snippets_controller.rb 2.95 KB
Newer Older
1
class Projects::SnippetsController < Projects::ApplicationController
Douwe Maan's avatar
Douwe Maan committed
2
  include RendersNotes
3
  include ToggleAwardEmoji
4
  include SpammableActions
5
  include SnippetsActions
Douwe Maan's avatar
Douwe Maan committed
6
  include RendersBlob
7

8
  before_action :check_snippets_available!
9
  before_action :snippet, only: [:show, :edit, :destroy, :update, :raw, :toggle_award_emoji, :mark_as_spam]
Andrew8xx8's avatar
Andrew8xx8 committed
10 11

  # Allow read any snippet
12
  before_action :authorize_read_project_snippet!, except: [:new, :create, :index]
Andrew8xx8's avatar
Andrew8xx8 committed
13 14

  # Allow write(create) snippet
15
  before_action :authorize_create_project_snippet!, only: [:new, :create]
Andrew8xx8's avatar
Andrew8xx8 committed
16 17

  # Allow modify snippet
18
  before_action :authorize_update_project_snippet!, only: [:edit, :update]
Andrew8xx8's avatar
Andrew8xx8 committed
19 20

  # Allow destroy snippet
21
  before_action :authorize_admin_project_snippet!, only: [:destroy]
Andrew8xx8's avatar
Andrew8xx8 committed
22 23 24 25

  respond_to :html

  def index
26
    @snippets = SnippetsFinder.new(
27 28 29
      current_user,
      project: @project,
      scope: params[:scope]
30
    ).execute
31 32
    @snippets = @snippets.page(params[:page])
    if @snippets.out_of_range? && @snippets.total_pages != 0
33
      redirect_to project_snippets_path(@project, page: @snippets.total_pages)
34
    end
Andrew8xx8's avatar
Andrew8xx8 committed
35 36 37
  end

  def new
38
    @snippet = @noteable = @project.snippets.build
Andrew8xx8's avatar
Andrew8xx8 committed
39 40 41
  end

  def create
42 43
    create_params = snippet_params.merge(spammable_params)

44
    @snippet = CreateSnippetService.new(@project, current_user, create_params).execute
45

46
    recaptcha_check_with_fallback { render :new }
Andrew8xx8's avatar
Andrew8xx8 committed
47 48 49
  end

  def update
50 51 52 53 54
    update_params = snippet_params.merge(spammable_params)

    UpdateSnippetService.new(project, current_user, @snippet, update_params).execute

    recaptcha_check_with_fallback { render :edit }
Andrew8xx8's avatar
Andrew8xx8 committed
55 56 57
  end

  def show
Douwe Maan's avatar
Douwe Maan committed
58
    blob = @snippet.blob
59
    conditionally_expand_blob(blob)
Douwe Maan's avatar
Douwe Maan committed
60 61 62 63 64 65 66

    respond_to do |format|
      format.html do
        @note = @project.notes.new(noteable: @snippet)
        @noteable = @snippet

        @discussions = @snippet.discussions
67
        @notes = prepare_notes_for_rendering(@discussions.flat_map(&:notes), @noteable)
Douwe Maan's avatar
Douwe Maan committed
68 69 70 71 72 73 74
        render 'show'
      end

      format.json do
        render_blob_json(blob)
      end
    end
Andrew8xx8's avatar
Andrew8xx8 committed
75 76 77
  end

  def destroy
78
    return access_denied! unless can?(current_user, :admin_project_snippet, @snippet)
Andrew8xx8's avatar
Andrew8xx8 committed
79 80 81

    @snippet.destroy

82
    redirect_to project_snippets_path(@project), status: 302
Andrew8xx8's avatar
Andrew8xx8 committed
83 84 85 86 87 88 89
  end

  protected

  def snippet
    @snippet ||= @project.snippets.find(params[:id])
  end
90
  alias_method :awardable, :snippet
91
  alias_method :spammable, :snippet
Andrew8xx8's avatar
Andrew8xx8 committed
92

93 94 95 96
  def spammable_path
    project_snippet_path(@project, @snippet)
  end

97 98 99 100
  def authorize_read_project_snippet!
    return render_404 unless can?(current_user, :read_project_snippet, @snippet)
  end

101
  def authorize_update_project_snippet!
102
    return render_404 unless can?(current_user, :update_project_snippet, @snippet)
Andrew8xx8's avatar
Andrew8xx8 committed
103 104
  end

105
  def authorize_admin_project_snippet!
106
    return render_404 unless can?(current_user, :admin_project_snippet, @snippet)
Andrew8xx8's avatar
Andrew8xx8 committed
107 108
  end

109
  def snippet_params
110
    params.require(:project_snippet).permit(:title, :content, :file_name, :private, :visibility_level, :description)
111
  end
Andrew8xx8's avatar
Andrew8xx8 committed
112
end