History for dmpopidor / app / policies
2016-10-07
@Brian Riley
Added tooltip for 'published' checkbox on guidance page. Added confirmation alert when clicking delete on guidance and guidance groups. Removed invalid policy check for organisation id match when creating new guidance
Brian Riley committed on 7 Oct 2016
2016-09-29
@briley
fixed organisation policy file to use user.organisation instead or user.organisation_id and fixed typos
briley committed on 29 Sep 2016
2016-09-28
@xsrust
fixed issue where orgs cannot customise other org's(funders) templates. logic for this auth limiting dosent make me happy as it potentially allows organisations to submit edited json via post and change the other organisations existing sections, even if that option is not available through the ui
xsrust committed on 28 Sep 2016
2016-09-16
@xsrust
added authorization to settings/plans and settings/projects
xsrust committed on 16 Sep 2016
@xsrust
added auth and removed json from project_groups controller. additionally added constraint to projects and plans controllers that all actions must be authenticated through pundit
xsrust committed on 16 Sep 2016
@xsrust
removed unused json responses and added auth to plans controller
xsrust committed on 16 Sep 2016
@xsrust
removed json and added authorization to projects controller
xsrust committed on 16 Sep 2016
@xsrust
moved authorization logic from comments controller to policy file. Additionally removed unused crud methods
xsrust committed on 16 Sep 2016
@xsrust
moved logic for authorization out of answers controller into the policy
xsrust committed on 16 Sep 2016
@xsrust
removed authorization from home-controller as some users will not be logged in when request fielded
xsrust committed on 16 Sep 2016
@xsrust
forced auth on organisations_controller. TODO: re-check parent, children, and templates after AJAX removed
xsrust committed on 16 Sep 2016
@xsrust
added auth to home controller
xsrust committed on 16 Sep 2016
@xsrust
forced all actions to be authenticated through pundit
xsrust committed on 16 Sep 2016
2016-09-01
@xsrust
added ability to grant permissions to other users
xsrust committed on 1 Sep 2016
2016-08-18
@xsrust
bugfixes to auth
xsrust committed on 18 Aug 2016
@xsrust
finished implimenting new authorization scheme in dmptemplates
xsrust committed on 18 Aug 2016
@xsrust
updated authorization for all controllers ...
xsrust committed on 18 Aug 2016
@xsrust
added pundit auth to dmptemplates controller
xsrust committed on 18 Aug 2016
@xsrust
added pundit auth to guidance groups
xsrust committed on 18 Aug 2016
@xsrust
added pundit auth to guidances
xsrust committed on 18 Aug 2016
@xsrust
added pundit auth to organisations controller
xsrust committed on 18 Aug 2016
@xsrust
added pundit authorization to users
xsrust committed on 18 Aug 2016
@xsrust
proof of concept for pundit ...
xsrust committed on 18 Aug 2016