user) || user.admin?
2015-11-26 14:37:03 +05:30
rules += [
2014-09-02 18:07:02 +05:30
:create_projects,
2015-11-26 14:37:03 +05:30
:admin_milestones
]
2014-09-02 18:07:02 +05:30
end
2015-04-26 12:48:37 +05:30
# Only group owner and administrators can admin group
2014-09-02 18:07:02 +05:30
if group.has_owner?(user) || user.admin?
2015-11-26 14:37:03 +05:30
rules += [
2015-04-26 12:48:37 +05:30
:admin_group,
2015-09-11 14:41:01 +05:30
:admin_namespace,
:admin_group_member
2015-11-26 14:37:03 +05:30
]
2014-09-02 18:07:02 +05:30
end
rules.flatten
end
2015-04-26 12:48:37 +05:30
def namespace_abilities(user, namespace)
2014-09-02 18:07:02 +05:30
rules = []
2015-04-26 12:48:37 +05:30
# Only namespace owner and administrators can admin it
2014-09-02 18:07:02 +05:30
if namespace.owner == user || user.admin?
2015-11-26 14:37:03 +05:30
rules += [
2014-09-02 18:07:02 +05:30
:create_projects,
2015-04-26 12:48:37 +05:30
:admin_namespace
2015-11-26 14:37:03 +05:30
]
2014-09-02 18:07:02 +05:30
end
rules.flatten
end
2015-09-11 14:41:01 +05:30
[:issue, :merge_request].each do |name|
2014-09-02 18:07:02 +05:30
define_method "#{name}_abilities" do |user, subject|
2015-09-11 14:41:01 +05:30
rules = []
if subject.author == user || (subject.respond_to?(:assignee) && subject.assignee == user)
rules += [
2014-09-02 18:07:02 +05:30
:"read_#{name}",
2015-09-11 14:41:01 +05:30
:"update_#{name}",
2014-09-02 18:07:02 +05:30
]
2015-09-11 14:41:01 +05:30
end
rules += project_abilities(user, subject.project)
rules
end
end
2015-11-26 14:37:03 +05:30
[:note, :project_snippet].each do |name|
2015-09-11 14:41:01 +05:30
define_method "#{name}_abilities" do |user, subject|
rules = []
if subject.author == user
rules += [
2014-09-02 18:07:02 +05:30
:"read_#{name}",
2015-09-11 14:41:01 +05:30
:"update_#{name}",
:"admin_#{name}"
2014-09-02 18:07:02 +05:30
]
end
2015-09-11 14:41:01 +05:30
if subject.respond_to?(:project) && subject.project
rules += project_abilities(user, subject.project)
end
rules
2014-09-02 18:07:02 +05:30
end
end
2015-11-26 14:37:03 +05:30
def personal_snippet_abilities(user, snippet)
rules = []
if snippet.author == user
rules += [
:read_personal_snippet,
:update_personal_snippet,
:admin_personal_snippet
]
end
if snippet.public? || snippet.internal?
rules << :read_personal_snippet
2015-11-26 14:37:03 +05:30
end
rules
end
2015-04-26 12:48:37 +05:30
def group_member_abilities(user, subject)
2014-09-02 18:07:02 +05:30
rules = []
target_user = subject.user
group = subject.group
2015-09-11 14:41:01 +05:30
2015-11-26 14:37:03 +05:30
unless group.last_owner?(target_user)
can_manage = group_abilities(user, group).include?(:admin_group_member)
2015-12-23 02:04:40 +05:30
if can_manage
2015-11-26 14:37:03 +05:30
rules << :update_group_member
rules << :destroy_group_member
2015-12-23 02:04:40 +05:30
elsif user == target_user
2015-11-26 14:37:03 +05:30
rules << :destroy_group_member
end
2014-09-02 18:07:02 +05:30
end
2015-09-11 14:41:01 +05:30
2015-11-26 14:37:03 +05:30
rules
end
def project_member_abilities(user, subject)
rules = []
target_user = subject.user
project = subject.project
unless target_user == project.owner
can_manage = project_abilities(user, project).include?(:admin_project_member)
2015-12-23 02:04:40 +05:30
if can_manage
2015-11-26 14:37:03 +05:30
rules << :update_project_member
rules << :destroy_project_member
2015-12-23 02:04:40 +05:30
elsif user == target_user
2015-11-26 14:37:03 +05:30
rules << :destroy_project_member
end
2014-09-02 18:07:02 +05:30
end
2015-09-11 14:41:01 +05:30
2014-09-02 18:07:02 +05:30
rules
end
2015-04-26 12:48:37 +05:30
2016-04-02 18:10:28 +05:30
def commit_status_abilities(user, subject)
rules = project_abilities(user, subject.project)
# If subject is Ci::Build which inherits from CommitStatus filter the abilities
rules = filter_build_abilities(rules) if subject.is_a?(Ci::Build)
rules
end
def filter_build_abilities(rules)
# If we can't read build we should also not have that
# ability when looking at this in context of commit_status
%w(read create update admin).each do |rule|
rules.delete(:"#{rule}_commit_status") unless rules.include?(:"#{rule}_build")
end
rules
end
2015-04-26 12:48:37 +05:30
def abilities
@abilities ||= begin
2015-11-26 14:37:03 +05:30
abilities = Six.new
abilities << self
abilities
end
2015-04-26 12:48:37 +05:30
end
2015-09-11 14:41:01 +05:30
private
def named_abilities(name)
[
:"read_#{name}",
:"create_#{name}",
:"update_#{name}",
:"admin_#{name}"
]
end
2014-09-02 18:07:02 +05:30
end
end