Class: Admin::Privacy::DeletionRequestsController

Inherits:
CrmController show all
Defined in:
app/controllers/admin/privacy/deletion_requests_controller.rb

Overview

Controller: admin review queue for privacy deletion requests.

Constant Summary collapse

MANUAL_SOURCES =

Manual deletion request sources (excludes webhook/callback sources).

::Privacy::DeletionRequest::SOURCES - %w[facebook_callback].freeze

Constants included from Controllers::ReferenceFindable

Controllers::ReferenceFindable::ID_EMBEDDED_PATTERNS

Constants included from Controllers::AnalyticsEvents

Controllers::AnalyticsEvents::MAX_QUEUED_EVENTS, Controllers::AnalyticsEvents::SESSION_KEY

Constants included from Controllers::ErrorRendering

Controllers::ErrorRendering::NON_CONTENT_PATH_PREFIXES

Instance Method Summary collapse

Methods inherited from CrmController

#access_denied, #context_id, #context_object, #crm_home_path, #current_ability, #default_url_options, #download_temp, #get_tempfile_path_for_download, #init_status_job_collector, #initialize_crm_lazy_chunks, #persist_enqueued_status_jobs, #record_not_found, #redirect_to_job_or_fallback, #render_edit_action, #set_context, #set_download_path, #stash_file_for_temp_download, #sync_admin_presence_cookie, #touch_employee_last_seen

Methods inherited from ApplicationController

#account_impersonated?, #add_to_flash, #after_sign_in_path_for, #bypass_forgery_protection?, #chat_enabled?, #cloudflare_cleared?, #default_catalog, #default_url_options, #enable_turbo_frames, #find_publication, #fix_invalid_accept_header, #init_js_utils, #is_globals_call?, #layout_by_resource, #locale_store, #redirect_to, #require_employee_for_crm, #set_base_host, #set_real_ip, #set_report_errors_for, #should_render_layout?, #skip_layout_for_turbo_frame?, #stamp_impersonation_context, #tab_frame_breakout_request?, #warmlyyours_canada_ip?, #warmlyyours_ip?, #y

Methods included from Controllers::ReturnPathHandling

#check_for_return_path, #redirect_to_return_path_or_default

Methods included from Controllers::AnalyticsEvents

#consume_queued_analytics_events, #registration_lead_type, #track_event

Methods included from Controllers::DeviceDetection

#device_detector, #is_ie?

Methods included from Controllers::SubdomainDetection

#is_crm_request?, #is_www_request?, #json_request?

Methods included from Controllers::TurboSafeRedirect

#redirect_to

Methods included from Controllers::TrackingDetection

#bot_request?, #gdpr_country?, #gdpr_country_data, #prevent_bots, #set_tracking_cookie, #track_visitor?

Methods included from Controllers::AcceleratedFileSending

#send_file_accelerated, #send_upload_accelerated

Methods included from Controllers::ErrorRendering

#excp_string, #mail_to_for_error_reporting, #render_400, #render_404, #render_406, #render_410, #render_500, #render_invalid_authenticity_token, #render_ip_spoof_error, #render_unpermitted_parameters, #safe_referer_or_fallback

Methods included from Controllers::TurnstileVerification

#load_turnstile_script_tag, #turnstile_lazy_widget, #turnstile_script_tag, #turnstile_widget, #validate_turnstile!

Methods included from Controllers::CloudflareCaching

edge_cached, #edge_cached_action?, #reset_cloudflare_cache, #set_cloudflare_cache, #skip_edge_cache!, #skip_session

Methods included from Controllers::Webpackable

#preload_webpack_fonts, #webpack_css_include, #webpack_css_url, #webpack_js_include, #wpd_is_running?

Methods included from Controllers::Localizable

#cloudflare_country_locale, #determine_request_locale, #geocoder_locale, #guest_user_locale_check, #locale_optional_www_auth_path?, #param_locale, #set_locale, #set_request_locale, #skip_localization?, #warmlyyours_ip_locale

Methods included from Controllers::Authenticable

#access_denied, #authenticate_account, #authenticate_account!, #authenticate_account_from_login_token!, #check_is_a_manager, #check_is_a_sales_manager, #check_is_an_admin, #check_is_an_employee, #check_party, #clear_mismatched_guest_user, #create_guest_user, #credentials?, #current_or_guest_user, #current_or_guest_user_id_read_only, #current_user, #devise_mapping, #fully_logged_in?, #generate_bot_id, #guest_user, #identifiable?, #init_current_user, #initialize_guest, #load_context_user, #logging_in, #resource, #resource_name, #restrict_access_for_non_employees, #scrubbed_request_path, #user_object, #warn_on_session_guest_id_leak

Methods included from UrlsHelper

#catalog_breadcrumb_links, #catalog_link, #catalog_link_for_product_line, #catalog_link_for_sku, #cms_link, #delocalized_path, #path_to_sales_product_sku, #path_to_sales_product_sku_for_product_line, #path_to_sales_product_sku_for_product_line_slug, #product_line_from_catalog_link, #protocol_neutral_url, #sanitize_external_url, #valid_external_url?

Instance Method Details

#approvevoid

This method returns an undefined value.

Approves a deletion request and re-enqueues the scrub worker.

Clears any Tier-3 review hold and re-enqueues the deletion worker to proceed.



104
105
106
107
108
109
110
111
# File 'app/controllers/admin/privacy/deletion_requests_controller.rb', line 104

def approve
  return redirect_back_with_error(:approve) unless @request.can_start_processing?

  @request.update!(reviewed_by: , reviewed_at: Time.current)
  ::Privacy::DataDeletionWorker.perform_async(@request.id)
  flash[:success] = "Approved request ##{@request.id}; scrub enqueued."
  redirect_to admin_privacy_deletion_request_path(@request)
end

#createvoid

This method returns an undefined value.

Creates a manual deletion request and enqueues the scrub worker.

Resolves account_id / party_id from email or account_id input, then enqueues
the deletion worker. The same Tier-3 review gate and scrub pipeline apply;
admin doesn't need further action unless a trigger fires (held_for_review email).



56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
# File 'app/controllers/admin/privacy/deletion_requests_controller.rb', line 56

def create
  @sources = MANUAL_SOURCES
  attrs    = manual_request_params

  @request = ::Privacy::DeletionRequest.new(
    source: attrs[:source].presence_in(MANUAL_SOURCES) || 'manual_email'
  )
  # Echo the virtual attrs so a re-render preserves what the admin typed.
  @request.  = attrs[:account_lookup]
  @request.contact_email   = attrs[:contact_email]
  @request.intake_notes    = attrs[:intake_notes]
  @request. = attrs[:require_account]

  if attrs[:account_lookup].blank?
    @request.errors.add(:account_lookup,
                        "can't be blank — enter an account email, login, or numeric account ID")
    render :new, status: :unprocessable_entity
    return
  end

   = (attrs[:account_lookup])
  if .nil? && attrs[:require_account] == '1'
    @request.errors.add(:account_lookup,
                        "did not match any account. Uncheck 'Require matching account' to record a no_account_found row anyway.")
    render :new, status: :unprocessable_entity
    return
  end

  @request. = 
  @request.party   = &.party
  @request.data = {
    contact_email:  attrs[:contact_email].presence,
    account_lookup: attrs[:account_lookup],
    intake_notes:   attrs[:intake_notes].presence,
    created_by:     .email
  }.compact
  @request.save!

  ::Privacy::DataDeletionWorker.perform_async(@request.id)
  flash[:success] = "Created request ##{@request.id}; worker enqueued."
  redirect_to admin_privacy_deletion_request_path(@request)
end

#declinevoid

This method returns an undefined value.

Declines a deletion request (terminal "no").

Marks the request as declined and prevents further processing.



118
119
120
121
122
123
124
125
# File 'app/controllers/admin/privacy/deletion_requests_controller.rb', line 118

def decline
  return redirect_back_with_error(:decline) unless @request.can_decline?

  @request.update!(reviewed_by: , reviewed_at: Time.current)
  @request.decline
  flash[:success] = "Declined request ##{@request.id}."
  redirect_to admin_privacy_deletion_request_path(@request)
end

#indexvoid

This method returns an undefined value.

Renders the deletion requests index with pending and review-held requests.



26
27
28
29
# File 'app/controllers/admin/privacy/deletion_requests_controller.rb', line 26

def index
  @needs_review_requests = ::Privacy::DeletionRequest.needs_review.recent.limit(100)
  @recent_requests       = ::Privacy::DeletionRequest.recent.limit(100)
end

#newvoid

This method returns an undefined value.

Renders the manual deletion request intake form.

Used for requests that arrived by email, postal mail, or in-person rather
than through Meta's webhook callback.



44
45
46
47
# File 'app/controllers/admin/privacy/deletion_requests_controller.rb', line 44

def new
  @request = ::Privacy::DeletionRequest.new(source: 'manual_email')
  @sources = MANUAL_SOURCES
end

#retry_requestvoid

This method returns an undefined value.

Retries a failed deletion request.

Transitions request from failed state back to pending and re-enqueues the worker.



132
133
134
135
136
137
138
139
# File 'app/controllers/admin/privacy/deletion_requests_controller.rb', line 132

def retry_request
  return redirect_back_with_error(:retry) unless @request.can_retry_processing?

  @request.retry_processing
  ::Privacy::DataDeletionWorker.perform_async(@request.id)
  flash[:success] = "Re-enqueued request ##{@request.id}."
  redirect_to admin_privacy_deletion_request_path(@request)
end

#showvoid

This method returns an undefined value.

Renders details and action buttons for a specific deletion request.



34
35
36
# File 'app/controllers/admin/privacy/deletion_requests_controller.rb', line 34

def show
  # Renders details + actions; no extra setup needed.
end