[#4601] Change Manage Budget to a givable permission
This commit is contained in:
@@ -24,7 +24,7 @@ Redmine::Plugin.register :redmine_contracts do
|
|||||||
permission(:manage_budget, {
|
permission(:manage_budget, {
|
||||||
:contracts => [:index, :new, :create, :show, :edit, :update, :destroy],
|
:contracts => [:index, :new, :create, :show, :edit, :update, :destroy],
|
||||||
:deliverables => [:index, :new, :create, :show, :edit, :update, :destroy]
|
:deliverables => [:index, :new, :create, :show, :edit, :update, :destroy]
|
||||||
}, :public => true)
|
})
|
||||||
end
|
end
|
||||||
|
|
||||||
contract_list_submenu_items = Proc.new {|project|
|
contract_list_submenu_items = Proc.new {|project|
|
||||||
|
|||||||
@@ -6,6 +6,9 @@ class ContractsDeleteTest < ActionController::IntegrationTest
|
|||||||
def setup
|
def setup
|
||||||
@project = Project.generate!(:identifier => 'main')
|
@project = Project.generate!(:identifier => 'main')
|
||||||
@contract = Contract.generate!(:project => @project, :name => 'A Contract')
|
@contract = Contract.generate!(:project => @project, :name => 'A Contract')
|
||||||
|
@user = User.generate_user_with_permission_to_manage_budget(:project => @project)
|
||||||
|
|
||||||
|
login_as(@user.login, 'contracts')
|
||||||
end
|
end
|
||||||
|
|
||||||
should "allow admins to delete the contract" do
|
should "allow admins to delete the contract" do
|
||||||
@@ -39,10 +42,7 @@ class ContractsDeleteTest < ActionController::IntegrationTest
|
|||||||
|
|
||||||
assert_select "a", :text => /Delete/, :count => 0
|
assert_select "a", :text => /Delete/, :count => 0
|
||||||
delete contract_path(@project, @contract)
|
delete contract_path(@project, @contract)
|
||||||
assert_response :redirect
|
assert_forbidden
|
||||||
follow_redirect!
|
|
||||||
assert_response :success
|
|
||||||
assert_template 'account/login' # Prompt for login
|
|
||||||
|
|
||||||
assert Contract.find_by_id(@contract.id), "Contract deleted"
|
assert Contract.find_by_id(@contract.id), "Contract deleted"
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -9,9 +9,30 @@ class ContractsEditTest < ActionController::IntegrationTest
|
|||||||
@role = Role.generate!
|
@role = Role.generate!
|
||||||
User.add_to_project(@account_executive, @project, @role)
|
User.add_to_project(@account_executive, @project, @role)
|
||||||
@contract = Contract.generate!(:project => @project, :name => 'A Contract', :account_executive => @account_executive)
|
@contract = Contract.generate!(:project => @project, :name => 'A Contract', :account_executive => @account_executive)
|
||||||
|
@user = User.generate_user_with_permission_to_manage_budget(:project => @project)
|
||||||
|
|
||||||
|
login_as(@user.login, 'contracts')
|
||||||
end
|
end
|
||||||
|
|
||||||
should "allow any user to edit the contract" do
|
should "block anonymous users from editing the contract" do
|
||||||
|
logout
|
||||||
|
visit "/projects/#{@project.identifier}/contracts/#{@contract.id}/edit"
|
||||||
|
|
||||||
|
assert_requires_login
|
||||||
|
end
|
||||||
|
|
||||||
|
should "block unauthorized users from editing the contract" do
|
||||||
|
logout
|
||||||
|
|
||||||
|
@user = User.generate!(:password => 'test', :password_confirmation => 'test')
|
||||||
|
login_as(@user.login, 'test')
|
||||||
|
|
||||||
|
visit "/projects/#{@project.identifier}/contracts/#{@contract.id}/edit"
|
||||||
|
|
||||||
|
assert_forbidden
|
||||||
|
end
|
||||||
|
|
||||||
|
should "allow authorized users to edit the contract" do
|
||||||
visit_contracts_for_project(@project)
|
visit_contracts_for_project(@project)
|
||||||
click_link @contract.id
|
click_link @contract.id
|
||||||
assert_response :success
|
assert_response :success
|
||||||
|
|||||||
@@ -16,9 +16,31 @@ class ContractsListTest < ActionController::IntegrationTest
|
|||||||
@contract2,
|
@contract2,
|
||||||
@other_contract
|
@other_contract
|
||||||
].map {|c| c.reload }
|
].map {|c| c.reload }
|
||||||
|
|
||||||
|
@user = User.generate_user_with_permission_to_manage_budget(:project => @project)
|
||||||
|
|
||||||
|
login_as(@user.login, 'contracts')
|
||||||
end
|
end
|
||||||
|
|
||||||
should "allow any user to list the contracts on a project" do
|
should "block anonymous users from listing the contracts" do
|
||||||
|
logout
|
||||||
|
visit "/projects/#{@project.identifier}/contracts"
|
||||||
|
|
||||||
|
assert_requires_login
|
||||||
|
end
|
||||||
|
|
||||||
|
should "block unauthorized users from listing contracts" do
|
||||||
|
logout
|
||||||
|
|
||||||
|
@user = User.generate!(:password => 'test', :password_confirmation => 'test')
|
||||||
|
login_as(@user.login, 'test')
|
||||||
|
|
||||||
|
visit "/projects/#{@project.identifier}/contracts"
|
||||||
|
|
||||||
|
assert_forbidden
|
||||||
|
end
|
||||||
|
|
||||||
|
should "allow authorized users to list the contracts on a project" do
|
||||||
visit_contracts_for_project(@project)
|
visit_contracts_for_project(@project)
|
||||||
end
|
end
|
||||||
|
|
||||||
|
|||||||
@@ -7,9 +7,30 @@ class ContractsNewTest < ActionController::IntegrationTest
|
|||||||
@project = Project.generate!(:identifier => 'main')
|
@project = Project.generate!(:identifier => 'main')
|
||||||
PaymentTerm.generate!(:type => 'PaymentTerm', :name => 'Net 15')
|
PaymentTerm.generate!(:type => 'PaymentTerm', :name => 'Net 15')
|
||||||
PaymentTerm.generate!(:type => 'PaymentTerm', :name => 'Net 30')
|
PaymentTerm.generate!(:type => 'PaymentTerm', :name => 'Net 30')
|
||||||
|
@user = User.generate_user_with_permission_to_manage_budget(:project => @project)
|
||||||
|
|
||||||
|
login_as(@user.login, 'contracts')
|
||||||
end
|
end
|
||||||
|
|
||||||
should "allow any user to open the new contracts form" do
|
should "block anonymous users from opening the new contract form" do
|
||||||
|
logout
|
||||||
|
visit "/projects/#{@project.identifier}/contracts/new"
|
||||||
|
|
||||||
|
assert_requires_login
|
||||||
|
end
|
||||||
|
|
||||||
|
should "block unauthorized users from opening the new contract form" do
|
||||||
|
logout
|
||||||
|
|
||||||
|
@user = User.generate!(:password => 'test', :password_confirmation => 'test')
|
||||||
|
login_as(@user.login, 'test')
|
||||||
|
|
||||||
|
visit "/projects/#{@project.identifier}/contracts/new"
|
||||||
|
|
||||||
|
assert_forbidden
|
||||||
|
end
|
||||||
|
|
||||||
|
should "allow authorized users to open the new contracts form" do
|
||||||
visit_contracts_for_project(@project)
|
visit_contracts_for_project(@project)
|
||||||
click_link 'New Contract'
|
click_link 'New Contract'
|
||||||
assert_response :success
|
assert_response :success
|
||||||
|
|||||||
@@ -6,9 +6,30 @@ class ContractsShowTest < ActionController::IntegrationTest
|
|||||||
def setup
|
def setup
|
||||||
@project = Project.generate!(:identifier => 'main').reload
|
@project = Project.generate!(:identifier => 'main').reload
|
||||||
@contract = Contract.generate!(:project => @project)
|
@contract = Contract.generate!(:project => @project)
|
||||||
|
@user = User.generate_user_with_permission_to_manage_budget(:project => @project)
|
||||||
|
|
||||||
|
login_as(@user.login, 'contracts')
|
||||||
end
|
end
|
||||||
|
|
||||||
should "allow any user to view the contract" do
|
should "block anonymous users from viewing the contract" do
|
||||||
|
logout
|
||||||
|
visit "/projects/#{@project.identifier}/contracts/#{@contract.id}"
|
||||||
|
|
||||||
|
assert_requires_login
|
||||||
|
end
|
||||||
|
|
||||||
|
should "block unauthorized users from viewing the contract" do
|
||||||
|
logout
|
||||||
|
|
||||||
|
@user = User.generate!(:password => 'test', :password_confirmation => 'test')
|
||||||
|
login_as(@user.login, 'test')
|
||||||
|
|
||||||
|
visit "/projects/#{@project.identifier}/contracts/#{@contract.id}"
|
||||||
|
|
||||||
|
assert_forbidden
|
||||||
|
end
|
||||||
|
|
||||||
|
should "allow authorized users to view the contract" do
|
||||||
visit_contracts_for_project(@project)
|
visit_contracts_for_project(@project)
|
||||||
click_link @contract.id
|
click_link @contract.id
|
||||||
assert_response :success
|
assert_response :success
|
||||||
|
|||||||
@@ -12,9 +12,38 @@ class DeliverableDetailsShowTest < ActionController::IntegrationTest
|
|||||||
@deliverable1.overhead_budgets << OverheadBudget.spawn(:budget => 200, :hours => 10)
|
@deliverable1.overhead_budgets << OverheadBudget.spawn(:budget => 200, :hours => 10)
|
||||||
|
|
||||||
@deliverable1.save!
|
@deliverable1.save!
|
||||||
|
@user = User.generate_user_with_permission_to_manage_budget(:project => @project)
|
||||||
|
|
||||||
|
login_as(@user.login, 'contracts')
|
||||||
end
|
end
|
||||||
|
|
||||||
context "for a JS request" do
|
context "for an anonymous JS request" do
|
||||||
|
should "require login" do
|
||||||
|
logout
|
||||||
|
|
||||||
|
visit "/projects/#{@project.id}/contracts/#{@contract.id}/deliverables/#{@deliverable1.id}", :get, {:format => 'js', :as => 'deliverable_details_row'}
|
||||||
|
|
||||||
|
assert_response :unauthorized
|
||||||
|
end
|
||||||
|
|
||||||
|
end
|
||||||
|
|
||||||
|
context "for an unauthorized JS request" do
|
||||||
|
should "be forbidden" do
|
||||||
|
logout
|
||||||
|
|
||||||
|
@user = User.generate!(:password => 'test', :password_confirmation => 'test')
|
||||||
|
login_as(@user.login, 'test')
|
||||||
|
|
||||||
|
visit "/projects/#{@project.id}/contracts/#{@contract.id}/deliverables/#{@deliverable1.id}", :get, {:format => 'js', :as => 'deliverable_details_row'}
|
||||||
|
|
||||||
|
assert_response :forbidden
|
||||||
|
end
|
||||||
|
|
||||||
|
end
|
||||||
|
|
||||||
|
|
||||||
|
context "for an authorized JS request" do
|
||||||
should "render the details for the deliverable" do
|
should "render the details for the deliverable" do
|
||||||
visit "/projects/#{@project.id}/contracts/#{@contract.id}/deliverables/#{@deliverable1.id}", :get, {:format => 'js', :as => 'deliverable_details_row'}
|
visit "/projects/#{@project.id}/contracts/#{@contract.id}/deliverables/#{@deliverable1.id}", :get, {:format => 'js', :as => 'deliverable_details_row'}
|
||||||
|
|
||||||
|
|||||||
@@ -8,9 +8,31 @@ class DeliverablesDeleteTest < ActionController::IntegrationTest
|
|||||||
@contract = Contract.generate!(:project => @project, :name => 'A Contract')
|
@contract = Contract.generate!(:project => @project, :name => 'A Contract')
|
||||||
@manager = User.generate!
|
@manager = User.generate!
|
||||||
@deliverable = FixedDeliverable.generate!(:contract => @contract, :manager => @manager)
|
@deliverable = FixedDeliverable.generate!(:contract => @contract, :manager => @manager)
|
||||||
|
@user = User.generate_user_with_permission_to_manage_budget(:project => @project)
|
||||||
|
|
||||||
|
login_as(@user.login, 'contracts')
|
||||||
end
|
end
|
||||||
|
|
||||||
should "allow anyone to delete the deliverable" do
|
should "block anonymous users from deleting the deliverable" do
|
||||||
|
logout
|
||||||
|
delete "/projects/#{@project.identifier}/contracts/#{@contract.id}/deliverables/#{@deliverable.id}"
|
||||||
|
follow_redirect!
|
||||||
|
|
||||||
|
assert_requires_login
|
||||||
|
end
|
||||||
|
|
||||||
|
should "block unauthorized users from deleting the deliverable" do
|
||||||
|
logout
|
||||||
|
|
||||||
|
@user = User.generate!(:password => 'test', :password_confirmation => 'test')
|
||||||
|
login_as(@user.login, 'test')
|
||||||
|
|
||||||
|
delete "/projects/#{@project.identifier}/contracts/#{@contract.id}/deliverables/#{@deliverable.id}"
|
||||||
|
|
||||||
|
assert_forbidden
|
||||||
|
end
|
||||||
|
|
||||||
|
should "allow authorized users to delete the deliverable" do
|
||||||
visit_contract_page(@contract)
|
visit_contract_page(@contract)
|
||||||
|
|
||||||
click_link_within "#deliverable_details_#{@deliverable.id}", 'Delete'
|
click_link_within "#deliverable_details_#{@deliverable.id}", 'Delete'
|
||||||
|
|||||||
@@ -12,9 +12,30 @@ class DeliverablesEditTest < ActionController::IntegrationTest
|
|||||||
@fixed_deliverable = FixedDeliverable.generate!(:contract => @contract, :manager => @manager, :title => 'The Title')
|
@fixed_deliverable = FixedDeliverable.generate!(:contract => @contract, :manager => @manager, :title => 'The Title')
|
||||||
@hourly_deliverable = HourlyDeliverable.generate!(:contract => @contract, :manager => @manager, :title => 'An Hourly')
|
@hourly_deliverable = HourlyDeliverable.generate!(:contract => @contract, :manager => @manager, :title => 'An Hourly')
|
||||||
|
|
||||||
|
@user = User.generate_user_with_permission_to_manage_budget(:project => @project)
|
||||||
|
|
||||||
|
login_as(@user.login, 'contracts')
|
||||||
end
|
end
|
||||||
|
|
||||||
should "allow any user to edit the Fixed deliverable" do
|
should "block anonymous users from editing the deliverable" do
|
||||||
|
logout
|
||||||
|
visit "/projects/#{@project.identifier}/contracts/#{@contract.id}/deliverables/#{@fixed_deliverable.id}"
|
||||||
|
|
||||||
|
assert_requires_login
|
||||||
|
end
|
||||||
|
|
||||||
|
should "block unauthorized users from editing the deliverable" do
|
||||||
|
logout
|
||||||
|
|
||||||
|
@user = User.generate!(:password => 'test', :password_confirmation => 'test')
|
||||||
|
login_as(@user.login, 'test')
|
||||||
|
|
||||||
|
visit "/projects/#{@project.identifier}/contracts/#{@contract.id}/deliverables/#{@fixed_deliverable.id}"
|
||||||
|
|
||||||
|
assert_forbidden
|
||||||
|
end
|
||||||
|
|
||||||
|
should "allow authorized users to edit the Fixed deliverable" do
|
||||||
visit_contract_page(@contract)
|
visit_contract_page(@contract)
|
||||||
click_link_within "#deliverable_details_#{@fixed_deliverable.id}", 'Edit'
|
click_link_within "#deliverable_details_#{@fixed_deliverable.id}", 'Edit'
|
||||||
assert_response :success
|
assert_response :success
|
||||||
@@ -44,7 +65,7 @@ class DeliverablesEditTest < ActionController::IntegrationTest
|
|||||||
|
|
||||||
end
|
end
|
||||||
|
|
||||||
should "allow any user to edit the Hourly deliverable" do
|
should "allow authorized users to edit the Hourly deliverable" do
|
||||||
visit_contract_page(@contract)
|
visit_contract_page(@contract)
|
||||||
click_link_within "#deliverable_details_#{@hourly_deliverable.id}", 'Edit'
|
click_link_within "#deliverable_details_#{@hourly_deliverable.id}", 'Edit'
|
||||||
assert_response :success
|
assert_response :success
|
||||||
|
|||||||
@@ -8,6 +8,9 @@ class DeliverablesListTest < ActionController::IntegrationTest
|
|||||||
@contract = Contract.generate!(:project => @project)
|
@contract = Contract.generate!(:project => @project)
|
||||||
@manager = User.generate!
|
@manager = User.generate!
|
||||||
@deliverable = FixedDeliverable.generate!(:contract => @contract, :manager => @manager)
|
@deliverable = FixedDeliverable.generate!(:contract => @contract, :manager => @manager)
|
||||||
|
@user = User.generate_user_with_permission_to_manage_budget(:project => @project)
|
||||||
|
|
||||||
|
login_as(@user.login, 'contracts')
|
||||||
end
|
end
|
||||||
|
|
||||||
should "redirect to the contract page" do
|
should "redirect to the contract page" do
|
||||||
|
|||||||
@@ -6,9 +6,30 @@ class DeliverablesNewTest < ActionController::IntegrationTest
|
|||||||
def setup
|
def setup
|
||||||
@project = Project.generate!(:identifier => 'main')
|
@project = Project.generate!(:identifier => 'main')
|
||||||
@contract = Contract.generate!(:project => @project)
|
@contract = Contract.generate!(:project => @project)
|
||||||
|
@user = User.generate_user_with_permission_to_manage_budget(:project => @project)
|
||||||
|
|
||||||
|
login_as(@user.login, 'contracts')
|
||||||
end
|
end
|
||||||
|
|
||||||
should "allow any user to open the new deliverable form" do
|
should "block anonymous users from opening the new deliverable form" do
|
||||||
|
logout
|
||||||
|
visit "/projects/#{@project.identifier}/contracts/#{@contract.id}/deliverables/new"
|
||||||
|
|
||||||
|
assert_requires_login
|
||||||
|
end
|
||||||
|
|
||||||
|
should "block unauthorized users from opening the new deliverable form" do
|
||||||
|
logout
|
||||||
|
|
||||||
|
@user = User.generate!(:password => 'test', :password_confirmation => 'test')
|
||||||
|
login_as(@user.login, 'test')
|
||||||
|
|
||||||
|
visit "/projects/#{@project.identifier}/contracts/#{@contract.id}/deliverables/new"
|
||||||
|
|
||||||
|
assert_forbidden
|
||||||
|
end
|
||||||
|
|
||||||
|
should "allow authorized users open the new deliverable form" do
|
||||||
visit_contract_page(@contract)
|
visit_contract_page(@contract)
|
||||||
click_link 'Add New'
|
click_link 'Add New'
|
||||||
assert_response :success
|
assert_response :success
|
||||||
|
|||||||
@@ -8,6 +8,9 @@ class DeliverablesShowTest < ActionController::IntegrationTest
|
|||||||
@contract = Contract.generate!(:project => @project)
|
@contract = Contract.generate!(:project => @project)
|
||||||
@manager = User.generate!
|
@manager = User.generate!
|
||||||
@deliverable = FixedDeliverable.generate!(:contract => @contract, :manager => @manager)
|
@deliverable = FixedDeliverable.generate!(:contract => @contract, :manager => @manager)
|
||||||
|
@user = User.generate_user_with_permission_to_manage_budget(:project => @project)
|
||||||
|
|
||||||
|
login_as(@user.login, 'contracts')
|
||||||
end
|
end
|
||||||
|
|
||||||
should "redirect to the contract page" do
|
should "redirect to the contract page" do
|
||||||
|
|||||||
@@ -1,17 +1,15 @@
|
|||||||
require 'test_helper'
|
require 'test_helper'
|
||||||
|
|
||||||
class DisabledContractsModuleTest < ActionController::IntegrationTest
|
class DisabledContractsModuleTest < ActionController::IntegrationTest
|
||||||
def setup
|
|
||||||
@user = User.generate!(:login => 'existing', :password => 'existing', :password_confirmation => 'existing', :admin => true)
|
|
||||||
login_as
|
|
||||||
end
|
|
||||||
|
|
||||||
context "on a project with the Contracts module disabled" do
|
context "on a project with the Contracts module disabled" do
|
||||||
setup do
|
setup do
|
||||||
@project = Project.generate!
|
@project = Project.generate!
|
||||||
@project.enabled_modules.find_by_name('contracts').destroy
|
@project.enabled_modules.find_by_name('contracts').destroy
|
||||||
@project.reload
|
@project.reload
|
||||||
assert !@project.module_enabled?(:contracts), "Contracts enabled on project"
|
assert !@project.module_enabled?(:contracts), "Contracts enabled on project"
|
||||||
|
|
||||||
|
@user = User.generate_user_with_permission_to_manage_budget(:project => @project)
|
||||||
|
login_as(@user.login, 'contracts')
|
||||||
end
|
end
|
||||||
|
|
||||||
should "not show the menu item" do
|
should "not show the menu item" do
|
||||||
|
|||||||
@@ -34,6 +34,16 @@ def User.add_to_project(user, project, role)
|
|||||||
Member.generate!(:principal => user, :project => project, :roles => [role])
|
Member.generate!(:principal => user, :project => project, :roles => [role])
|
||||||
end
|
end
|
||||||
|
|
||||||
|
def User.generate_user_with_permission_to_manage_budget(options={})
|
||||||
|
project = options[:project]
|
||||||
|
|
||||||
|
user = User.generate!(:password => 'contracts', :password_confirmation => 'contracts')
|
||||||
|
role = Role.generate!(:permissions => [:view_issues, :edit_issues, :add_issues, :manage_budget])
|
||||||
|
User.add_to_project(user, project, role)
|
||||||
|
user
|
||||||
|
end
|
||||||
|
|
||||||
|
|
||||||
module IntegrationTestHelper
|
module IntegrationTestHelper
|
||||||
def login_as(user="existing", password="existing")
|
def login_as(user="existing", password="existing")
|
||||||
visit "/login"
|
visit "/login"
|
||||||
@@ -44,6 +54,12 @@ module IntegrationTestHelper
|
|||||||
assert User.current.logged?
|
assert User.current.logged?
|
||||||
end
|
end
|
||||||
|
|
||||||
|
def logout
|
||||||
|
visit '/logout'
|
||||||
|
assert_response :success
|
||||||
|
assert !User.current.logged?
|
||||||
|
end
|
||||||
|
|
||||||
def visit_project(project)
|
def visit_project(project)
|
||||||
visit '/'
|
visit '/'
|
||||||
assert_response :success
|
assert_response :success
|
||||||
@@ -83,6 +99,11 @@ module IntegrationTestHelper
|
|||||||
assert_response :forbidden
|
assert_response :forbidden
|
||||||
assert_template 'common/403'
|
assert_template 'common/403'
|
||||||
end
|
end
|
||||||
|
|
||||||
|
def assert_requires_login
|
||||||
|
assert_response :success
|
||||||
|
assert_template 'account/login'
|
||||||
|
end
|
||||||
|
|
||||||
end
|
end
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user