Class: PagesController
- Inherits:
-
BasePortalController
- Object
- ActionController::Base
- ApplicationController
- BasePortalController
- PagesController
- Defined in:
- app/controllers/pages_controller.rb
Overview
Renders static/CMS marketing pages from app/views/pages/**/*.html.erb
by filesystem-derived id, plus the page sitemap. Edge-cached; 404s route
through render_404 rather than raising.
Constant Summary collapse
- CONTENT_PATH =
Filesystem/URL path for content.
"pages"
Constants included from Controllers::MasqueradeGuarded
Controllers::MasqueradeGuarded::DEFAULT_BLOCK_MESSAGE
Constants included from Controllers::AnalyticsEvents
Controllers::AnalyticsEvents::MAX_QUEUED_EVENTS, Controllers::AnalyticsEvents::SESSION_KEY
Constants included from Controllers::ErrorRendering
Controllers::ErrorRendering::NON_CONTENT_PATH_PREFIXES
Instance Attribute Summary collapse
-
#main_tag ⇒ Object
readonly
protected
Returns the value of attribute main_tag.
Class Method Summary collapse
-
.catalog_rooted_page_ids ⇒ Array<String>
Returns CMS page IDs whose first path segment matches a catalog product-line root slug (e.g.
"floor-heating/heated-floor-mat"). -
.page_ids ⇒ Array<String>
Every routable page id, derived from the CMS template filesystem.
Instance Method Summary collapse
-
#cache_page? ⇒ Boolean
protected
Whether this page id is eligible for Cloudflare edge caching (a denylist of pages that must always be dynamic).
-
#layout_for_page ⇒ String
protected
The layout for CMS pages.
-
#set_main_tag ⇒ void
protected
Resolves the page's associated DigitalAsset tag, if any.
-
#show ⇒ void
Renders the CMS page for
params[:id], stashing any OAuth token/verifier params into cookies for the page to consume. -
#sitemap ⇒ void
Lists every page id for the HTML/XML page sitemap.
-
#validate_page_id ⇒ void
protected
Rejects malformed, overlong, or suspiciously repetitive page ids (e.g. path-traversal probes) with a 404 before routing/rendering.
Methods inherited from BasePortalController
#current_ability, #portal_party, #set_catalog, #set_webpack
Methods included from Controllers::MasqueradeGuarded
block_while_masquerading, #masquerade_blocks?
Methods inherited from ApplicationController
#account_impersonated?, #add_to_flash, #after_sign_in_path_for, #bypass_forgery_protection?, #chat_enabled?, #cloudflare_cleared?, #default_catalog, #default_url_options, #enable_turbo_frames, #find_publication, #fix_invalid_accept_header, #init_js_utils, #is_globals_call?, #layout_by_resource, #locale_store, #redirect_to, #require_employee_for_crm, #set_base_host, #set_real_ip, #set_report_errors_for, #should_render_layout?, #skip_layout_for_turbo_frame?, #stamp_impersonation_context, #tab_frame_breakout_request?, #warmlyyours_canada_ip?, #warmlyyours_ip?, #y
Methods included from Controllers::ReturnPathHandling
#check_for_return_path, #redirect_to_return_path_or_default
Methods included from Controllers::AnalyticsEvents
#consume_queued_analytics_events, #registration_lead_type, #track_event
Methods included from Controllers::DeviceDetection
Methods included from Controllers::SubdomainDetection
#is_crm_request?, #is_www_request?, #json_request?
Methods included from Controllers::TurboSafeRedirect
Methods included from Controllers::TrackingDetection
#bot_request?, #gdpr_country?, #gdpr_country_data, #prevent_bots, #set_tracking_cookie, #track_visitor?
Methods included from Controllers::AcceleratedFileSending
#send_file_accelerated, #send_upload_accelerated
Methods included from Controllers::ErrorRendering
#excp_string, #mail_to_for_error_reporting, #render_400, #render_404, #render_406, #render_410, #render_500, #render_invalid_authenticity_token, #render_ip_spoof_error, #render_unpermitted_parameters, #safe_referer_or_fallback
Methods included from Controllers::TurnstileVerification
#load_turnstile_script_tag, #turnstile_lazy_widget, #turnstile_script_tag, #turnstile_widget, #validate_turnstile!
Methods included from Controllers::CloudflareCaching
edge_cached, #edge_cached_action?, #reset_cloudflare_cache, #set_cloudflare_cache, #skip_edge_cache!, #skip_session
Methods included from Controllers::Webpackable
#preload_webpack_fonts, #webpack_css_include, #webpack_css_url, #webpack_js_include, #wpd_is_running?
Methods included from Controllers::Localizable
#cloudflare_country_locale, #determine_request_locale, #geocoder_locale, #guest_user_locale_check, #locale_optional_www_auth_path?, #param_locale, #set_locale, #set_request_locale, #skip_localization?, #warmlyyours_ip_locale
Methods included from Controllers::Authenticable
#access_denied, #authenticate_account, #authenticate_account!, #authenticate_account_from_login_token!, #check_is_a_manager, #check_is_a_sales_manager, #check_is_an_admin, #check_is_an_employee, #check_party, #clear_mismatched_guest_user, #create_guest_user, #credentials?, #current_or_guest_user, #current_or_guest_user_id_read_only, #current_user, #devise_mapping, #fully_logged_in?, #generate_bot_id, #guest_user, #identifiable?, #init_current_user, #initialize_guest, #load_context_user, #logging_in, #resource, #resource_name, #restrict_access_for_non_employees, #scrubbed_request_path, #user_object, #warn_on_session_guest_id_leak
Methods included from UrlsHelper
#catalog_breadcrumb_links, #catalog_link, #catalog_link_for_product_line, #catalog_link_for_sku, #cms_link, #delocalized_path, #path_to_sales_product_sku, #path_to_sales_product_sku_for_product_line, #path_to_sales_product_sku_for_product_line_slug, #product_line_from_catalog_link, #protocol_neutral_url, #sanitize_external_url, #valid_external_url?
Instance Attribute Details
#main_tag ⇒ Object (readonly, protected)
Returns the value of attribute main_tag.
127 128 129 |
# File 'app/controllers/pages_controller.rb', line 127 def main_tag @main_tag end |
Class Method Details
.catalog_rooted_page_ids ⇒ Array<String>
Returns CMS page IDs whose first path segment matches a catalog
product-line root slug (e.g. "floor-heating/heated-floor-mat").
Logic Details
config/routes/www.rb iterates this list to install explicit
pages#show routes ahead of Www::CatalogController's :root/*path
wildcard. Without those explicit routes, catalog-rooted CMS URLs would
match the wildcard first, return a cms_fallback result, and end up as
a 404 via Www::CatalogController#resolve → render_404. Routing them
straight to PagesController#show keeps them on the edge_cached path
that wires up Cloudflare-CDN-Cache-Control.
Computed at boot from the filesystem (no DB), memoized, and frozen.
Adding a new CMS template under app/views/pages/<catalog-root>/
requires a server restart before the router picks it up.
97 98 99 100 101 |
# File 'app/controllers/pages_controller.rb', line 97 def self.catalog_rooted_page_ids @catalog_rooted_page_ids ||= page_ids.select do |id| CatalogPathResolver::PRODUCT_LINE_ROOT_SLUGS.include?(id.split('/').first) end.freeze end |
.page_ids ⇒ Array<String>
Every routable page id, derived from the CMS template filesystem.
72 73 74 75 76 77 |
# File 'app/controllers/pages_controller.rb', line 72 def self.page_ids pages_path = Rails.root.join("app/views", CONTENT_PATH) Dir.glob(pages_path.join("**/*.html.erb")) .map { |f| f.sub("#{pages_path}/", "").sub(/\.html\.erb$/, "") } .reject { |f| f.start_with?("_") || f.include?("/_") } end |
Instance Method Details
#cache_page? ⇒ Boolean (protected)
Whether this page id is eligible for Cloudflare edge caching (a
denylist of pages that must always be dynamic).
116 117 118 |
# File 'app/controllers/pages_controller.rb', line 116 def cache_page? !params[:id].in?(['webinar', 'sales/refurbished', 'sales', 'sales/towel-warmer']) end |
#layout_for_page ⇒ String (protected)
The layout for CMS pages.
108 109 110 |
# File 'app/controllers/pages_controller.rb', line 108 def layout_for_page 'www/cms_page' end |
#set_main_tag ⇒ void (protected)
This method returns an undefined value.
Resolves the page's associated DigitalAsset tag, if any.
123 124 125 |
# File 'app/controllers/pages_controller.rb', line 123 def set_main_tag @main_tag = DigitalAsset.page_tag_for(params[:id]) if params[:id].present? end |
#show ⇒ void
This method returns an undefined value.
Renders the CMS page for params[:id], stashing any OAuth
token/verifier params into cookies for the page to consume.
43 44 45 46 47 48 49 50 51 52 53 54 |
# File 'app/controllers/pages_controller.rb', line 43 def show request.format = :html unless params[:format]&.in?(%i[html]) if params[:oauth_token].present? && params[:oauth_verifier].present? ['oauth_token'] = params[:oauth_token] ['oauth_verifier'] = params[:oauth_verifier] end respond_to do |format| format.html { render(template: current_page, locals: { current_page: current_page }) } end end |
#sitemap ⇒ void
This method returns an undefined value.
Lists every page id for the HTML/XML page sitemap.
59 60 61 62 63 64 65 66 |
# File 'app/controllers/pages_controller.rb', line 59 def sitemap @pages = self.class.page_ids set_cloudflare_cache(tags: %w[page]) respond_to do |format| format.html format.xml end end |
#validate_page_id ⇒ void (protected)
This method returns an undefined value.
Rejects malformed, overlong, or suspiciously repetitive page ids
(e.g. path-traversal probes) with a 404 before routing/rendering.
133 134 135 136 137 138 139 |
# File 'app/controllers/pages_controller.rb', line 133 def validate_page_id page_id = params[:id].to_s return render_404 unless page_id.match?(%r{\A[a-zA-Z0-9\-/_.]+\z}) return render_404 if page_id.length > 200 render_404 if page_id.match?(%r{(\w+)/\1/\1}) end |