Add finer permission requirements for managing webhooks (#25463)
This commit is contained in:
@ -14,7 +14,7 @@ class WebhookPolicy < ApplicationPolicy
|
||||
end
|
||||
|
||||
def update?
|
||||
role.can?(:manage_webhooks)
|
||||
role.can?(:manage_webhooks) && record.required_permissions.all? { |permission| role.can?(permission) }
|
||||
end
|
||||
|
||||
def enable?
|
||||
@ -30,6 +30,6 @@ class WebhookPolicy < ApplicationPolicy
|
||||
end
|
||||
|
||||
def destroy?
|
||||
role.can?(:manage_webhooks)
|
||||
role.can?(:manage_webhooks) && record.required_permissions.all? { |permission| role.can?(permission) }
|
||||
end
|
||||
end
|
||||
|
Reference in New Issue
Block a user