2014-02-13 11:42:35 -05:00
|
|
|
# mixin for all Guardian methods dealing with user permissions
|
|
|
|
module UserGuardian
|
|
|
|
|
|
|
|
def can_edit_user?(user)
|
|
|
|
is_me?(user) || is_staff?
|
|
|
|
end
|
|
|
|
|
|
|
|
def can_edit_username?(user)
|
2014-03-08 01:16:49 -05:00
|
|
|
return false if (SiteSetting.sso_overrides_username? && SiteSetting.enable_sso?)
|
2014-02-13 11:42:35 -05:00
|
|
|
return true if is_staff?
|
|
|
|
return false if SiteSetting.username_change_period <= 0
|
|
|
|
is_me?(user) && (user.post_count == 0 || user.created_at > SiteSetting.username_change_period.days.ago)
|
|
|
|
end
|
|
|
|
|
|
|
|
def can_edit_email?(user)
|
2014-03-08 01:16:49 -05:00
|
|
|
return false if (SiteSetting.sso_overrides_email? && SiteSetting.enable_sso?)
|
2014-02-13 11:42:35 -05:00
|
|
|
return false unless SiteSetting.email_editable?
|
2014-08-14 22:41:01 -04:00
|
|
|
return true if is_staff?
|
2014-02-13 11:42:35 -05:00
|
|
|
can_edit?(user)
|
|
|
|
end
|
|
|
|
|
2014-03-13 16:26:40 -04:00
|
|
|
def can_edit_name?(user)
|
|
|
|
return false if not(SiteSetting.enable_names?)
|
|
|
|
return false if (SiteSetting.sso_overrides_name? && SiteSetting.enable_sso?)
|
|
|
|
return true if is_staff?
|
|
|
|
can_edit?(user)
|
|
|
|
end
|
|
|
|
|
2014-09-02 21:32:27 -04:00
|
|
|
def can_see_notifications?(user)
|
|
|
|
is_me?(user) || is_admin?
|
|
|
|
end
|
|
|
|
|
2014-02-13 11:42:35 -05:00
|
|
|
def can_block_user?(user)
|
|
|
|
user && is_staff? && not(user.staff?)
|
|
|
|
end
|
|
|
|
|
|
|
|
def can_unblock_user?(user)
|
|
|
|
user && is_staff?
|
|
|
|
end
|
|
|
|
|
|
|
|
def can_delete_user?(user)
|
2014-07-28 13:17:37 -04:00
|
|
|
return false if user.nil? || user.admin?
|
2014-02-13 11:42:35 -05:00
|
|
|
if is_me?(user)
|
|
|
|
user.post_count <= 1
|
|
|
|
else
|
2014-07-28 13:17:37 -04:00
|
|
|
is_staff? && (user.first_post_created_at.nil? || user.first_post_created_at > SiteSetting.delete_user_max_post_age.to_i.days.ago)
|
2014-02-13 11:42:35 -05:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2015-03-06 16:44:54 -05:00
|
|
|
def can_anonymize_user?(user)
|
|
|
|
is_staff? && !user.nil? && !user.staff?
|
|
|
|
end
|
|
|
|
|
2016-05-06 13:34:33 -04:00
|
|
|
def can_reset_bounce_score?(user)
|
|
|
|
user && is_staff?
|
|
|
|
end
|
|
|
|
|
2014-09-29 16:31:05 -04:00
|
|
|
def can_check_emails?(user)
|
|
|
|
is_admin? || (is_staff? && SiteSetting.show_email_on_profile)
|
|
|
|
end
|
|
|
|
|
2014-11-27 13:51:13 -05:00
|
|
|
def restrict_user_fields?(user)
|
|
|
|
user.trust_level == TrustLevel[0] && anonymous?
|
|
|
|
end
|
|
|
|
|
2015-01-05 13:49:32 -05:00
|
|
|
def can_see_staff_info?(user)
|
|
|
|
user && is_staff?
|
|
|
|
end
|
|
|
|
|
2017-09-12 16:06:01 -04:00
|
|
|
def can_see_suspension_reason?(user)
|
|
|
|
return true unless SiteSetting.hide_suspension_reasons?
|
|
|
|
user == @user || is_staff?
|
|
|
|
end
|
|
|
|
|
2014-03-13 16:26:40 -04:00
|
|
|
end
|