Class: CreditCardVaultsController

Inherits:
CrmController show all
Defined in:
app/controllers/credit_card_vaults_controller.rb

Overview

== Schema Information

Table name: credit_card_vaults

id :integer not null, primary key
vault_id :integer
description :string(255) not null
customer_id :integer not null
number :string(255) not null
expiration_date :date not null
creator_id :integer
updater_id :integer
created_at :datetime
updated_at :datetime
card_type :string(255)
zip_code :string(10)

Constant Summary

Constants included from Controllers::ReferenceFindable

Controllers::ReferenceFindable::ID_EMBEDDED_PATTERNS

Constants included from Controllers::AnalyticsEvents

Controllers::AnalyticsEvents::MAX_QUEUED_EVENTS, Controllers::AnalyticsEvents::SESSION_KEY

Constants included from Controllers::ErrorRendering

Controllers::ErrorRendering::NON_CONTENT_PATH_PREFIXES

Instance Method Summary collapse

Methods inherited from CrmController

#access_denied, #context_id, #context_object, #crm_home_path, #current_ability, #default_url_options, #download_temp, #get_tempfile_path_for_download, #init_status_job_collector, #initialize_crm_lazy_chunks, #persist_enqueued_status_jobs, #record_not_found, #redirect_to_job_or_fallback, #render_edit_action, #set_context, #set_download_path, #stash_file_for_temp_download, #sync_admin_presence_cookie, #touch_employee_last_seen

Methods inherited from ApplicationController

#account_impersonated?, #add_to_flash, #after_sign_in_path_for, #bypass_forgery_protection?, #chat_enabled?, #cloudflare_cleared?, #default_catalog, #default_url_options, #enable_turbo_frames, #find_publication, #fix_invalid_accept_header, #init_js_utils, #is_globals_call?, #layout_by_resource, #locale_store, #redirect_to, #require_employee_for_crm, #set_base_host, #set_real_ip, #set_report_errors_for, #should_render_layout?, #skip_layout_for_turbo_frame?, #stamp_impersonation_context, #tab_frame_breakout_request?, #warmlyyours_canada_ip?, #warmlyyours_ip?, #y

Methods included from Controllers::ReturnPathHandling

#check_for_return_path, #redirect_to_return_path_or_default

Methods included from Controllers::AnalyticsEvents

#consume_queued_analytics_events, #registration_lead_type, #track_event

Methods included from Controllers::DeviceDetection

#device_detector, #is_ie?

Methods included from Controllers::SubdomainDetection

#is_crm_request?, #is_www_request?, #json_request?

Methods included from Controllers::TurboSafeRedirect

#redirect_to

Methods included from Controllers::TrackingDetection

#bot_request?, #gdpr_country?, #gdpr_country_data, #prevent_bots, #set_tracking_cookie, #track_visitor?

Methods included from Controllers::AcceleratedFileSending

#send_file_accelerated, #send_upload_accelerated

Methods included from Controllers::ErrorRendering

#excp_string, #mail_to_for_error_reporting, #render_400, #render_404, #render_406, #render_410, #render_500, #render_invalid_authenticity_token, #render_ip_spoof_error, #render_unpermitted_parameters, #safe_referer_or_fallback

Methods included from Controllers::TurnstileVerification

#load_turnstile_script_tag, #turnstile_lazy_widget, #turnstile_script_tag, #turnstile_widget, #validate_turnstile!

Methods included from Controllers::CloudflareCaching

edge_cached, #edge_cached_action?, #reset_cloudflare_cache, #set_cloudflare_cache, #skip_edge_cache!, #skip_session

Methods included from Controllers::Webpackable

#preload_webpack_fonts, #webpack_css_include, #webpack_css_url, #webpack_js_include, #wpd_is_running?

Methods included from Controllers::Localizable

#cloudflare_country_locale, #determine_request_locale, #geocoder_locale, #guest_user_locale_check, #locale_optional_www_auth_path?, #param_locale, #set_locale, #set_request_locale, #skip_localization?, #warmlyyours_ip_locale

Methods included from Controllers::Authenticable

#access_denied, #authenticate_account, #authenticate_account!, #authenticate_account_from_login_token!, #check_is_a_manager, #check_is_a_sales_manager, #check_is_an_admin, #check_is_an_employee, #check_party, #clear_mismatched_guest_user, #create_guest_user, #credentials?, #current_or_guest_user, #current_or_guest_user_id_read_only, #current_user, #devise_mapping, #fully_logged_in?, #generate_bot_id, #guest_user, #identifiable?, #init_current_user, #initialize_guest, #load_context_user, #logging_in, #resource, #resource_name, #restrict_access_for_non_employees, #scrubbed_request_path, #user_object, #warn_on_session_guest_id_leak

Methods included from UrlsHelper

#catalog_breadcrumb_links, #catalog_link, #catalog_link_for_product_line, #catalog_link_for_sku, #cms_link, #delocalized_path, #path_to_sales_product_sku, #path_to_sales_product_sku_for_product_line, #path_to_sales_product_sku_for_product_line_slug, #product_line_from_catalog_link, #protocol_neutral_url, #sanitize_external_url, #valid_external_url?

Instance Method Details

#createvoid

This method returns an undefined value.

POST /customers/:customer_id/credit_card_vaults — stores a new card.



56
57
58
59
60
61
62
63
64
65
66
67
68
69
# File 'app/controllers/credit_card_vaults_controller.rb', line 56

def create
  @credit_card_vault = @customer.credit_card_vaults.new(params[:credit_card_vault])
  @credit_card_vault.card_token = params[:payment][:card_token]
  @credit_card_vault.hidden = false
  @credit_card_vault.consent_given_at = Time.current
  @credit_card_vault.consent_channel = "crm_manual:#{current_user.name.presence || current_user.}"

  if @credit_card_vault.store_card
    redirect_to_return_path_or_default customer_credit_card_vaults_path(@customer)
  else
    @payment = @credit_card_vault.payments.first || Payment.new
    render :new, status: :unprocessable_content
  end
end

#destroyvoid

This method returns an undefined value.

DELETE /customers/:customer_id/credit_card_vaults/:id — removes a
stored card.



75
76
77
78
79
80
# File 'app/controllers/credit_card_vaults_controller.rb', line 75

def destroy
  customer = @credit_card_vault.customer
  if @credit_card_vault.destroy
    redirect_to customer_credit_card_vaults_path(@customer)
  end
end

This method returns an undefined value.

POST /customers/:customer_id/credit_card_vaults/:id/grant_consent —
grants storage consent for a card added without it, making it visible.



86
87
88
89
90
# File 'app/controllers/credit_card_vaults_controller.rb', line 86

def grant_consent
  channel = "crm_manual:#{current_user.name.presence || current_user.}"
  @credit_card_vault.grant_consent!(channel)
  redirect_to customer_credit_card_vaults_path(@customer), notice: "Consent granted for #{@credit_card_vault.card_type} ending in #{@credit_card_vault.number}. Card is now visible."
end

#indexvoid

This method returns an undefined value.

GET /customers/:customer_id/credit_card_vaults — a customer's stored
payment methods (cards, PayPal), synced with Stripe first.



26
27
28
29
30
31
32
33
# File 'app/controllers/credit_card_vaults_controller.rb', line 26

def index
  @customer = Customer.find(params[:customer_id])
  CreditCardVault.sync_stripe_status!(@customer)
  @credit_card_vaults = @customer.credit_card_vaults.visible.includes(:payments).order(created_at: :desc)
  @hidden_vaults = current_user.is_admin? ? @customer.credit_card_vaults.where(hidden: true).includes(:payments).order(created_at: :desc) : []
  @detached_vaults = current_user.is_admin? ? @customer.credit_card_vaults.detached.includes(:payments).order(stripe_detached_at: :desc) : []
  @paypal_payments = @customer.payments.paypal_payments.includes(:order).order(created_at: :desc) if @customer.paypal_vault_token_id.present?
end

#newvoid

This method returns an undefined value.

GET /customers/:customer_id/credit_card_vaults/new — blank
add-card form.



48
49
50
51
# File 'app/controllers/credit_card_vaults_controller.rb', line 48

def new
  @credit_card_vault = CreditCardVault.new
  @payment = Payment.new
end

#remove_paypal_vaultvoid

This method returns an undefined value.

DELETE /customers/:customer_id/credit_card_vaults/remove_paypal_vault —
removes the customer's stored PayPal wallet token, at PayPal and locally.



96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
# File 'app/controllers/credit_card_vaults_controller.rb', line 96

def remove_paypal_vault
  @customer = Customer.find(params[:customer_id])
  token_id = @customer.paypal_vault_token_id

  if token_id.blank?
    redirect_to customer_credit_card_vaults_path(@customer), alert: "No PayPal wallet to remove."
    return
  end

  response = Payment::Apis::Paypal.delete_vault_payment_token(token_id)

  if response['_http_success'] || response['_http_status'] == 404
    @customer.update!(paypal_vault_token_id: nil, paypal_vault_customer_id: nil)
    redirect_to customer_credit_card_vaults_path(@customer), notice: "PayPal wallet removed."
  else
    Rails.logger.error("[PayPal Vault] Delete failed for customer #{@customer.id}: status=#{response['_http_status']}")
    redirect_to customer_credit_card_vaults_path(@customer), alert: "Failed to remove PayPal wallet from PayPal. Please try again."
  end
end

#showvoid

This method returns an undefined value.

GET /customers/:customer_id/credit_card_vaults/:id — a single stored
card and its payment history.



39
40
41
42
# File 'app/controllers/credit_card_vaults_controller.rb', line 39

def show
  @credit_card_vault = @customer.credit_card_vaults.find(params[:id])
  @payments = @credit_card_vault.payments.includes(:order).order(created_at: :desc)
end