Class: Admin::Privacy::DeletionRequestsController
- Inherits:
-
CrmController
- Object
- ActionController::Base
- ApplicationController
- CrmController
- Admin::Privacy::DeletionRequestsController
- Defined in:
- app/controllers/admin/privacy/deletion_requests_controller.rb
Overview
Controller: admin review queue for privacy deletion requests.
Constant Summary collapse
- MANUAL_SOURCES =
Manual deletion request sources (excludes webhook/callback sources).
::Privacy::DeletionRequest::SOURCES - %w[facebook_callback].freeze
Constants included from Controllers::ReferenceFindable
Controllers::ReferenceFindable::ID_EMBEDDED_PATTERNS
Constants included from Controllers::AnalyticsEvents
Controllers::AnalyticsEvents::MAX_QUEUED_EVENTS, Controllers::AnalyticsEvents::SESSION_KEY
Constants included from Controllers::ErrorRendering
Controllers::ErrorRendering::NON_CONTENT_PATH_PREFIXES
Instance Method Summary collapse
-
#approve ⇒ void
Approves a deletion request and re-enqueues the scrub worker.
-
#create ⇒ void
Creates a manual deletion request and enqueues the scrub worker.
-
#decline ⇒ void
Declines a deletion request (terminal "no").
-
#index ⇒ void
Renders the deletion requests index with pending and review-held requests.
-
#new ⇒ void
Renders the manual deletion request intake form.
-
#retry_request ⇒ void
Retries a failed deletion request.
-
#show ⇒ void
Renders details and action buttons for a specific deletion request.
Methods inherited from CrmController
#access_denied, #context_id, #context_object, #crm_home_path, #current_ability, #default_url_options, #download_temp, #get_tempfile_path_for_download, #init_status_job_collector, #initialize_crm_lazy_chunks, #persist_enqueued_status_jobs, #record_not_found, #redirect_to_job_or_fallback, #render_edit_action, #set_context, #set_download_path, #stash_file_for_temp_download, #sync_admin_presence_cookie, #touch_employee_last_seen
Methods inherited from ApplicationController
#account_impersonated?, #add_to_flash, #after_sign_in_path_for, #bypass_forgery_protection?, #chat_enabled?, #cloudflare_cleared?, #default_catalog, #default_url_options, #enable_turbo_frames, #find_publication, #fix_invalid_accept_header, #init_js_utils, #is_globals_call?, #layout_by_resource, #locale_store, #redirect_to, #require_employee_for_crm, #set_base_host, #set_real_ip, #set_report_errors_for, #should_render_layout?, #skip_layout_for_turbo_frame?, #stamp_impersonation_context, #tab_frame_breakout_request?, #warmlyyours_canada_ip?, #warmlyyours_ip?, #y
Methods included from Controllers::ReturnPathHandling
#check_for_return_path, #redirect_to_return_path_or_default
Methods included from Controllers::AnalyticsEvents
#consume_queued_analytics_events, #registration_lead_type, #track_event
Methods included from Controllers::DeviceDetection
Methods included from Controllers::SubdomainDetection
#is_crm_request?, #is_www_request?, #json_request?
Methods included from Controllers::TurboSafeRedirect
Methods included from Controllers::TrackingDetection
#bot_request?, #gdpr_country?, #gdpr_country_data, #prevent_bots, #set_tracking_cookie, #track_visitor?
Methods included from Controllers::AcceleratedFileSending
#send_file_accelerated, #send_upload_accelerated
Methods included from Controllers::ErrorRendering
#excp_string, #mail_to_for_error_reporting, #render_400, #render_404, #render_406, #render_410, #render_500, #render_invalid_authenticity_token, #render_ip_spoof_error, #render_unpermitted_parameters, #safe_referer_or_fallback
Methods included from Controllers::TurnstileVerification
#load_turnstile_script_tag, #turnstile_lazy_widget, #turnstile_script_tag, #turnstile_widget, #validate_turnstile!
Methods included from Controllers::CloudflareCaching
edge_cached, #edge_cached_action?, #reset_cloudflare_cache, #set_cloudflare_cache, #skip_edge_cache!, #skip_session
Methods included from Controllers::Webpackable
#preload_webpack_fonts, #webpack_css_include, #webpack_css_url, #webpack_js_include, #wpd_is_running?
Methods included from Controllers::Localizable
#cloudflare_country_locale, #determine_request_locale, #geocoder_locale, #guest_user_locale_check, #locale_optional_www_auth_path?, #param_locale, #set_locale, #set_request_locale, #skip_localization?, #warmlyyours_ip_locale
Methods included from Controllers::Authenticable
#access_denied, #authenticate_account, #authenticate_account!, #authenticate_account_from_login_token!, #check_is_a_manager, #check_is_a_sales_manager, #check_is_an_admin, #check_is_an_employee, #check_party, #clear_mismatched_guest_user, #create_guest_user, #credentials?, #current_or_guest_user, #current_or_guest_user_id_read_only, #current_user, #devise_mapping, #fully_logged_in?, #generate_bot_id, #guest_user, #identifiable?, #init_current_user, #initialize_guest, #load_context_user, #logging_in, #resource, #resource_name, #restrict_access_for_non_employees, #scrubbed_request_path, #user_object, #warn_on_session_guest_id_leak
Methods included from UrlsHelper
#catalog_breadcrumb_links, #catalog_link, #catalog_link_for_product_line, #catalog_link_for_sku, #cms_link, #delocalized_path, #path_to_sales_product_sku, #path_to_sales_product_sku_for_product_line, #path_to_sales_product_sku_for_product_line_slug, #product_line_from_catalog_link, #protocol_neutral_url, #sanitize_external_url, #valid_external_url?
Instance Method Details
#approve ⇒ void
This method returns an undefined value.
Approves a deletion request and re-enqueues the scrub worker.
Clears any Tier-3 review hold and re-enqueues the deletion worker to proceed.
104 105 106 107 108 109 110 111 |
# File 'app/controllers/admin/privacy/deletion_requests_controller.rb', line 104 def approve return redirect_back_with_error(:approve) unless @request.can_start_processing? @request.update!(reviewed_by: current_account, reviewed_at: Time.current) ::Privacy::DataDeletionWorker.perform_async(@request.id) flash[:success] = "Approved request ##{@request.id}; scrub enqueued." redirect_to admin_privacy_deletion_request_path(@request) end |
#create ⇒ void
This method returns an undefined value.
Creates a manual deletion request and enqueues the scrub worker.
Resolves account_id / party_id from email or account_id input, then enqueues
the deletion worker. The same Tier-3 review gate and scrub pipeline apply;
admin doesn't need further action unless a trigger fires (held_for_review email).
56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 |
# File 'app/controllers/admin/privacy/deletion_requests_controller.rb', line 56 def create @sources = MANUAL_SOURCES attrs = manual_request_params @request = ::Privacy::DeletionRequest.new( source: attrs[:source].presence_in(MANUAL_SOURCES) || 'manual_email' ) # Echo the virtual attrs so a re-render preserves what the admin typed. @request.account_lookup = attrs[:account_lookup] @request.contact_email = attrs[:contact_email] @request.intake_notes = attrs[:intake_notes] @request.require_account = attrs[:require_account] if attrs[:account_lookup].blank? @request.errors.add(:account_lookup, "can't be blank — enter an account email, login, or numeric account ID") render :new, status: :unprocessable_entity return end account = resolve_account(attrs[:account_lookup]) if account.nil? && attrs[:require_account] == '1' @request.errors.add(:account_lookup, "did not match any account. Uncheck 'Require matching account' to record a no_account_found row anyway.") render :new, status: :unprocessable_entity return end @request.account = account @request.party = account&.party @request.data = { contact_email: attrs[:contact_email].presence, account_lookup: attrs[:account_lookup], intake_notes: attrs[:intake_notes].presence, created_by: current_account.email }.compact @request.save! ::Privacy::DataDeletionWorker.perform_async(@request.id) flash[:success] = "Created request ##{@request.id}; worker enqueued." redirect_to admin_privacy_deletion_request_path(@request) end |
#decline ⇒ void
This method returns an undefined value.
Declines a deletion request (terminal "no").
Marks the request as declined and prevents further processing.
118 119 120 121 122 123 124 125 |
# File 'app/controllers/admin/privacy/deletion_requests_controller.rb', line 118 def decline return redirect_back_with_error(:decline) unless @request.can_decline? @request.update!(reviewed_by: current_account, reviewed_at: Time.current) @request.decline flash[:success] = "Declined request ##{@request.id}." redirect_to admin_privacy_deletion_request_path(@request) end |
#index ⇒ void
This method returns an undefined value.
Renders the deletion requests index with pending and review-held requests.
26 27 28 29 |
# File 'app/controllers/admin/privacy/deletion_requests_controller.rb', line 26 def index @needs_review_requests = ::Privacy::DeletionRequest.needs_review.recent.limit(100) @recent_requests = ::Privacy::DeletionRequest.recent.limit(100) end |
#new ⇒ void
This method returns an undefined value.
Renders the manual deletion request intake form.
Used for requests that arrived by email, postal mail, or in-person rather
than through Meta's webhook callback.
44 45 46 47 |
# File 'app/controllers/admin/privacy/deletion_requests_controller.rb', line 44 def new @request = ::Privacy::DeletionRequest.new(source: 'manual_email') @sources = MANUAL_SOURCES end |
#retry_request ⇒ void
This method returns an undefined value.
Retries a failed deletion request.
Transitions request from failed state back to pending and re-enqueues the worker.
132 133 134 135 136 137 138 139 |
# File 'app/controllers/admin/privacy/deletion_requests_controller.rb', line 132 def retry_request return redirect_back_with_error(:retry) unless @request.can_retry_processing? @request.retry_processing ::Privacy::DataDeletionWorker.perform_async(@request.id) flash[:success] = "Re-enqueued request ##{@request.id}." redirect_to admin_privacy_deletion_request_path(@request) end |
#show ⇒ void
This method returns an undefined value.
Renders details and action buttons for a specific deletion request.
34 35 36 |
# File 'app/controllers/admin/privacy/deletion_requests_controller.rb', line 34 def show # Renders details + actions; no extra setup needed. end |