metamaps--metamaps/app/controllers/application_controller.rb

86 lines
2 KiB
Ruby
Raw Permalink Normal View History

2016-09-24 03:00:46 +00:00
# frozen_string_literal: true
2012-09-23 02:39:12 +00:00
class ApplicationController < ActionController::Base
2016-03-25 04:26:07 +00:00
include ApplicationHelper
2016-02-13 09:28:09 +00:00
include Pundit
2016-03-11 22:37:32 +00:00
include PunditExtra
2016-03-11 13:35:48 +00:00
rescue_from Pundit::NotAuthorizedError, with: :handle_unauthorized
protect_from_forgery(with: :exception)
2015-11-03 14:22:53 +00:00
2016-09-24 04:27:34 +00:00
before_action :invite_link
2016-02-19 01:23:39 +00:00
after_action :allow_embedding
2016-03-25 04:26:07 +00:00
def default_serializer_options
{ root: false }
end
# this is for global login
include ContentHelper
2015-12-22 18:16:03 +00:00
2012-09-23 02:39:12 +00:00
helper_method :user
helper_method :authenticated?
helper_method :admin?
2015-12-22 18:16:03 +00:00
2014-10-07 21:46:09 +00:00
def after_sign_in_path_for(resource)
sign_in_url = url_for(action: 'new', controller: 'sessions', only_path: false)
2014-10-07 21:46:09 +00:00
if request.referer == sign_in_url
super
elsif params[:uv_login] == '1'
'http://support.metamaps.cc/login_success?sso=' + current_sso_token
2014-10-07 21:46:09 +00:00
else
stored_location_for(resource) || request.referer || root_path
end
end
2015-12-22 18:16:03 +00:00
2016-03-11 13:35:48 +00:00
def handle_unauthorized
if authenticated?
head :forbidden # TODO: make this better
else
redirect_to new_user_session_path, notice: 'Try signing in to do that.'
end
2016-03-11 13:35:48 +00:00
end
2016-03-25 04:26:07 +00:00
private
2012-09-23 02:39:12 +00:00
2016-09-24 04:27:34 +00:00
def invite_link
@invite_link = "#{request.base_url}/join" + (current_user ? "?code=#{current_user.code}" : '')
2016-03-29 14:34:47 +00:00
end
2012-09-23 02:39:12 +00:00
def require_no_user
2016-09-24 04:27:34 +00:00
return true unless authenticated?
redirect_to edit_user_path(user), notice: 'You must be logged out.'
return false
2012-09-23 02:39:12 +00:00
end
2015-12-22 18:16:03 +00:00
2012-09-23 02:39:12 +00:00
def require_user
2016-09-24 04:27:34 +00:00
return true if authenticated?
redirect_to new_user_session_path, notice: 'You must be logged in.'
return false
2012-09-23 02:39:12 +00:00
end
2015-12-22 18:16:03 +00:00
def require_admin
2016-09-24 03:00:46 +00:00
return true if authenticated? && admin?
redirect_to root_url, notice: 'You need to be an admin for that.'
false
end
2015-12-22 18:16:03 +00:00
2012-09-23 02:39:12 +00:00
def user
current_user
end
2015-12-22 18:16:03 +00:00
2012-09-23 02:39:12 +00:00
def authenticated?
current_user
end
2015-12-22 18:16:03 +00:00
def admin?
authenticated? && current_user.admin
end
2015-11-03 14:22:53 +00:00
2016-02-19 01:23:39 +00:00
def allow_embedding
# allow all
2016-02-19 01:23:39 +00:00
response.headers.except! 'X-Frame-Options'
# or allow a whitelist
# response.headers['X-Frame-Options'] = 'ALLOW-FROM http://blog.metamaps.cc'
2015-11-03 14:22:53 +00:00
end
2012-09-23 02:39:12 +00:00
end