Class: MyOrdersController

Inherits:
BasePortalController show all
Defined in:
app/controllers/my_orders_controller.rb

Overview

Customer-portal "My Orders" area: lists, views, edits, and downloads
invoices for the customer's own Order records. request_smartinstall
and update_post_checkout are reachable unauthenticated — the
post-checkout confirmation flow before an account may fully exist yet.

Constant Summary

Constants included from Controllers::MasqueradeGuarded

Controllers::MasqueradeGuarded::DEFAULT_BLOCK_MESSAGE

Constants included from Controllers::AnalyticsEvents

Controllers::AnalyticsEvents::MAX_QUEUED_EVENTS, Controllers::AnalyticsEvents::SESSION_KEY

Constants included from Controllers::ErrorRendering

Controllers::ErrorRendering::NON_CONTENT_PATH_PREFIXES

Instance Method Summary collapse

Methods inherited from BasePortalController

#current_ability, #portal_party, #set_catalog, #set_webpack

Methods included from Controllers::MasqueradeGuarded

block_while_masquerading, #masquerade_blocks?

Methods inherited from ApplicationController

#account_impersonated?, #add_to_flash, #after_sign_in_path_for, #bypass_forgery_protection?, #chat_enabled?, #cloudflare_cleared?, #default_catalog, #default_url_options, #enable_turbo_frames, #find_publication, #fix_invalid_accept_header, #init_js_utils, #is_globals_call?, #layout_by_resource, #locale_store, #redirect_to, #require_employee_for_crm, #set_base_host, #set_real_ip, #set_report_errors_for, #should_render_layout?, #skip_layout_for_turbo_frame?, #stamp_impersonation_context, #tab_frame_breakout_request?, #warmlyyours_canada_ip?, #warmlyyours_ip?, #y

Methods included from Controllers::ReturnPathHandling

#check_for_return_path, #redirect_to_return_path_or_default

Methods included from Controllers::AnalyticsEvents

#consume_queued_analytics_events, #registration_lead_type, #track_event

Methods included from Controllers::DeviceDetection

#device_detector, #is_ie?

Methods included from Controllers::SubdomainDetection

#is_crm_request?, #is_www_request?, #json_request?

Methods included from Controllers::TurboSafeRedirect

#redirect_to

Methods included from Controllers::TrackingDetection

#bot_request?, #gdpr_country?, #gdpr_country_data, #prevent_bots, #set_tracking_cookie, #track_visitor?

Methods included from Controllers::AcceleratedFileSending

#send_file_accelerated, #send_upload_accelerated

Methods included from Controllers::ErrorRendering

#excp_string, #mail_to_for_error_reporting, #render_400, #render_404, #render_406, #render_410, #render_500, #render_invalid_authenticity_token, #render_ip_spoof_error, #render_unpermitted_parameters, #safe_referer_or_fallback

Methods included from Controllers::TurnstileVerification

#load_turnstile_script_tag, #turnstile_lazy_widget, #turnstile_script_tag, #turnstile_widget, #validate_turnstile!

Methods included from Controllers::CloudflareCaching

edge_cached, #edge_cached_action?, #reset_cloudflare_cache, #set_cloudflare_cache, #skip_edge_cache!, #skip_session

Methods included from Controllers::Webpackable

#preload_webpack_fonts, #webpack_css_include, #webpack_css_url, #webpack_js_include, #wpd_is_running?

Methods included from Controllers::Localizable

#cloudflare_country_locale, #determine_request_locale, #geocoder_locale, #guest_user_locale_check, #locale_optional_www_auth_path?, #param_locale, #set_locale, #set_request_locale, #skip_localization?, #warmlyyours_ip_locale

Methods included from Controllers::Authenticable

#access_denied, #authenticate_account, #authenticate_account!, #authenticate_account_from_login_token!, #check_is_a_manager, #check_is_a_sales_manager, #check_is_an_admin, #check_is_an_employee, #check_party, #clear_mismatched_guest_user, #create_guest_user, #credentials?, #current_or_guest_user, #current_or_guest_user_id_read_only, #current_user, #devise_mapping, #fully_logged_in?, #generate_bot_id, #guest_user, #identifiable?, #init_current_user, #initialize_guest, #load_context_user, #logging_in, #resource, #resource_name, #restrict_access_for_non_employees, #scrubbed_request_path, #user_object, #warn_on_session_guest_id_leak

Methods included from UrlsHelper

#catalog_breadcrumb_links, #catalog_link, #catalog_link_for_product_line, #catalog_link_for_sku, #cms_link, #delocalized_path, #path_to_sales_product_sku, #path_to_sales_product_sku_for_product_line, #path_to_sales_product_sku_for_product_line_slug, #product_line_from_catalog_link, #protocol_neutral_url, #sanitize_external_url, #valid_external_url?

Instance Method Details

#download_invoicevoid

This method returns an undefined value.

Streams the order's invoice PDF, if one has been generated.



55
56
57
58
59
60
61
62
63
# File 'app/controllers/my_orders_controller.rb', line 55

def download_invoice
  @order = @context_user.customer.orders.non_carts.find(params[:id])
  i = @order.invoices.find(params[:invoice_id])
  if i && (pdf = i.uploads.in_category('invoice_pdf').first)
    send_upload_accelerated(pdf, file_name: "invoice-#{i.reference_number}.pdf")
  else
    render inline: 'File is missing', status: :not_found
  end
end

#editvoid

This method returns an undefined value.

Loads an order for editing.



68
69
70
# File 'app/controllers/my_orders_controller.rb', line 68

def edit
  @order = @context_user.customer.orders.non_carts.find(params[:id])
end

#indexvoid

This method returns an undefined value.

Lists the customer's orders, filtered by params[:view]
(pending_payment, in_progress, completed, default all).



18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
# File 'app/controllers/my_orders_controller.rb', line 18

def index
  view_mode = params[:view]
  # :warranties preloaded for the per-order "Register Warranty" button
  # (app/views/my_orders/_order.html.erb) — avoids one query per order.
  @all_orders = (@context_user || @party).orders.active.non_credit.includes(:warranties)
  case view_mode
  when 'pending_payment'
    @pagy, @orders = pagy(@all_orders.pending_payment_and_unpaid_invoices.most_recent_first)
  when 'in_progress'
    @pagy, @orders = pagy(@all_orders.in_progress.most_recent_first)
  when 'completed'
    @pagy, @orders = pagy(@all_orders.invoiced.most_recent_first)
  else
    @pagy, @orders = pagy(@all_orders.most_recent_first)
  end
end

#request_smartinstallvoid

This method returns an undefined value.

Records SmartInstall interest as a follow-up Activity on the order
(or the party, if the order can't be resolved). Reachable without
login.



112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
# File 'app/controllers/my_orders_controller.rb', line 112

def request_smartinstall
  @order = begin
    (@context_user || @party).orders.find(params[:id])
  rescue StandardError
    nil
  end
  if @order
    create_smartinstall_lead(params[:smartinstall], @order)
  else
    create_smartinstall_lead(params[:smartinstall])
  end
  respond_to do |format|
    format.json { head :ok }
    format.turbo_stream {}
    format.any { head :ok }
  end
end

#showvoid

This method returns an undefined value.

Shows a single order, with warranty-registration state for its
products.



39
40
41
42
43
44
45
46
47
48
49
50
# File 'app/controllers/my_orders_controller.rb', line 39

def show
  @order = @context_user.customer.orders.non_carts.find(params[:id])
  # Warranty coverage block + register button (see the view's Warranty
  # section) — displayable items only needed when something is registered.
  @order_warranty = @order.warranties.first
  @order_products = @order_warranty&.products&.order(:id).to_a
  @order_displayable_line_items = @order_warranty ? Warranty.displayable_line_items(@order) : []
  @order.update_attribute!(:first_view_date, Time.current)
rescue ActiveRecord::RecordNotFound
  flash[:error] = 'Order not found or not authorized'
  redirect_to cms_link('/my_account')
end

#updatevoid

This method returns an undefined value.

Updates an order, redirecting to the orders index (with a note) if the
update reassigned it away from the current user's visibility.



76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
# File 'app/controllers/my_orders_controller.rb', line 76

def update
  @order = @context_user.customer.orders.non_carts.find(params[:id])
  if @order.update(params[:order])
    flash[:info] = 'Order was successfully updated.'
    # here we deal with when a user reassigns the resource to another user and can no longer see it
    if can? :see, @order
      redirect_to_return_path_or_default (@order)
    else
      flash[:info] += ' Order was reassigned.'
      redirect_to_return_path_or_default 
    end
  else
    render :edit, status: :unprocessable_content
  end
end

#update_post_checkoutvoid

This method returns an undefined value.

Applies post-checkout updates to an order (e.g. from an unauthenticated
confirmation page). Reachable without login.



96
97
98
99
100
101
102
103
104
105
# File 'app/controllers/my_orders_controller.rb', line 96

def update_post_checkout
  @order = (@context_user || @party).orders.find(params[:id])
  return unless @order.present? && @order.update(params[:order])

  respond_to do |format|
    format.json { head :ok }
    format.turbo_stream { head :ok }
    format.any { head :ok }
  end
end