15803: Tweak text on user admin page
[arvados.git] / apps / workbench / app / views / users / _show_admin.html.erb
1 <%# Copyright (C) The Arvados Authors. All rights reserved.
2
3 SPDX-License-Identifier: AGPL-3.0 %>
4
5 <div class="row">
6   <div class="col-md-6">
7
8     <p>
9       This button sets up a user.  After setup, they will be able use
10       Arvados.  This dialog box also allows you to optionally set up a
11       shell account for this user.  The login name is automatically
12       generated from the user's e-mail address.
13     </p>
14
15     <%= link_to "Setup account #{'for ' if @object.full_name.present?} #{@object.full_name}", setup_popup_user_url(id: @object.uuid),  {class: 'btn btn-primary', :remote => true, 'data-toggle' =>  "modal", 'data-target' => '#user-setup-modal-window'}  %>
16
17     <p style="margin-top: 3em">
18       As an admin, you can deactivate and reset this user. This will
19       remove all repository/VM permissions for the user. If you
20       "setup" the user again, the user will have to sign the user
21       agreement again.
22     </p>
23
24     <%= button_to "Deactivate #{@object.full_name}", unsetup_user_url(id: @object.uuid), class: 'btn btn-primary', data: {confirm: "Are you sure you want to deactivate #{@object.full_name}?"} %>
25
26     <p style="margin-top: 3em">
27       As an admin, you can log in as this user. When you&rsquo;ve
28       finished, you will need to log out and log in again with your
29       own account.
30     </p>
31
32     <%= button_to "Log in as #{@object.full_name}", sudo_user_url(id: @object.uuid), class: 'btn btn-primary' %>
33   </div>
34   <div class="col-md-6">
35     <div class="panel panel-default">
36       <div class="panel-heading">
37         Group memberships
38
39         <div class="pull-right">
40           <%= link_to raw('<i class="fa fa-plus"></i> Add new group'), "#",
41                        {class: 'btn btn-xs btn-primary', 'data-toggle' => "modal",
42                         'data-target' => '#add-group-modal'}  %>
43         </div>
44       </div>
45       <div class="panel-body">
46         <div class="alert alert-info">
47           <b>Tip:</b> in most cases, you want <i>both permissions at once</i> for a given group.
48           <br/>
49           The user&rarr;group permission is can_manage.
50           <br/>
51           The group&rarr;user permission is can_read.
52         </div>
53         <form>
54           <% permitted_group_perms = {}
55              Link.filter([
56              ['tail_uuid', '=', @object.uuid],
57              ['head_uuid', 'is_a', 'arvados#group'],
58              ['link_class', '=', 'permission'],
59              ]).each do |perm|
60                permitted_group_perms[perm.head_uuid] = perm.uuid
61              end %>
62           <% member_group_perms = {}
63              Link.permissions_for(@object).each do |perm|
64                member_group_perms[perm.tail_uuid] = perm.uuid
65              end %>
66           <% Group.order(['name']).where(group_class: 'role').each do |group| %>
67             <div>
68               <label class="checkbox-inline" data-toggle-permission="true" data-permission-tail="<%= @object.uuid %>" data-permission-name="can_manage">
69                 <%= check_box_tag(
70                     'group_uuids[]',
71                     group.uuid,
72                     permitted_group_perms[group.uuid],
73                     disabled: (group.owner_uuid == @object.uuid),
74                     data: {
75                       permission_head: group.uuid,
76                       permission_uuid: permitted_group_perms[group.uuid] || 'x'}) %>
77                 <small>user&rarr;group</small>
78               </label>
79               <label class="checkbox-inline" data-toggle-permission="true" data-permission-head="<%= @object.uuid %>" data-permission-name="can_read">
80                 <%= check_box_tag(
81                     'group_uuids[]',
82                     group.uuid,
83                     member_group_perms[group.uuid],
84                     disabled: (group.owner_uuid == @object.uuid),
85                     data: {
86                       permission_tail: group.uuid,
87                       permission_uuid: member_group_perms[group.uuid] || 'x'}) %>
88                 <small>group&rarr;user</small>
89               </label>
90               <label class="checkbox-inline">
91                 <%= group.name || '(unnamed)' %> <span class="deemphasize">(owned by <%= User.find?(group.owner_uuid).andand.full_name %>)</span>
92               </label>
93             </div>
94           <% end.empty? and begin %>
95             <div>
96               (No groups defined.)
97             </div>
98           <% end %>
99         </form>
100       </div>
101       <div class="panel-footer">
102         These groups (roles) can also be managed from the command line. For example:
103         <ul>
104           <li><code>arv group create \<br/>--group '{"group_class":"role","name":"New group"}'</code></li>
105           <li><code>arv group list \<br/>--filters '[["group_class","=","role"]]' \<br/>--select '["uuid","name"]'</code></li>
106           <li><code>arv edit <i>uuid</i></code></li>
107         </ul>
108       </div>
109     </div>
110   </div>
111 </div>
112
113 <div id="user-setup-modal-window" class="modal fade" role="dialog" aria-labelledby="myModalLabel" aria-hidden="true"></div>
114 <%= render partial: "add_group_modal" %>