Module: ActiveAdmin::BaseController::Authorization

Extended by:
ActiveSupport::Concern
Included in:
ActiveAdmin::BaseController
Defined in:
lib/active_admin/base_controller/authorization.rb

Constant Summary collapse

ACTIONS_DICTIONARY =
{
  index:   ActiveAdmin::Authorization::READ,
  show:    ActiveAdmin::Authorization::READ,
  new:     ActiveAdmin::Authorization::CREATE,
  create:  ActiveAdmin::Authorization::CREATE,
  edit:    ActiveAdmin::Authorization::UPDATE,
  update:  ActiveAdmin::Authorization::UPDATE,
  destroy: ActiveAdmin::Authorization::DESTROY
}

Instance Method Summary collapse

Instance Method Details

#action_to_permission(action) ⇒ Symbol (protected)

Converts a controller action into one of the correct Active Admin authorization names. Uses the ACTIONS_DICTIONARY to convert the action name to permission.

Parameters:

  • action (String, Symbol)

    The controller action name.

Returns:

  • (Symbol)

    The permission name to use.



95
96
97
98
99
# File 'lib/active_admin/base_controller/authorization.rb', line 95

def action_to_permission(action)
  if action && action = action.to_sym
    Authorization::ACTIONS_DICTIONARY[action] || action
  end
end

#active_admin_authorizationActiveAdmin::AuthorizationAdapter (protected)

Retrieve or instantiate the authorization instance for this resource



71
72
73
74
# File 'lib/active_admin/base_controller/authorization.rb', line 71

def active_admin_authorization
  @active_admin_authorization ||=
   active_admin_authorization_adapter.new active_admin_config, current_active_admin_user
end

#active_admin_authorization_adapterClass (protected)

Returns the class to be used as the authorization adapter

Returns:

  • (Class)


79
80
81
82
83
84
85
86
# File 'lib/active_admin/base_controller/authorization.rb', line 79

def active_admin_authorization_adapter
  adapter = active_admin_namespace.authorization_adapter
  if adapter.is_a? String
    adapter.constantize
  else
    adapter
  end
end

#authorize!(action, subject = nil) ⇒ Boolean (protected)

Authorize the action and subject. Available in the controller as well as all the views. If the action is not allowd, it raises an ActiveAdmin::AccessDenied exception.

Parameters:

  • action (Symbol)

    The action to check if the user has permission to perform on the subject.

  • subject (any) (defaults to: nil)

    The subject that the user is trying to perform the action on.

Returns:

  • (Boolean)

    True if authorized, otherwise raises an ActiveAdmin::AccessDenied.



52
53
54
55
56
57
58
# File 'lib/active_admin/base_controller/authorization.rb', line 52

def authorize!(action, subject = nil)
  unless authorized? action, subject
    raise ActiveAdmin::AccessDenied.new(current_active_admin_user,
                                        action,
                                        subject)
  end
end

#authorize_resource!(resource) ⇒ Object (protected)

Performs authorization on the resource using the current controller action as the permission action.



63
64
65
66
# File 'lib/active_admin/base_controller/authorization.rb', line 63

def authorize_resource!(resource)
  permission = action_to_permission(params[:action])
  authorize! permission, resource
end

#authorized?(action, subject = nil) ⇒ Boolean (protected)

Authorize the action and subject. Available in the controller as well as all the views.

Parameters:

  • action (Symbol)

    The action to check if the user has permission to perform on the subject.

  • subject (any) (defaults to: nil)

    The subject that the user is trying to perform the action on.

Returns:

  • (Boolean)


36
37
38
# File 'lib/active_admin/base_controller/authorization.rb', line 36

def authorized?(action, subject = nil)
  active_admin_authorization.authorized?(action, subject)
end

#dispatch_active_admin_access_denied(exception) ⇒ Object (protected)



101
102
103
# File 'lib/active_admin/base_controller/authorization.rb', line 101

def dispatch_active_admin_access_denied(exception)
  instance_exec(self, exception, &active_admin_namespace.on_unauthorized_access.to_proc)
end

#redirect_backwards_or_to_rootObject (protected)



120
121
122
# File 'lib/active_admin/base_controller/authorization.rb', line 120

def redirect_backwards_or_to_root
  redirect_back fallback_location: active_admin_root
end

#rescue_active_admin_access_denied(exception) ⇒ Object (protected)



105
106
107
108
109
110
111
112
113
114
115
116
117
118
# File 'lib/active_admin/base_controller/authorization.rb', line 105

def rescue_active_admin_access_denied(exception)
  error = exception.message

  respond_to do |format|
    format.html do
      flash[:error] = error
      redirect_backwards_or_to_root
    end

    format.csv  { render body:          error,           status: :unauthorized }
    format.json { render json: { error: error },         status: :unauthorized }
    format.xml  { render xml: "<error>#{error}</error>", status: :unauthorized }
  end
end