First version for App and Object auth.Taking Announcement as experiment

This commit is contained in:
Matthew Kaito Juyuan Fu 2012-02-15 18:20:44 +08:00
parent 17caa7cb1b
commit 5640e07733
31 changed files with 161 additions and 52 deletions

View File

@ -1,8 +1,12 @@
class Admin::ObjectAuthsController < ApplicationController class Admin::ObjectAuthsController < ApplicationController
include OrbitCoreLib::PermissionUnility
layout "admin" layout "admin"
before_filter :authenticate_user! before_filter :authenticate_user!
before_filter :check_if_user_can_do_object_auth
# before_filter :is_admin? ,:only => :index # before_filter :is_admin? ,:only => :index
def index def index
# if current_user.admin? # if current_user.admin?
@object_auths = ObjectAuth.all @object_auths = ObjectAuth.all
@ -70,7 +74,11 @@ class Admin::ObjectAuthsController < ApplicationController
def edit def edit
@object_auth = ObjectAuth.find(params[:id]) @object_auth = ObjectAuth.find(params[:id])
end end
private
def check_if_user_can_do_object_auth
unless check_permission(:manager)
render :nothing => true, :status => 403
end
end
end end

View File

@ -1,3 +0,0 @@
class ObitFrontendController< ObitFrontendComponentController
end

View File

@ -1,3 +0,0 @@
class ObitWidgetController< ObitFrontendComponentController
end

View File

@ -0,0 +1,24 @@
class OrbitBackendController< ApplicationController
before_filter :authenticate_user!
before_filter :setup_vars
# before_filter {|c| c.front_end_available(@app_title)}
before_filter :check_user_can_use,:except => [:public]
include OrbitCoreLib::PermissionUnility
layout 'admin'
def setup_vars
@app_title = request.fullpath.split('/')[2]
@module_app = ModuleApp.first(conditions: {:key => @app_title} )
end
private
def check_user_can_use
unless check_permission
redirect_to polymorphic_path(['panel',@app_title,'back_end','public'])
end
end
end

View File

@ -1,4 +1,4 @@
class ObitFrontendComponentController< ApplicationController class OrbitFrontendComponentController< ApplicationController
before_filter :setup_vars before_filter :setup_vars
before_filter {|c| c.front_end_available(@app_title)} before_filter {|c| c.front_end_available(@app_title)}
layout 'production' layout 'production'

View File

@ -0,0 +1,3 @@
class OrbitFrontendController< OrbitFrontendComponentController
end

View File

@ -0,0 +1,3 @@
class ObitWidgetController< OrbitFrontendComponentController
end

View File

@ -3,4 +3,9 @@ module Admin::AppAuthHelper
link_to t(:enable), eval("admin_#{attribute_type}_path(attribute, :authenticity_token => form_authenticity_token, :#{attribute_type} => {:disabled => true})"), :remote => true, :method => :put, :id => "disable_#{attribute.id}", :style => "display:#{attribute.is_disabled? ? 'none' : ''}", :class => 'switch' link_to t(:enable), eval("admin_#{attribute_type}_path(attribute, :authenticity_token => form_authenticity_token, :#{attribute_type} => {:disabled => true})"), :remote => true, :method => :put, :id => "disable_#{attribute.id}", :style => "display:#{attribute.is_disabled? ? 'none' : ''}", :class => 'switch'
link_to t(:disable), eval("admin_#{attribute_type}_path(attribute, :authenticity_token => form_authenticity_token, :#{attribute_type} => {:disabled => false})"), :remote => true, :method => :put, :id => "enable_#{attribute.id}", :style => "display:#{attribute.is_disabled? ? '' : 'none'}", :class => 'switch' link_to t(:disable), eval("admin_#{attribute_type}_path(attribute, :authenticity_token => form_authenticity_token, :#{attribute_type} => {:disabled => false})"), :remote => true, :method => :put, :id => "enable_#{attribute.id}", :style => "display:#{attribute.is_disabled? ? '' : 'none'}", :class => 'switch'
end end
def if_permitted_to(user,role)
end
end end

View File

@ -5,4 +5,17 @@ module AdminHelper
link_to('/' , admin_items_path) + ( @parent_items.map{ |i| link_to(i.name, admin_items_path(:parent_id=>i.id) ) } << @parent_item.name ).join("/").html_safe link_to('/' , admin_items_path) + ( @parent_items.map{ |i| link_to(i.name, admin_items_path(:parent_id=>i.id) ) } << @parent_item.name ).join("/").html_safe
end end
# Check if the current_user is manager in current module app
def is_manager?
@module_app.is_manager?(current_user) || is_admin?
end
# Check if the current_user is sub manager in current module app
def is_sub_manager?
@module_app.is_sub_manager?(current_user)|| is_admin?
end
def is_admin?
current_user.admin?
end
end end

View File

@ -2,4 +2,5 @@ class AppAuth < PrototypeAuth
belongs_to :module_app belongs_to :module_app
end end

View File

@ -22,6 +22,14 @@ class ModuleApp
before_save :set_key before_save :set_key
def is_manager?(user)
managing_users.include?(user)
end
def is_sub_manager?(user)
sub_managing_users.include?(user) || is_manager?(user)
end
def managing_users def managing_users
self.managers.collect{ |t| t.user } self.managers.collect{ |t| t.user }
end end

View File

@ -16,7 +16,7 @@ class PrototypeAuth
has_and_belongs_to_many :roles has_and_belongs_to_many :roles
has_and_belongs_to_many :sub_roles has_and_belongs_to_many :sub_roles
attr_protected :roles,:sub_roles,:privilege_users,:blocked_users,:users attr_protected :roles,:sub_roles,:privilege_users,:blocked_users
def add_role role def add_role role
add_operation(:roles,role) add_operation(:roles,role)

View File

@ -1 +0,0 @@
<%= f.select :module_app_id, @apps.collect { |t| [t.title.capitalize, t.id] }, {:include_blank => true} ,{:rel => admin_module_apps_path } %>

View File

@ -11,4 +11,4 @@
<%= render :partial => "admin/components/user_role_management", :locals => { <%= render :partial => "admin/components/user_role_management", :locals => {
:object => @object_auth.auth_obj ,:auth=>@object_auth,:submit_url=>create_role_admin_object_auth_path(@object_auth),:ploy_route_ary=>['remove',:admin,@object_auth] } %> :object => @object_auth.auth_obj ,:auth=>@object_auth,:submit_url=>create_role_admin_object_auth_path(@object_auth),:ploy_route_ary=>['remove',:admin,@object_auth] } %>
<%= link_to 'Back to object',eval(@object_auth.obj_authable.class.to_s+"::AfterObjectAuthUrl") %>

View File

@ -14,7 +14,7 @@ PrototypeR4::Application.routes.draw do
resources :app_auths resources :app_auths
resources :object_auths do resources :object_auths do
collection do collection do
match 'new/:type/:obj_id',:action => 'new',:via => "get",:as => :init match 'new/:type/:obj_id/:module_app_id',:action => 'new',:via => "get",:as => :init
end end
member do member do
match ':id/create_role',:action => 'create_role',:via => "post",:as => :create_role match ':id/create_role',:action => 'create_role',:via => "post",:as => :create_role

View File

@ -31,4 +31,26 @@ module OrbitCoreLib
end end
end end
module PermissionUnility
private
def check_permission(type = :use)
permission_grant = current_user.admin?? true : false
module_app = @module_app.nil?? ModuleApp.find(params[:module_app_id]) : @module_app
unless permission_grant
permission_grant = case type
when :use
users_ary = module_app.app_auth.auth_users rescue nil
users_ary = [] if users_ary.nil?
(users_ary.include?(current_user) || module_app.is_manager?(current_user) || module_app.is_sub_manager?(current_user))
when :manager
module_app.is_manager?(current_user)
when :sub_manager
module_app.is_manager?(current_user) || module_app.is_sub_manager?(current_user)
end
end
permission_grant
end
end
end end

22
lib/tasks/anc_tasks.rake Normal file
View File

@ -0,0 +1,22 @@
# encoding: utf-8
namespace :anc do
task :build => :environment do
bulletin_category_1 = BulletinCategory.create(:key => "C1ChrisCheckANDPreivew",:display => "List" )
bulletin_category_1.create_i18n_variable(:en => "ChrisCheckANDPreivew", :zh_tw => 'ChrisCheckANDPreivew')
bulletin_category_2 = BulletinCategory.create(:key => "C2MattCheckANDPreivew",:display => "List" )
bulletin_category_2.create_i18n_variable(:en => "MattCheckANDPreivew", :zh_tw => 'MattCheckANDPreivew')
bulletin_category_3 = BulletinCategory.create(:key => "C3MattCheckChrisPreview",:display => "List" )
bulletin_category_3.create_i18n_variable(:en => "MattCheckChrisPreview", :zh_tw => 'MattCheckChrisPreview')
bulletin_1 = Bulletin.create(:title => "C1P1",:status => nil,:subtitle => "",:text => "value",:postadate => Time.now,:deadline => nil,:bulletin_category => bulletin_category_1 )
bulletin_2 = Bulletin.create(:title => "C1P2",:status => nil,:subtitle => "",:text => "value",:postadate => Time.now,:deadline => nil,:bulletin_category => bulletin_category_1 )
bulletin_3 = Bulletin.create(:title => "C2P1",:status => nil,:subtitle => "",:text => "value",:postadate => Time.now,:deadline => nil,:bulletin_category => bulletin_category_2 )
bulletin_4 = Bulletin.create(:title => "C2P2",:status => nil,:subtitle => "",:text => "value",:postadate => Time.now,:deadline => nil,:bulletin_category => bulletin_category_2 )
bulletin_5 = Bulletin.create(:title => "C3P1",:status => nil,:subtitle => "",:text => "value",:postadate => Time.now,:deadline => nil,:bulletin_category => bulletin_category_3 )
bulletin_6 = Bulletin.create(:title => "C3P2",:status => nil,:subtitle => "",:text => "value",:postadate => Time.now,:deadline => nil,:bulletin_category => bulletin_category_3 )
end
end

View File

@ -125,6 +125,12 @@ namespace :dev do
AttributeValue.create( :user_id => user.id, :attribute_field_id => i_1.attribute_fields[1].id, :key => 'last_name', :en => 'Fu', :zh_tw => '傅' ) AttributeValue.create( :user_id => user.id, :attribute_field_id => i_1.attribute_fields[1].id, :key => 'last_name', :en => 'Fu', :zh_tw => '傅' )
AttributeValue.create( :user_id => user.id, :attribute_field_id => sr_2_1.attribute_fields[0].id, :key => 'major', :en => 'Information management', :zh_tw => '信息化管理' ) AttributeValue.create( :user_id => user.id, :attribute_field_id => sr_2_1.attribute_fields[0].id, :key => 'major', :en => 'Information management', :zh_tw => '信息化管理' )
AttributeValue.create( :user_id => user.id, :attribute_field_id => sr_2_1.attribute_fields[1].id, :key => 'department', :en => 'Computer Science', :zh_tw => '計算機科學' ) AttributeValue.create( :user_id => user.id, :attribute_field_id => sr_2_1.attribute_fields[1].id, :key => 'department', :en => 'Computer Science', :zh_tw => '計算機科學' )
user = User.create( :email => 'manager@rulingcom.com', :password => 'password', :password_confirmation => 'password', :admin => false, :role_id => r_2.id, :sub_role_ids => [sr_2_1.id ] )
AttributeValue.create( :user_id => user.id, :attribute_field_id => i_1.attribute_fields[0].id, :key => 'first_name', :en => 'Manager', :zh_tw => '管理員' )
AttributeValue.create( :user_id => user.id, :attribute_field_id => i_1.attribute_fields[1].id, :key => 'last_name', :en => 'Chen', :zh_tw => '陳' )
AttributeValue.create( :user_id => user.id, :attribute_field_id => sr_2_1.attribute_fields[0].id, :key => 'major', :en => 'Information management', :zh_tw => '信息化管理' )
AttributeValue.create( :user_id => user.id, :attribute_field_id => sr_2_1.attribute_fields[1].id, :key => 'department', :en => 'Computer Science', :zh_tw => '計算機科學' )
ad_banner = AdBanner.new(:title => 'banner_1',:post_date => Date.today,:context=> "context",:ad_fx=>'zoom',:direct_to_after_click=>true) ad_banner = AdBanner.new(:title => 'banner_1',:post_date => Date.today,:context=> "context",:ad_fx=>'zoom',:direct_to_after_click=>true)

View File

@ -1,5 +1,5 @@
{ {
"title": "Announcement", "title": "announcement",
"version": "0.1", "version": "0.1",
"organization": "Rulingcom", "organization": "Rulingcom",
"author": "RD dep", "author": "RD dep",

View File

@ -1,11 +1,12 @@
class Panel::Announcement::BackEnd::AnnouncementsController < ApplicationController class Panel::Announcement::BackEnd::AnnouncementsController < OrbitBackendController
layout 'admin'
def index
def public
render :text => "This is an public_page need to be build"
end end
def index
end
# GET /announcements/1 # GET /announcements/1
# GET /announcements/1.xml # GET /announcements/1.xml
def show def show
@ -76,4 +77,6 @@ class Panel::Announcement::BackEnd::AnnouncementsController < ApplicationControl
format.xml { head :ok } format.xml { head :ok }
end end
end end
end end

View File

@ -1,7 +1,5 @@
class Panel::Announcement::BackEnd::BulletinCategorysController < ApplicationController class Panel::Announcement::BackEnd::BulletinCategorysController < OrbitBackendController
layout 'admin'
def index def index
@bulletin_categorys = BulletinCategory.all @bulletin_categorys = BulletinCategory.all
@bulletin_category = BulletinCategory.new(:display => 'List') @bulletin_category = BulletinCategory.new(:display => 'List')

View File

@ -1,9 +1,6 @@
class Panel::Announcement::BackEnd::BulletinsController < ApplicationController class Panel::Announcement::BackEnd::BulletinsController < OrbitBackendController
layout 'admin' #before_filter :is_admin?
before_filter :authenticate_user!
before_filter :is_admin?
def index def index
# @bulletins = Bulletin.all # @bulletins = Bulletin.all

View File

@ -1,9 +1,10 @@
class Panel::Announcement::BackEnd::FactChecksController < ApplicationController class Panel::Announcement::BackEnd::FactChecksController < OrbitBackendController
before_filter :authenticate_user!
layout 'admin' layout 'admin'
def index def index
@bulletin_categorys_preview = BulletinCategory.authed_for_user(current_user,'preview') @bulletin_categorys_preview = BulletinCategory.authed_for_user(current_user,'preview')
@bulletin_categorys_check = BulletinCategory.authed_for_user(current_user,'check') @bulletin_categorys_check = BulletinCategory.authed_for_user(current_user,'fact_check')
end end
def new def new

View File

@ -6,7 +6,7 @@ class BulletinCategory
include OrbitCoreLib::ObjectAuthable include OrbitCoreLib::ObjectAuthable
ObjectAuthTitlesOptions = %W{preview fact_check} ObjectAuthTitlesOptions = %W{preview fact_check}
AfterObjectAuthUrl = '/panel/announcement/back_end/bulletin_categorys'
# include Mongoid::MultiParameterAttributes # include Mongoid::MultiParameterAttributes
PAYMENT_TYPES = [ "List", "Picture" ] PAYMENT_TYPES = [ "List", "Picture" ]

View File

@ -5,13 +5,15 @@
<td><%= bulletin_category.i18n_variable[locale] rescue nil %></td> <td><%= bulletin_category.i18n_variable[locale] rescue nil %></td>
<% end %> <% end %>
<td><%= bulletin_category.display %></td> <td><%= bulletin_category.display %></td>
<td> <% if is_manager? %>
<%= link_to t('blog.new_auth'), init_admin_object_auths_path("BulletinCategory",bulletin_category) %> <br/ > <td>
<% bulletin_category.object_auths.each do |obj_auth| %> <%= link_to t('blog.new_auth'), init_admin_object_auths_path("BulletinCategory",bulletin_category,@module_app) %> <br/ >
<%= link_to obj_auth.title,edit_admin_object_auth_url(obj_auth) %><br /> <% bulletin_category.object_auths.each do |obj_auth| %>
<% end %> <%= link_to obj_auth.title,edit_admin_object_auth_url(obj_auth) %><br />
</td> <% end %>
<td> </td>
<td>
<% end %>
<%= link_to t('bulletin_category.edit'), edit_panel_announcement_back_end_bulletin_category_path(bulletin_category), :remote => true %> | <%= link_to t('bulletin_category.edit'), edit_panel_announcement_back_end_bulletin_category_path(bulletin_category), :remote => true %> |
<%= link_to t('bulletin_category.quick_edit'), panel_announcement_back_end_bulletin_category_quick_edit_path(bulletin_category), :remote => true %> | <%= link_to t('bulletin_category.quick_edit'), panel_announcement_back_end_bulletin_category_quick_edit_path(bulletin_category), :remote => true %> |
<%= link_to t('bulletin_category.delete'), panel_announcement_back_end_bulletin_category_path(bulletin_category), :confirm => t('announcement.sure?'), :method => :delete, :remote => true %> <%= link_to t('bulletin_category.delete'), panel_announcement_back_end_bulletin_category_path(bulletin_category), :confirm => t('announcement.sure?'), :method => :delete, :remote => true %>

View File

@ -7,9 +7,8 @@
<ul class="list"> <ul class="list">
<li><%= link_to t('bulletin.new_announcement'), new_panel_announcement_back_end_bulletin_path %></li> <li><%= link_to t('bulletin.new_announcement'), new_panel_announcement_back_end_bulletin_path %></li>
<li><%= link_to t('bulletin.announcement_list'), panel_announcement_back_end_bulletins_path %></li> <li><%= link_to t('bulletin.announcement_list'), panel_announcement_back_end_bulletins_path %></li>
<li><%= link_to t('bulletin.new_announcement_class'), panel_announcement_back_end_bulletin_categorys_path %></li> <li><%= link_to t('bulletin.new_announcement_class'), panel_announcement_back_end_bulletin_categorys_path if is_manager?%></li>
<li><%= link_to t('bulletin.my_announcement_fact_check'), panel_announcement_back_end_fact_checks_path %></li> <li><%= link_to t('bulletin.my_announcement_fact_check'), panel_announcement_back_end_fact_checks_path if is_sub_manager?%></li>
</ul> </ul>
<% end -%> <% end -%>

View File

@ -42,10 +42,14 @@
<br /> <br />
<h1><%= t('bulletin.list_announcement') %></h1> <h1><%= t('bulletin.list_announcement') %></h1>
<div id="preview_block">
<h1>Preview</h1>
<%= render :partial => "list_table", :collection => @bulletin_categorys_preview,:as => :bulletin_category%> <%= render :partial => "list_table", :collection => @bulletin_categorys_preview,:as => :bulletin_category%>
</div>
===================================================================================================================
<div id="check_block">
<h1>Check Please</h1>
<%= render :partial => "list_table", :collection => @bulletin_categorys_check,:as => :bulletin_category%> <%= render :partial => "list_table", :collection => @bulletin_categorys_check,:as => :bulletin_category%>
</div>
<br /> <br />

View File

@ -3,6 +3,7 @@ Rails.application.routes.draw do
namespace :panel do namespace :panel do
namespace :announcement do namespace :announcement do
namespace :back_end do namespace :back_end do
match 'public' => "announcements#public",:as => :public
resources :fact_checks resources :fact_checks
root :to => "bulletins#index" root :to => "bulletins#index"
resources :bulletins resources :bulletins
@ -14,7 +15,7 @@ Rails.application.routes.draw do
root :to => "bulletins#index" root :to => "bulletins#index"
resources :bulletins resources :bulletins
end end
namespace :widget do namespace :widget do
root :to => "bulletins#index" root :to => "bulletins#index"
end end
end end

View File

@ -1,4 +0,0 @@
# desc "Explaining what the task does"
# task :announcement do
# # Task goes here
# end

View File

@ -1,4 +1,4 @@
class Panel::NewBlog::FrontEnd::CommentsController < ObitFrontendController class Panel::NewBlog::FrontEnd::CommentsController < OrbitFrontendController
def create def create
@post = Post.find(params[:post_id]) @post = Post.find(params[:post_id])
@comment = @post.comments.create!(params[:comment]) @comment = @post.comments.create!(params[:comment])

View File

@ -1,4 +1,4 @@
class Panel::NewBlog::FrontEnd::PostsController < ObitFrontendController class Panel::NewBlog::FrontEnd::PostsController < OrbitFrontendController
# GET /posts # GET /posts
# GET /posts.xml # GET /posts.xml
def index def index