Skip to content
Snippets Groups Projects
Select Git revision
  • ag-test
  • rs-test
  • master default protected
  • test-me-pa
  • mksionek-master-patch-52381
  • new-branch-10
  • test-conflicts
  • test-suggestions
  • alejandro-test
  • patch-25
  • winh-test-image-doscussion
  • stg-lfs-image-test-2
  • stg-lfs-image-test
  • test42016
  • issue_42016
  • issue-32709
  • add-codeowners
  • ClemMakesApps-master-patch-62759
  • bvl-staging-test
  • bvl-merge-base-api
  • v9.2.0-rc6 protected
  • v9.2.0-rc5 protected
  • v9.2.0-rc4 protected
  • v9.2.0-rc3 protected
  • v9.1.4 protected
  • v9.2.0-rc2 protected
  • v9.2.0-rc1 protected
  • v9.1.3 protected
  • v8.17.6 protected
  • v9.0.7 protected
  • v9.1.2 protected
  • v9.1.1 protected
  • v9.2.0.pre protected
  • v9.1.0 protected
  • v9.1.0-rc7 protected
  • v9.1.0-rc6 protected
  • v9.0.6 protected
  • v9.1.0-rc5 protected
  • v9.1.0-rc4 protected
  • v9.1.0-rc3 protected
40 results

user_policy.rb

  • Timothy Andrew's avatar
    6fdb17cb
    Don't allow deleting a ghost user. · 6fdb17cb
    Timothy Andrew authored
    - Add a `destroy_user` ability. This didn't exist before, and was implicit in
      other abilities (only admins could access the admin area, so only they could
      destroy all users; a user can only access their own account page, and so can
      destroy only themselves).
    
    - Grant this ability to admins, and when the current user is trying to destroy
      themselves. Disallow destroying ghost users in all cases.
    
    - Modify the `Users::DestroyService` to check this ability. Also check it in
      views to decide whether or not to show the "Delete User" button.
    
    - Add a short summary of the Ghost User to the bio.
    6fdb17cb
    History
    Don't allow deleting a ghost user.
    Timothy Andrew authored
    - Add a `destroy_user` ability. This didn't exist before, and was implicit in
      other abilities (only admins could access the admin area, so only they could
      destroy all users; a user can only access their own account page, and so can
      destroy only themselves).
    
    - Grant this ability to admins, and when the current user is trying to destroy
      themselves. Disallow destroying ghost users in all cases.
    
    - Modify the `Users::DestroyService` to check this ability. Also check it in
      views to decide whether or not to show the "Delete User" button.
    
    - Add a short summary of the Ghost User to the bio.
Code owners
Assign users and groups as approvers for specific file changes. Learn more.