Skip to content

Commit

Permalink
Finish up subscriptions permissions for users / groups. Close #74.
Browse files Browse the repository at this point in the history
  • Loading branch information
bamnet committed Jun 19, 2012
1 parent 5542ceb commit 2238e2c
Show file tree
Hide file tree
Showing 2 changed files with 46 additions and 1 deletion.
6 changes: 5 additions & 1 deletion app/models/ability.rb
Original file line number Diff line number Diff line change
Expand Up @@ -104,7 +104,11 @@ def user_abilities(user)

#Subscriptions
#Only the owning group or user can manage screen subscriptions
can :manage, Subscription, :screen => { :owner_id => user.id}
can :manage, Subscription, :screen => { :owner_id => user.id, :owner_type => 'User'}
can :manage, Subscription do |subscription|
screen = subscription.screen
screen.owner.is_a?(Group) && screen.owner.leaders.include?(user)
end

# Users can read group screens
can :read, Screen do |screen|
Expand Down
41 changes: 41 additions & 0 deletions test/unit/abilities/user/subscription_test.rb
Original file line number Diff line number Diff line change
@@ -0,0 +1,41 @@
require 'test_helper'

class UserSubscriptionAbilityTest < ActiveSupport::TestCase
def setup
@katie = users(:katie)
@kristen = users(:kristen)
@feed = feeds(:service)
@kt_screen = screens(:one)
@wtg_screen = screens(:two)
@subscription = Subscription.new(:feed => @feed)
end

test "Screen user owner all access" do
abilities = [:update, :delete, :read]
ability = Ability.new(@katie)
@subscription.screen = @kt_screen
abilities.each do |action|
assert ability.can?(action, @subscription)
end

ability = Ability.new(@kristen)
abilities.each do |action|
assert ability.cannot?(action, @subscription)
end
end

test "Screen group owner all access" do
abilities = [:update, :delete, :read]
ability = Ability.new(@katie)
@subscription.screen = @wtg_screen
abilities.each do |action|
assert ability.can?(action, @subscription)
end

ability = Ability.new(@kristen)
abilities.each do |action|
assert ability.cannot?(action, @subscription)
end
end
end

0 comments on commit 2238e2c

Please sign in to comment.