diff options
| author | erdgeist <erdgeist@erdgeist.org> | 2026-08-01 00:27:34 +0200 |
|---|---|---|
| committer | erdgeist <erdgeist@erdgeist.org> | 2026-08-01 00:27:34 +0200 |
| commit | 8bcacace28df52fd972c54e6850aa3b93f5c8bdf (patch) | |
| tree | 05e90dd4e8f31ebb142f66239025da15e873901f /app/controllers/concerns | |
| parent | 529f81b28ed77c62acaa63fad957e751798f2440 (diff) | |
Declare role requirements per controller
RoleRequired supplies require_redaktion and require_admin for surfaces that
are not nodes and so cannot be reached by Node#restricted?.
Navigation is content rather than plumbing, so menu_items requires
redaktion. User management is janitorial and requires admin: index, new,
create, reset_otp, deactivate, reactivate. verify_status now also covers
show, without which any logged-in user could read any account by walking a
small id space. Editing your own account stays open.
The dashboard hides the Users and Navigation buttons from those who cannot
use them; everything else stays visible to everyone. Both denials share one
message and land on the dashboard.
Adds redella (redaktion) and alufa (redaktion + alumni) fixtures.
Diffstat (limited to 'app/controllers/concerns')
| -rw-r--r-- | app/controllers/concerns/role_required.rb | 23 |
1 files changed, 23 insertions, 0 deletions
diff --git a/app/controllers/concerns/role_required.rb b/app/controllers/concerns/role_required.rb new file mode 100644 index 00000000..b841b8cc --- /dev/null +++ b/app/controllers/concerns/role_required.rb | |||
| @@ -0,0 +1,23 @@ | |||
| 1 | # Controller-level role gates, for surfaces that are not nodes and so cannot | ||
| 2 | # be reached by Node#restricted?. The node gates live in the models, since | ||
| 3 | # those verbs are callable from rake tasks; these are HTTP-only. | ||
| 4 | module RoleRequired | ||
| 5 | extend ActiveSupport::Concern | ||
| 6 | |||
| 7 | private | ||
| 8 | |||
| 9 | def require_redaktion | ||
| 10 | return if current_user&.redaktion? | ||
| 11 | deny_role_access(:redaktion_required) | ||
| 12 | end | ||
| 13 | |||
| 14 | def require_admin | ||
| 15 | return if current_user&.is_admin? | ||
| 16 | deny_role_access(:admin_required) | ||
| 17 | end | ||
| 18 | |||
| 19 | def deny_role_access(key) | ||
| 20 | flash[:error] = t("flash.common.#{key}") | ||
| 21 | redirect_to admin_path | ||
| 22 | end | ||
| 23 | end | ||
