2025-07-18 17:36:37 +01:00
|
|
|
# frozen_string_literal: true
|
|
|
|
|
|
2011-05-29 13:11:52 -07:00
|
|
|
#-- copyright
|
2020-01-15 11:31:26 +01:00
|
|
|
# OpenProject is an open source project management software.
|
2024-07-30 13:42:36 +02:00
|
|
|
# Copyright (C) the OpenProject GmbH
|
2011-05-30 20:52:25 +02:00
|
|
|
#
|
2011-05-29 13:11:52 -07:00
|
|
|
# This program is free software; you can redistribute it and/or
|
2013-06-05 16:27:56 +02:00
|
|
|
# modify it under the terms of the GNU General Public License version 3.
|
2011-05-30 20:52:25 +02:00
|
|
|
#
|
2013-09-16 17:59:31 +02:00
|
|
|
# OpenProject is a fork of ChiliProject, which is a fork of Redmine. The copyright follows:
|
2021-01-13 17:47:45 +01:00
|
|
|
# Copyright (C) 2006-2013 Jean-Philippe Lang
|
2013-09-16 17:59:31 +02:00
|
|
|
# Copyright (C) 2010-2013 the ChiliProject Team
|
|
|
|
|
#
|
|
|
|
|
# This program is free software; you can redistribute it and/or
|
|
|
|
|
# modify it under the terms of the GNU General Public License
|
|
|
|
|
# as published by the Free Software Foundation; either version 2
|
|
|
|
|
# of the License, or (at your option) any later version.
|
|
|
|
|
#
|
|
|
|
|
# This program is distributed in the hope that it will be useful,
|
|
|
|
|
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
|
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
|
# GNU General Public License for more details.
|
|
|
|
|
#
|
|
|
|
|
# You should have received a copy of the GNU General Public License
|
|
|
|
|
# along with this program; if not, write to the Free Software
|
|
|
|
|
# Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
|
|
|
|
|
#
|
2021-09-02 21:49:06 +02:00
|
|
|
# See COPYRIGHT and LICENSE files for more details.
|
2011-05-29 13:11:52 -07:00
|
|
|
#++
|
|
|
|
|
|
2006-06-28 18:11:03 +00:00
|
|
|
class MembersController < ApplicationController
|
2023-10-27 15:34:08 +02:00
|
|
|
include MemberHelper
|
2025-10-09 09:57:50 +02:00
|
|
|
|
2026-02-02 13:54:14 +01:00
|
|
|
before_action :find_project_by_project_id
|
2026-02-04 09:29:05 +01:00
|
|
|
before_action :find_member, except: %i[index create autocomplete_for_member destroy_by_principal]
|
2016-09-06 15:40:49 +02:00
|
|
|
before_action :authorize
|
2006-06-28 18:11:03 +00:00
|
|
|
|
2015-09-02 17:23:22 +01:00
|
|
|
def index
|
2016-08-15 15:31:39 +01:00
|
|
|
set_index_data!
|
2015-09-02 17:23:22 +01:00
|
|
|
end
|
|
|
|
|
|
2026-02-09 15:26:41 +01:00
|
|
|
def create # rubocop:disable Metrics/AbcSize
|
2023-10-27 15:34:08 +02:00
|
|
|
overall_result = []
|
2010-05-24 20:21:16 +00:00
|
|
|
|
2024-02-05 15:27:23 +00:00
|
|
|
find_or_create_users(send_notification: true) do |member_params|
|
2023-10-27 15:34:08 +02:00
|
|
|
service_call = Members::CreateService
|
|
|
|
|
.new(user: current_user)
|
|
|
|
|
.call(member_params)
|
|
|
|
|
|
2023-11-01 12:30:03 +01:00
|
|
|
overall_result.push(service_call)
|
2023-10-27 15:34:08 +02:00
|
|
|
end
|
|
|
|
|
|
|
|
|
|
if overall_result.empty?
|
2024-03-18 18:43:34 +01:00
|
|
|
flash[:error] = I18n.t("activerecord.errors.models.member.principal_blank")
|
|
|
|
|
redirect_to project_members_path(project_id: @project, status: "all")
|
2023-10-27 15:34:08 +02:00
|
|
|
elsif overall_result.all?(&:success?)
|
2024-03-18 18:43:34 +01:00
|
|
|
flash[:notice] = members_added_notice(overall_result.map(&:result))
|
2013-01-16 17:07:33 +01:00
|
|
|
|
2024-03-18 18:43:34 +01:00
|
|
|
redirect_to project_members_path(project_id: @project, status: "all")
|
2016-07-18 10:48:49 +02:00
|
|
|
else
|
2024-03-18 18:43:34 +01:00
|
|
|
display_error(overall_result.first, now: true)
|
2015-09-02 17:23:22 +01:00
|
|
|
|
2016-08-15 15:31:39 +01:00
|
|
|
set_index_data!
|
2015-09-02 17:23:22 +01:00
|
|
|
|
2016-07-18 10:48:49 +02:00
|
|
|
respond_to do |format|
|
2024-03-18 18:43:34 +01:00
|
|
|
format.html { render "index" }
|
2010-05-24 20:21:16 +00:00
|
|
|
end
|
2007-09-14 11:34:08 +00:00
|
|
|
end
|
|
|
|
|
end
|
2011-05-30 20:52:25 +02:00
|
|
|
|
2012-08-21 17:12:13 +02:00
|
|
|
def update
|
2021-04-20 13:45:42 +02:00
|
|
|
service_call = Members::UpdateService
|
|
|
|
|
.new(user: current_user, model: @member)
|
|
|
|
|
.call(permitted_params.member)
|
2017-07-17 11:05:12 +02:00
|
|
|
|
2021-04-20 13:45:42 +02:00
|
|
|
if service_call.success?
|
2024-03-18 18:43:34 +01:00
|
|
|
flash[:notice] = I18n.t(:notice_successful_update)
|
2015-09-10 11:25:40 +01:00
|
|
|
else
|
2021-04-20 13:45:42 +02:00
|
|
|
display_error(service_call)
|
2014-04-07 16:19:31 +02:00
|
|
|
end
|
2014-04-02 10:57:18 +02:00
|
|
|
|
2015-09-07 16:08:00 +01:00
|
|
|
redirect_to project_members_path(project_id: @project,
|
2015-09-02 17:23:22 +01:00
|
|
|
page: params[:page],
|
|
|
|
|
per_page: params[:per_page])
|
2007-01-26 17:59:06 +00:00
|
|
|
end
|
2007-03-12 17:59:02 +00:00
|
|
|
|
2026-02-10 10:58:57 +01:00
|
|
|
def destroy_by_principal # rubocop:disable Metrics/AbcSize
|
2026-02-02 13:54:14 +01:00
|
|
|
principal = Principal.visible.find(params[:principal_id])
|
2024-03-18 18:40:07 +01:00
|
|
|
|
|
|
|
|
service_call = Members::DeleteByPrincipalService
|
2024-06-20 16:40:03 -05:00
|
|
|
.new(user: current_user, project: @project, principal:)
|
|
|
|
|
.call(params.permit(:project, :work_package_shares_role_id))
|
2015-09-14 16:52:49 +01:00
|
|
|
|
2021-04-20 13:45:42 +02:00
|
|
|
if service_call.success?
|
2024-03-18 18:40:07 +01:00
|
|
|
flash[:notice] = I18n.t(:notice_member_removed, user: principal.name)
|
|
|
|
|
else
|
|
|
|
|
display_error(service_call)
|
2007-05-05 15:21:18 +00:00
|
|
|
end
|
2015-09-02 17:23:22 +01:00
|
|
|
|
2025-07-24 16:02:40 +02:00
|
|
|
redirect_to project_members_path(project_id: @project), status: :see_other
|
2007-03-12 17:59:02 +00:00
|
|
|
end
|
2011-05-30 20:52:25 +02:00
|
|
|
|
2023-10-23 13:52:22 +02:00
|
|
|
def autocomplete_for_member
|
2025-10-13 08:50:53 +02:00
|
|
|
type = params[:type]
|
|
|
|
|
@principals = possible_members(params[:q], 100, type:)
|
2023-10-23 13:52:22 +02:00
|
|
|
|
2025-10-13 08:50:53 +02:00
|
|
|
if type.nil? || type == "User"
|
|
|
|
|
@email = suggest_invite_via_email?(current_user, params[:q], @principals | @project.principals)
|
|
|
|
|
end
|
2023-10-23 13:52:22 +02:00
|
|
|
|
|
|
|
|
respond_to do |format|
|
|
|
|
|
format.json do
|
2026-03-20 11:59:22 +01:00
|
|
|
render json: build_members, escape: true
|
2023-10-23 13:52:22 +02:00
|
|
|
end
|
|
|
|
|
end
|
|
|
|
|
end
|
|
|
|
|
|
2012-04-24 17:03:09 +02:00
|
|
|
private
|
|
|
|
|
|
2026-02-02 13:36:51 +01:00
|
|
|
def find_member
|
|
|
|
|
@member = @project.members.visible.find(params[:id])
|
|
|
|
|
end
|
|
|
|
|
|
2026-02-04 09:29:05 +01:00
|
|
|
def authorize_for?(controller, action)
|
2023-10-27 10:45:11 +02:00
|
|
|
current_user.allowed_in_project?({ controller:, action: }, @project)
|
2016-08-09 10:57:19 +01:00
|
|
|
end
|
|
|
|
|
|
2024-10-03 22:34:05 +03:00
|
|
|
def user_allowed_to_view_emails?
|
|
|
|
|
current_user.allowed_globally?(:view_user_email)
|
|
|
|
|
end
|
|
|
|
|
|
2023-10-23 13:52:22 +02:00
|
|
|
def build_members
|
|
|
|
|
paths = API::V3::Utilities::PathHelper::ApiV3Path
|
|
|
|
|
principals = @principals.map do |principal|
|
2024-10-03 16:15:27 +03:00
|
|
|
member = {
|
2023-10-23 13:52:22 +02:00
|
|
|
id: principal.id,
|
|
|
|
|
name: principal.name,
|
|
|
|
|
href: paths.send(principal.type.underscore, principal.id)
|
|
|
|
|
}
|
2024-10-03 22:34:05 +03:00
|
|
|
member[:email] = principal.mail if user_allowed_to_view_emails?
|
2024-10-03 16:15:27 +03:00
|
|
|
member
|
2023-10-23 13:52:22 +02:00
|
|
|
end
|
|
|
|
|
|
|
|
|
|
if @email
|
2024-03-18 18:43:34 +01:00
|
|
|
principals << { id: @email, name: I18n.t("members.invite_by_mail", mail: @email) }
|
2023-10-23 13:52:22 +02:00
|
|
|
end
|
|
|
|
|
|
|
|
|
|
principals
|
|
|
|
|
end
|
|
|
|
|
|
2016-08-09 10:57:19 +01:00
|
|
|
def members_table_options(roles)
|
2024-03-18 18:40:07 +01:00
|
|
|
shared_role = WorkPackageRole.find_by(id: params[:shared_role_id])
|
|
|
|
|
shared_role_name = shared_role && Members::UserFilterComponent.mapped_shared_role_name(shared_role)
|
|
|
|
|
|
2016-08-09 10:57:19 +01:00
|
|
|
{
|
|
|
|
|
project: @project,
|
|
|
|
|
available_roles: roles,
|
2026-02-04 09:29:05 +01:00
|
|
|
authorize_update: authorize_for?("members", :update),
|
|
|
|
|
authorize_delete: authorize_for?("members", :destroy),
|
2024-07-02 15:04:09 +02:00
|
|
|
authorize_work_package_shares_view: current_user.allowed_in_project?(:view_shared_work_packages, @project),
|
|
|
|
|
authorize_work_package_shares_delete: current_user.allowed_in_project?(:share_work_packages, @project),
|
2024-03-26 17:28:13 +01:00
|
|
|
authorize_manage_user: current_user.allowed_globally?(:manage_user),
|
2024-03-18 18:40:07 +01:00
|
|
|
is_filtered: Members::UserFilterComponent.filtered?(params),
|
|
|
|
|
shared_role_name:
|
2016-08-09 10:57:19 +01:00
|
|
|
}
|
|
|
|
|
end
|
|
|
|
|
|
|
|
|
|
def members_filter_options(roles)
|
2026-04-17 10:55:43 +02:00
|
|
|
groups = Group.visible.sort
|
2023-12-19 15:43:36 +01:00
|
|
|
shares = WorkPackageRole.all
|
2023-05-17 11:26:24 +03:00
|
|
|
status = Members::UserFilterComponent.status_param(params)
|
2016-08-09 10:57:19 +01:00
|
|
|
|
2016-08-12 14:59:27 +01:00
|
|
|
{
|
|
|
|
|
groups:,
|
|
|
|
|
roles:,
|
|
|
|
|
status:,
|
2023-12-19 15:43:36 +01:00
|
|
|
shares:,
|
2016-08-14 21:05:07 +01:00
|
|
|
clear_url: project_members_path(@project),
|
|
|
|
|
project: @project
|
2016-08-12 14:59:27 +01:00
|
|
|
}
|
2016-08-09 10:57:19 +01:00
|
|
|
end
|
|
|
|
|
|
2025-10-01 13:58:16 +02:00
|
|
|
def suggest_invite_via_email?(user, query, visible_principals)
|
|
|
|
|
return false unless user_allowed_to_invite?(user)
|
|
|
|
|
|
|
|
|
|
query =~ mail_regex &&
|
|
|
|
|
visible_principals.none? { |p| p.mail == query || p.login == query } &&
|
2023-10-23 13:52:22 +02:00
|
|
|
query # finally return email
|
|
|
|
|
end
|
|
|
|
|
|
|
|
|
|
def mail_regex
|
|
|
|
|
/\A\S+@\S+\.\S+\z/
|
|
|
|
|
end
|
|
|
|
|
|
2016-08-15 15:31:39 +01:00
|
|
|
def set_index_data!
|
|
|
|
|
set_roles_and_principles!
|
|
|
|
|
|
2017-07-31 18:13:51 +02:00
|
|
|
@members = index_members
|
2016-08-15 15:31:39 +01:00
|
|
|
@members_table_options = members_table_options @roles
|
|
|
|
|
@members_filter_options = members_filter_options @roles
|
|
|
|
|
end
|
|
|
|
|
|
2015-09-02 17:23:22 +01:00
|
|
|
def set_roles_and_principles!
|
2023-10-05 15:28:31 +02:00
|
|
|
@roles = ProjectRole.givable
|
2015-09-02 17:23:22 +01:00
|
|
|
# Check if there is at least one principal that can be added to the project
|
2024-03-18 18:43:34 +01:00
|
|
|
@principals_available = possible_members("", 1)
|
2021-02-04 09:52:56 +01:00
|
|
|
end
|
|
|
|
|
|
2025-10-13 08:50:53 +02:00
|
|
|
def possible_members(criteria, limit, type: nil)
|
2021-02-04 09:52:56 +01:00
|
|
|
Principal
|
2026-02-02 13:36:51 +01:00
|
|
|
.visible
|
2025-10-13 08:50:53 +02:00
|
|
|
.possible_member(@project, type:)
|
2024-10-03 22:34:05 +03:00
|
|
|
.like(criteria, email: user_allowed_to_view_emails?)
|
2021-02-04 09:52:56 +01:00
|
|
|
.limit(limit)
|
2015-09-02 17:23:22 +01:00
|
|
|
end
|
|
|
|
|
|
2017-07-31 18:13:51 +02:00
|
|
|
def index_members
|
2023-12-19 16:18:20 +01:00
|
|
|
filters = params.slice(*Members::UserFilterComponent.filter_param_keys)
|
2017-07-31 18:13:51 +02:00
|
|
|
filters[:project_id] = @project.id.to_s
|
|
|
|
|
|
2023-05-17 11:26:24 +03:00
|
|
|
@members_query = Members::UserFilterComponent.query(filters)
|
2017-07-31 18:13:51 +02:00
|
|
|
end
|
|
|
|
|
|
2015-09-04 15:05:44 +01:00
|
|
|
def members_added_notice(members)
|
|
|
|
|
if members.size == 1
|
2020-09-16 11:26:15 +02:00
|
|
|
I18n.t(:notice_member_added, name: members.first.name)
|
2015-09-04 15:05:44 +01:00
|
|
|
else
|
2020-09-16 11:26:15 +02:00
|
|
|
I18n.t(:notice_members_added, number: members.size)
|
2015-09-04 15:05:44 +01:00
|
|
|
end
|
|
|
|
|
end
|
2020-09-17 09:15:19 +02:00
|
|
|
|
|
|
|
|
def no_create_errors?(members)
|
2023-07-13 15:06:22 +02:00
|
|
|
members.present? && members.map(&:errors).none?(&:any?)
|
2020-09-17 09:15:19 +02:00
|
|
|
end
|
|
|
|
|
|
|
|
|
|
def sort_by_groups_last(members)
|
|
|
|
|
group_ids = Group.where(id: members.map(&:user_id)).pluck(:id)
|
|
|
|
|
|
|
|
|
|
members.sort_by { |m| group_ids.include?(m.user_id) ? 1 : -1 }
|
|
|
|
|
end
|
2021-04-20 13:45:42 +02:00
|
|
|
|
2024-03-18 18:43:34 +01:00
|
|
|
def display_error(service_call, now: false)
|
|
|
|
|
message = service_call.errors.full_messages.compact.join(", ")
|
2021-04-20 13:45:42 +02:00
|
|
|
|
2024-03-18 18:43:34 +01:00
|
|
|
if now
|
|
|
|
|
flash.now[:error] = message
|
|
|
|
|
else
|
|
|
|
|
flash[:error] = message
|
|
|
|
|
end
|
2021-04-20 13:45:42 +02:00
|
|
|
end
|
2006-06-28 18:11:03 +00:00
|
|
|
end
|