- ##
- # require that the user is an administrator, or fill out a helpful error message
- # and return them to theuser page.
- def require_administrator
- unless @user.administrator?
- flash[:error] = t 'user_role.filter.not_an_administrator'
- redirect_to :controller => 'user', :action => 'view', :display_name => @this_user.display_name
+ authorize_resource
+
+ before_action :lookup_user
+ before_action :require_valid_role
+ before_action :not_in_role, :only => :create
+ before_action :in_role, :only => :destroy
+
+ def create
+ @user.roles.create(:role => @role, :granter => current_user)
+ redirect_to user_path(@user)
+ end
+
+ def destroy
+ # checks that administrator role is not revoked from current user
+ if current_user == @user && @role == "administrator"
+ flash[:error] = t("user_role.filter.not_revoke_admin_current_user")
+ else
+ UserRole.where(:user => @user, :role => @role).delete_all