Class: Crm::AccountsController

Inherits:
CrmController show all
Defined in:
app/controllers/crm/accounts_controller.rb

Overview

Controller: accounts.

Constant Summary

Constants included from Controllers::ReferenceFindable

Controllers::ReferenceFindable::ID_EMBEDDED_PATTERNS

Constants included from Controllers::AnalyticsEvents

Controllers::AnalyticsEvents::MAX_QUEUED_EVENTS, Controllers::AnalyticsEvents::SESSION_KEY

Constants included from Controllers::ErrorRendering

Controllers::ErrorRendering::NON_CONTENT_PATH_PREFIXES

Instance Method Summary collapse

Methods inherited from CrmController

#access_denied, #context_id, #context_object, #crm_home_path, #current_ability, #default_url_options, #download_temp, #get_tempfile_path_for_download, #init_status_job_collector, #initialize_crm_lazy_chunks, #persist_enqueued_status_jobs, #record_not_found, #redirect_to_job_or_fallback, #render_edit_action, #set_context, #set_download_path, #stash_file_for_temp_download, #sync_admin_presence_cookie, #touch_employee_last_seen

Methods inherited from ApplicationController

#account_impersonated?, #add_to_flash, #after_sign_in_path_for, #bypass_forgery_protection?, #chat_enabled?, #cloudflare_cleared?, #default_catalog, #default_url_options, #enable_turbo_frames, #find_publication, #fix_invalid_accept_header, #init_js_utils, #is_globals_call?, #layout_by_resource, #locale_store, #redirect_to, #require_employee_for_crm, #set_base_host, #set_real_ip, #set_report_errors_for, #should_render_layout?, #skip_layout_for_turbo_frame?, #stamp_impersonation_context, #tab_frame_breakout_request?, #warmlyyours_canada_ip?, #warmlyyours_ip?, #y

Methods included from Controllers::ReturnPathHandling

#check_for_return_path, #redirect_to_return_path_or_default

Methods included from Controllers::AnalyticsEvents

#consume_queued_analytics_events, #registration_lead_type, #track_event

Methods included from Controllers::DeviceDetection

#device_detector, #is_ie?

Methods included from Controllers::SubdomainDetection

#is_crm_request?, #is_www_request?, #json_request?

Methods included from Controllers::TurboSafeRedirect

#redirect_to

Methods included from Controllers::TrackingDetection

#bot_request?, #gdpr_country?, #gdpr_country_data, #prevent_bots, #set_tracking_cookie, #track_visitor?

Methods included from Controllers::AcceleratedFileSending

#send_file_accelerated, #send_upload_accelerated

Methods included from Controllers::ErrorRendering

#excp_string, #mail_to_for_error_reporting, #render_400, #render_404, #render_406, #render_410, #render_500, #render_invalid_authenticity_token, #render_ip_spoof_error, #render_unpermitted_parameters, #safe_referer_or_fallback

Methods included from Controllers::TurnstileVerification

#load_turnstile_script_tag, #turnstile_lazy_widget, #turnstile_script_tag, #turnstile_widget, #validate_turnstile!

Methods included from Controllers::CloudflareCaching

edge_cached, #edge_cached_action?, #reset_cloudflare_cache, #set_cloudflare_cache, #skip_edge_cache!, #skip_session

Methods included from Controllers::Webpackable

#preload_webpack_fonts, #webpack_css_include, #webpack_css_url, #webpack_js_include, #wpd_is_running?

Methods included from Controllers::Localizable

#cloudflare_country_locale, #determine_request_locale, #geocoder_locale, #guest_user_locale_check, #locale_optional_www_auth_path?, #param_locale, #set_locale, #set_request_locale, #skip_localization?, #warmlyyours_ip_locale

Methods included from Controllers::Authenticable

#access_denied, #authenticate_account, #authenticate_account!, #authenticate_account_from_login_token!, #check_is_a_manager, #check_is_a_sales_manager, #check_is_an_admin, #check_is_an_employee, #check_party, #clear_mismatched_guest_user, #create_guest_user, #credentials?, #current_or_guest_user, #current_or_guest_user_id_read_only, #current_user, #devise_mapping, #fully_logged_in?, #generate_bot_id, #guest_user, #identifiable?, #init_current_user, #initialize_guest, #load_context_user, #logging_in, #resource, #resource_name, #restrict_access_for_non_employees, #scrubbed_request_path, #user_object, #warn_on_session_guest_id_leak

Methods included from UrlsHelper

#catalog_breadcrumb_links, #catalog_link, #catalog_link_for_product_line, #catalog_link_for_sku, #cms_link, #delocalized_path, #path_to_sales_product_sku, #path_to_sales_product_sku_for_product_line, #path_to_sales_product_sku_for_product_line_slug, #product_line_from_catalog_link, #protocol_neutral_url, #sanitize_external_url, #valid_external_url?

Instance Method Details

#becomevoid

This method returns an undefined value.

GET /:party_type/:party_id/account/become — starts a masquerade
(impersonation) session as this account.



64
65
66
67
68
69
70
71
72
73
74
75
76
# File 'app/controllers/crm/accounts_controller.rb', line 64

def become
  return reject_become_without_permission unless .can_impersonate?(@account.party)

  # The handoff is purely an in-flight signed token + Redis-backed
  # replay guard now. The audit row lands in `login_activities` on the
  # WWW side via AuthTrail when the customer is actually signed in
  # (see Www::MasqueradesController#new + config/initializers/authtrail.rb).
  redirect_to "#{WEB_URL}/masquerade/new?token=#{CGI.escape(masquerade_handoff_token)}", allow_other_host: true
rescue Masquerade::HandoffToken::Error => e
  Rails.logger.error("Masquerade handoff failed: #{e.class}: #{e.message}")
  flash[:error] = 'Could not start masquerade session. Please try again.'
  redirect_to polymorphic_path([@party, :account])
end

#createvoid

This method returns an undefined value.

POST /:party_type/:party_id/account — creates an online account for the
party via Account::Inviter.



39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
# File 'app/controllers/crm/accounts_controller.rb', line 39

def create
  # Use Account.new (not @party.build_account) so we don't replace the
  # has_one :account association in memory. has_one autosave on save would
  # otherwise destroy any pre-existing account on this party - the same
  # silent-destroy primitive that wiped a real customer's account in
  # ticket BC-498301955. Account::Inviter#process inserts a brand-new row
  # via Account.invite!, leaving any existing accounts untouched.
  @account = Account.new(params[:account])

  result = Account::Inviter.new.process(party: @party, email: @account.email, login: @account.)
  @account = result. || @account
  @account.roles << Role.find_by(name: "online_customer_sales_representative") if @party.is_a?(Contact)
  if @account&.persisted?
    redirect_to polymorphic_path([@party, :account])
  else
    flash.now[:error] = result.messages.join('. ')
    set_available_email_accounts
    render :new, status: :unprocessable_content
  end
end

#destroyvoid

This method returns an undefined value.

DELETE /:party_type/:party_id/account — destroys the party's online account.



81
82
83
84
85
86
87
88
# File 'app/controllers/crm/accounts_controller.rb', line 81

def destroy
  if @account.destroy
    flash[:info] = "Online account deleted"
  else
    flash[:error] = "Could not delete online account. #{@account.errors_to_s}"
  end
  redirect_to polymorphic_path([@party, :account])
end

#edit_emailvoid

This method returns an undefined value.

GET /:party_type/:party_id/account/edit_email — form for changing the
account's login email.



124
125
126
# File 'app/controllers/crm/accounts_controller.rb', line 124

def edit_email
  set_available_email_accounts
end

#newvoid

This method returns an undefined value.

GET /:party_type/:party_id/account/new — blank online-account form.



19
20
21
22
23
# File 'app/controllers/crm/accounts_controller.rb', line 19

def new
  set_available_email_accounts

  @account = Account.new(email: @party.email)
end

#resend_invitationvoid

This method returns an undefined value.

POST /:party_type/:party_id/account/resend_invitation — resends the
Devise invitation email, unless it was already accepted.



108
109
110
111
112
113
114
115
116
117
118
# File 'app/controllers/crm/accounts_controller.rb', line 108

def resend_invitation
  begin
    raise "Invitation was already accepted" if @account.invitation_accepted_at.present?

    @account.invite!
    flash[:info] = "Invitation was resent to #{@account.email}"
  rescue StandardError => e
    flash[:error] = "Invitation could not be sent. #{e}"
  end
  redirect_to polymorphic_path([@party, :account])
end

#reset_passwordvoid

This method returns an undefined value.

POST /:party_type/:party_id/account/reset_password — sends the account
Devise's reset-password instructions email.



94
95
96
97
98
99
100
101
102
# File 'app/controllers/crm/accounts_controller.rb', line 94

def reset_password
  begin
    @account.send_reset_password_instructions
    flash[:info] = "Password reset instructions have been sent to the customer at #{@account.email}"
  rescue StandardError => e
    flash[:error] = "Password reset instructions could not be sent, message : #{e}, please contact an administrator."
  end
  redirect_to polymorphic_path([@party, :account])
end

#set_emailvoid

This method returns an undefined value.

PATCH /:party_type/:party_id/account/set_email — changes the account's
login email.



132
133
134
135
136
137
138
139
# File 'app/controllers/crm/accounts_controller.rb', line 132

def set_email
  if @account.update(params[:account])
    redirect_to polymorphic_path([@party, :account])
  else
    set_available_email_accounts
    render action: :edit_email, status: :unprocessable_content
  end
end

#set_rolevoid

This method returns an undefined value.

PATCH /:party_type/:party_id/account/set_role — assigns the account's role.



144
145
146
147
148
149
150
151
# File 'app/controllers/crm/accounts_controller.rb', line 144

def set_role
  if 
    flash[:info] = "Role/permissions were set for login: #{@account.email}"
  else
    flash[:error] = "Role/permissions could not be set for login: #{@account.email}"
  end
  redirect_to polymorphic_path([@party, :account])
end

#showvoid

This method returns an undefined value.

GET /:party_type/:party_id/account — a party's online account and its
recent login activity, or redirects to the new-account form if none exists.



10
11
12
13
14
# File 'app/controllers/crm/accounts_controller.rb', line 10

def show
  return redirect_to polymorphic_path([@party, :account], action: :new) unless @account

  
end

#toggle_disabledvoid

This method returns an undefined value.

PATCH /:party_type/:party_id/account/toggle_disabled — flips the
account's disabled flag.



29
30
31
32
33
# File 'app/controllers/crm/accounts_controller.rb', line 29

def toggle_disabled
  @account.toggle(:disabled)
  @account.save
  redirect_to polymorphic_path([@party, :account])
end