Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
Ref #4248
This PR aims at fixing permission checks for showing the
new order
button in the admin area.We're currently using the
manage
permission, which seems to be a bit too much for just showing a button, given thatmanage
is the maximum level of permission for a resource. Checking for thecreate
permission would be much more appropriate.In order to achieve the goal, the
DefaultCustomer
permission rule for creating orders has been made stricter, so by default users can create a order only when:email
field (guest checkout);A few specs were updated, as a consequence.
Checklist: