##// END OF EJS Templates
Do not authorize project identifier with numbers only (would be interpreted as the project id in urls)....
Jean-Philippe Lang -
r1094:0123dc36515d
parent child
Show More
@@ -1,233 +1,234
1 # redMine - project management software
1 # redMine - project management software
2 # Copyright (C) 2006 Jean-Philippe Lang
2 # Copyright (C) 2006 Jean-Philippe Lang
3 #
3 #
4 # This program is free software; you can redistribute it and/or
4 # This program is free software; you can redistribute it and/or
5 # modify it under the terms of the GNU General Public License
5 # modify it under the terms of the GNU General Public License
6 # as published by the Free Software Foundation; either version 2
6 # as published by the Free Software Foundation; either version 2
7 # of the License, or (at your option) any later version.
7 # of the License, or (at your option) any later version.
8 #
8 #
9 # This program is distributed in the hope that it will be useful,
9 # This program is distributed in the hope that it will be useful,
10 # but WITHOUT ANY WARRANTY; without even the implied warranty of
10 # but WITHOUT ANY WARRANTY; without even the implied warranty of
11 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
11 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 # GNU General Public License for more details.
12 # GNU General Public License for more details.
13 #
13 #
14 # You should have received a copy of the GNU General Public License
14 # You should have received a copy of the GNU General Public License
15 # along with this program; if not, write to the Free Software
15 # along with this program; if not, write to the Free Software
16 # Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
16 # Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
17
17
18 class Project < ActiveRecord::Base
18 class Project < ActiveRecord::Base
19 # Project statuses
19 # Project statuses
20 STATUS_ACTIVE = 1
20 STATUS_ACTIVE = 1
21 STATUS_ARCHIVED = 9
21 STATUS_ARCHIVED = 9
22
22
23 has_many :members, :include => :user, :conditions => "#{User.table_name}.status=#{User::STATUS_ACTIVE}"
23 has_many :members, :include => :user, :conditions => "#{User.table_name}.status=#{User::STATUS_ACTIVE}"
24 has_many :users, :through => :members
24 has_many :users, :through => :members
25 has_many :custom_values, :dependent => :delete_all, :as => :customized
25 has_many :custom_values, :dependent => :delete_all, :as => :customized
26 has_many :enabled_modules, :dependent => :delete_all
26 has_many :enabled_modules, :dependent => :delete_all
27 has_and_belongs_to_many :trackers, :order => "#{Tracker.table_name}.position"
27 has_and_belongs_to_many :trackers, :order => "#{Tracker.table_name}.position"
28 has_many :issues, :dependent => :destroy, :order => "#{Issue.table_name}.created_on DESC", :include => [:status, :tracker]
28 has_many :issues, :dependent => :destroy, :order => "#{Issue.table_name}.created_on DESC", :include => [:status, :tracker]
29 has_many :issue_changes, :through => :issues, :source => :journals
29 has_many :issue_changes, :through => :issues, :source => :journals
30 has_many :versions, :dependent => :destroy, :order => "#{Version.table_name}.effective_date DESC, #{Version.table_name}.name DESC"
30 has_many :versions, :dependent => :destroy, :order => "#{Version.table_name}.effective_date DESC, #{Version.table_name}.name DESC"
31 has_many :time_entries, :dependent => :delete_all
31 has_many :time_entries, :dependent => :delete_all
32 has_many :queries, :dependent => :delete_all
32 has_many :queries, :dependent => :delete_all
33 has_many :documents, :dependent => :destroy
33 has_many :documents, :dependent => :destroy
34 has_many :news, :dependent => :delete_all, :include => :author
34 has_many :news, :dependent => :delete_all, :include => :author
35 has_many :issue_categories, :dependent => :delete_all, :order => "#{IssueCategory.table_name}.name"
35 has_many :issue_categories, :dependent => :delete_all, :order => "#{IssueCategory.table_name}.name"
36 has_many :boards, :order => "position ASC"
36 has_many :boards, :order => "position ASC"
37 has_one :repository, :dependent => :destroy
37 has_one :repository, :dependent => :destroy
38 has_many :changesets, :through => :repository
38 has_many :changesets, :through => :repository
39 has_one :wiki, :dependent => :destroy
39 has_one :wiki, :dependent => :destroy
40 # Custom field for the project issues
40 # Custom field for the project issues
41 has_and_belongs_to_many :custom_fields,
41 has_and_belongs_to_many :custom_fields,
42 :class_name => 'IssueCustomField',
42 :class_name => 'IssueCustomField',
43 :order => "#{CustomField.table_name}.position",
43 :order => "#{CustomField.table_name}.position",
44 :join_table => "#{table_name_prefix}custom_fields_projects#{table_name_suffix}",
44 :join_table => "#{table_name_prefix}custom_fields_projects#{table_name_suffix}",
45 :association_foreign_key => 'custom_field_id'
45 :association_foreign_key => 'custom_field_id'
46
46
47 acts_as_tree :order => "name", :counter_cache => true
47 acts_as_tree :order => "name", :counter_cache => true
48
48
49 acts_as_searchable :columns => ['name', 'description'], :project_key => 'id'
49 acts_as_searchable :columns => ['name', 'description'], :project_key => 'id'
50 acts_as_event :title => Proc.new {|o| "#{l(:label_project)}: #{o.name}"},
50 acts_as_event :title => Proc.new {|o| "#{l(:label_project)}: #{o.name}"},
51 :url => Proc.new {|o| {:controller => 'projects', :action => 'show', :id => o.id}}
51 :url => Proc.new {|o| {:controller => 'projects', :action => 'show', :id => o.id}}
52
52
53 attr_protected :status, :enabled_module_names
53 attr_protected :status, :enabled_module_names
54
54
55 validates_presence_of :name, :identifier
55 validates_presence_of :name, :identifier
56 validates_uniqueness_of :name, :identifier
56 validates_uniqueness_of :name, :identifier
57 validates_associated :custom_values, :on => :update
57 validates_associated :custom_values, :on => :update
58 validates_associated :repository, :wiki
58 validates_associated :repository, :wiki
59 validates_length_of :name, :maximum => 30
59 validates_length_of :name, :maximum => 30
60 validates_length_of :homepage, :maximum => 60
60 validates_length_of :homepage, :maximum => 60
61 validates_length_of :identifier, :in => 3..20
61 validates_length_of :identifier, :in => 3..20
62 validates_format_of :identifier, :with => /^[a-z0-9\-]*$/
62 validates_format_of :identifier, :with => /^[a-z0-9\-]*$/
63
63
64 before_destroy :delete_all_members
64 before_destroy :delete_all_members
65
65
66 def identifier=(identifier)
66 def identifier=(identifier)
67 super unless identifier_frozen?
67 super unless identifier_frozen?
68 end
68 end
69
69
70 def identifier_frozen?
70 def identifier_frozen?
71 errors[:identifier].nil? && !(new_record? || identifier.blank?)
71 errors[:identifier].nil? && !(new_record? || identifier.blank?)
72 end
72 end
73
73
74 def issues_with_subprojects(include_subprojects=false)
74 def issues_with_subprojects(include_subprojects=false)
75 conditions = nil
75 conditions = nil
76 if include_subprojects && !active_children.empty?
76 if include_subprojects && !active_children.empty?
77 ids = [id] + active_children.collect {|c| c.id}
77 ids = [id] + active_children.collect {|c| c.id}
78 conditions = ["#{Issue.table_name}.project_id IN (#{ids.join(',')})"]
78 conditions = ["#{Issue.table_name}.project_id IN (#{ids.join(',')})"]
79 end
79 end
80 conditions ||= ["#{Issue.table_name}.project_id = ?", id]
80 conditions ||= ["#{Issue.table_name}.project_id = ?", id]
81 # Quick and dirty fix for Rails 2 compatibility
81 # Quick and dirty fix for Rails 2 compatibility
82 Issue.send(:with_scope, :find => { :conditions => conditions }) do
82 Issue.send(:with_scope, :find => { :conditions => conditions }) do
83 yield
83 yield
84 end
84 end
85 end
85 end
86
86
87 # Return all issues status changes for the project between the 2 given dates
87 # Return all issues status changes for the project between the 2 given dates
88 def issues_status_changes(from, to)
88 def issues_status_changes(from, to)
89 Journal.find(:all, :include => [:issue, :details, :user],
89 Journal.find(:all, :include => [:issue, :details, :user],
90 :conditions => ["#{Journal.table_name}.journalized_type = 'Issue'" +
90 :conditions => ["#{Journal.table_name}.journalized_type = 'Issue'" +
91 " AND #{Issue.table_name}.project_id = ?" +
91 " AND #{Issue.table_name}.project_id = ?" +
92 " AND #{JournalDetail.table_name}.prop_key = 'status_id'" +
92 " AND #{JournalDetail.table_name}.prop_key = 'status_id'" +
93 " AND #{Journal.table_name}.created_on BETWEEN ? AND ?",
93 " AND #{Journal.table_name}.created_on BETWEEN ? AND ?",
94 id, from, to+1])
94 id, from, to+1])
95 end
95 end
96
96
97 # returns latest created projects
97 # returns latest created projects
98 # non public projects will be returned only if user is a member of those
98 # non public projects will be returned only if user is a member of those
99 def self.latest(user=nil, count=5)
99 def self.latest(user=nil, count=5)
100 find(:all, :limit => count, :conditions => visible_by(user), :order => "created_on DESC")
100 find(:all, :limit => count, :conditions => visible_by(user), :order => "created_on DESC")
101 end
101 end
102
102
103 def self.visible_by(user=nil)
103 def self.visible_by(user=nil)
104 if user && user.admin?
104 if user && user.admin?
105 return "#{Project.table_name}.status=#{Project::STATUS_ACTIVE}"
105 return "#{Project.table_name}.status=#{Project::STATUS_ACTIVE}"
106 elsif user && user.memberships.any?
106 elsif user && user.memberships.any?
107 return "#{Project.table_name}.status=#{Project::STATUS_ACTIVE} AND (#{Project.table_name}.is_public = #{connection.quoted_true} or #{Project.table_name}.id IN (#{user.memberships.collect{|m| m.project_id}.join(',')}))"
107 return "#{Project.table_name}.status=#{Project::STATUS_ACTIVE} AND (#{Project.table_name}.is_public = #{connection.quoted_true} or #{Project.table_name}.id IN (#{user.memberships.collect{|m| m.project_id}.join(',')}))"
108 else
108 else
109 return "#{Project.table_name}.status=#{Project::STATUS_ACTIVE} AND #{Project.table_name}.is_public = #{connection.quoted_true}"
109 return "#{Project.table_name}.status=#{Project::STATUS_ACTIVE} AND #{Project.table_name}.is_public = #{connection.quoted_true}"
110 end
110 end
111 end
111 end
112
112
113 def self.find(*args)
113 def self.find(*args)
114 if args.first && args.first.is_a?(String) && !args.first.match(/^\d*$/)
114 if args.first && args.first.is_a?(String) && !args.first.match(/^\d*$/)
115 project = find_by_identifier(*args)
115 project = find_by_identifier(*args)
116 raise ActiveRecord::RecordNotFound, "Couldn't find Project with identifier=#{args.first}" if project.nil?
116 raise ActiveRecord::RecordNotFound, "Couldn't find Project with identifier=#{args.first}" if project.nil?
117 project
117 project
118 else
118 else
119 super
119 super
120 end
120 end
121 end
121 end
122
122
123 def to_param
123 def to_param
124 identifier
124 identifier
125 end
125 end
126
126
127 def active?
127 def active?
128 self.status == STATUS_ACTIVE
128 self.status == STATUS_ACTIVE
129 end
129 end
130
130
131 def archive
131 def archive
132 # Archive subprojects if any
132 # Archive subprojects if any
133 children.each do |subproject|
133 children.each do |subproject|
134 subproject.archive
134 subproject.archive
135 end
135 end
136 update_attribute :status, STATUS_ARCHIVED
136 update_attribute :status, STATUS_ARCHIVED
137 end
137 end
138
138
139 def unarchive
139 def unarchive
140 return false if parent && !parent.active?
140 return false if parent && !parent.active?
141 update_attribute :status, STATUS_ACTIVE
141 update_attribute :status, STATUS_ACTIVE
142 end
142 end
143
143
144 def active_children
144 def active_children
145 children.select {|child| child.active?}
145 children.select {|child| child.active?}
146 end
146 end
147
147
148 # Returns an array of the trackers used by the project and its sub projects
148 # Returns an array of the trackers used by the project and its sub projects
149 def rolled_up_trackers
149 def rolled_up_trackers
150 @rolled_up_trackers ||=
150 @rolled_up_trackers ||=
151 Tracker.find(:all, :include => :projects,
151 Tracker.find(:all, :include => :projects,
152 :select => "DISTINCT #{Tracker.table_name}.*",
152 :select => "DISTINCT #{Tracker.table_name}.*",
153 :conditions => ["#{Project.table_name}.id = ? OR #{Project.table_name}.parent_id = ?", id, id],
153 :conditions => ["#{Project.table_name}.id = ? OR #{Project.table_name}.parent_id = ?", id, id],
154 :order => "#{Tracker.table_name}.position")
154 :order => "#{Tracker.table_name}.position")
155 end
155 end
156
156
157 # Deletes all project's members
157 # Deletes all project's members
158 def delete_all_members
158 def delete_all_members
159 Member.delete_all(['project_id = ?', id])
159 Member.delete_all(['project_id = ?', id])
160 end
160 end
161
161
162 # Users issues can be assigned to
162 # Users issues can be assigned to
163 def assignable_users
163 def assignable_users
164 members.select {|m| m.role.assignable?}.collect {|m| m.user}.sort
164 members.select {|m| m.role.assignable?}.collect {|m| m.user}.sort
165 end
165 end
166
166
167 # Returns the mail adresses of users that should be always notified on project events
167 # Returns the mail adresses of users that should be always notified on project events
168 def recipients
168 def recipients
169 members.select {|m| m.mail_notification? || m.user.mail_notification?}.collect {|m| m.user.mail}
169 members.select {|m| m.mail_notification? || m.user.mail_notification?}.collect {|m| m.user.mail}
170 end
170 end
171
171
172 # Returns an array of all custom fields enabled for project issues
172 # Returns an array of all custom fields enabled for project issues
173 # (explictly associated custom fields and custom fields enabled for all projects)
173 # (explictly associated custom fields and custom fields enabled for all projects)
174 def custom_fields_for_issues(tracker)
174 def custom_fields_for_issues(tracker)
175 all_custom_fields.select {|c| tracker.custom_fields.include? c }
175 all_custom_fields.select {|c| tracker.custom_fields.include? c }
176 end
176 end
177
177
178 def all_custom_fields
178 def all_custom_fields
179 @all_custom_fields ||= (IssueCustomField.for_all + custom_fields).uniq
179 @all_custom_fields ||= (IssueCustomField.for_all + custom_fields).uniq
180 end
180 end
181
181
182 def <=>(project)
182 def <=>(project)
183 name.downcase <=> project.name.downcase
183 name.downcase <=> project.name.downcase
184 end
184 end
185
185
186 def to_s
186 def to_s
187 name
187 name
188 end
188 end
189
189
190 # Returns a short description of the projects (first lines)
190 # Returns a short description of the projects (first lines)
191 def short_description(length = 255)
191 def short_description(length = 255)
192 description.gsub(/^(.{#{length}}[^\n]*).*$/m, '\1').strip if description
192 description.gsub(/^(.{#{length}}[^\n]*).*$/m, '\1').strip if description
193 end
193 end
194
194
195 def allows_to?(action)
195 def allows_to?(action)
196 if action.is_a? Hash
196 if action.is_a? Hash
197 allowed_actions.include? "#{action[:controller]}/#{action[:action]}"
197 allowed_actions.include? "#{action[:controller]}/#{action[:action]}"
198 else
198 else
199 allowed_permissions.include? action
199 allowed_permissions.include? action
200 end
200 end
201 end
201 end
202
202
203 def module_enabled?(module_name)
203 def module_enabled?(module_name)
204 module_name = module_name.to_s
204 module_name = module_name.to_s
205 enabled_modules.detect {|m| m.name == module_name}
205 enabled_modules.detect {|m| m.name == module_name}
206 end
206 end
207
207
208 def enabled_module_names=(module_names)
208 def enabled_module_names=(module_names)
209 enabled_modules.clear
209 enabled_modules.clear
210 module_names = [] unless module_names && module_names.is_a?(Array)
210 module_names = [] unless module_names && module_names.is_a?(Array)
211 module_names.each do |name|
211 module_names.each do |name|
212 enabled_modules << EnabledModule.new(:name => name.to_s)
212 enabled_modules << EnabledModule.new(:name => name.to_s)
213 end
213 end
214 end
214 end
215
215
216 protected
216 protected
217 def validate
217 def validate
218 errors.add(parent_id, " must be a root project") if parent and parent.parent
218 errors.add(parent_id, " must be a root project") if parent and parent.parent
219 errors.add_to_base("A project with subprojects can't be a subproject") if parent and children.size > 0
219 errors.add_to_base("A project with subprojects can't be a subproject") if parent and children.size > 0
220 errors.add(:identifier, :activerecord_error_invalid) if !identifier.blank? && identifier.match(/^\d*$/)
220 end
221 end
221
222
222 private
223 private
223 def allowed_permissions
224 def allowed_permissions
224 @allowed_permissions ||= begin
225 @allowed_permissions ||= begin
225 module_names = enabled_modules.collect {|m| m.name}
226 module_names = enabled_modules.collect {|m| m.name}
226 Redmine::AccessControl.modules_permissions(module_names).collect {|p| p.name}
227 Redmine::AccessControl.modules_permissions(module_names).collect {|p| p.name}
227 end
228 end
228 end
229 end
229
230
230 def allowed_actions
231 def allowed_actions
231 @actions_allowed ||= allowed_permissions.inject([]) { |actions, permission| actions += Redmine::AccessControl.allowed_actions(permission) }.flatten
232 @actions_allowed ||= allowed_permissions.inject([]) { |actions, permission| actions += Redmine::AccessControl.allowed_actions(permission) }.flatten
232 end
233 end
233 end
234 end
General Comments 0
You need to be logged in to leave comments. Login now