before_action :authorize_web
before_action :set_locale
- before_action :require_user
- before_action :check_permission
+
+ authorize_resource
+
before_action :find_issue, :only => [:show, :resolve, :reopen, :ignore]
def index
@title = t ".title"
@issue_types = []
- @issue_types.concat %w[Note] if current_user.moderator?
- @issue_types.concat %w[DiaryEntry DiaryComment User] if current_user.administrator?
+ @issue_types.push("Note") if current_user.moderator?
+ @issue_types.push("DiaryEntry", "DiaryComment", "User") if current_user.administrator?
@users = User.joins(:roles).where(:user_roles => { :role => current_user.roles.map(&:role) }).distinct
@issues = Issue.visible_to(current_user)
@new_comment = IssueComment.new(:issue => @issue)
end
- # Status Transistions
+ # Status Transitions
def resolve
if @issue.resolve
+ @issue.updated_by = current_user.id
@issue.save!
redirect_to @issue, :notice => t(".resolved")
else
private
def find_issue
- @issue = Issue.find(params[:id])
- end
-
- def check_permission
- unless current_user.administrator? || current_user.moderator?
- flash[:error] = t("application.require_moderator_or_admin.not_a_moderator_or_admin")
- redirect_to root_path
- end
+ @issue = Issue.visible_to(current_user).find(params[:id])
+ rescue ActiveRecord::RecordNotFound
+ redirect_to :controller => "errors", :action => "not_found"
end
end