Class: PagesController

Inherits:
BasePortalController show all
Defined in:
app/controllers/pages_controller.rb

Overview

Renders static/CMS marketing pages from app/views/pages/**/*.html.erb
by filesystem-derived id, plus the page sitemap. Edge-cached; 404s route
through render_404 rather than raising.

Constant Summary collapse

CONTENT_PATH =

Filesystem/URL path for content.

"pages"

Constants included from Controllers::MasqueradeGuarded

Controllers::MasqueradeGuarded::DEFAULT_BLOCK_MESSAGE

Constants included from Controllers::AnalyticsEvents

Controllers::AnalyticsEvents::MAX_QUEUED_EVENTS, Controllers::AnalyticsEvents::SESSION_KEY

Constants included from Controllers::ErrorRendering

Controllers::ErrorRendering::NON_CONTENT_PATH_PREFIXES

Instance Attribute Summary collapse

Class Method Summary collapse

Instance Method Summary collapse

Methods inherited from BasePortalController

#current_ability, #portal_party, #set_catalog, #set_webpack

Methods included from Controllers::MasqueradeGuarded

block_while_masquerading, #masquerade_blocks?

Methods inherited from ApplicationController

#account_impersonated?, #add_to_flash, #after_sign_in_path_for, #bypass_forgery_protection?, #chat_enabled?, #cloudflare_cleared?, #default_catalog, #default_url_options, #enable_turbo_frames, #find_publication, #fix_invalid_accept_header, #init_js_utils, #is_globals_call?, #layout_by_resource, #locale_store, #redirect_to, #require_employee_for_crm, #set_base_host, #set_real_ip, #set_report_errors_for, #should_render_layout?, #skip_layout_for_turbo_frame?, #stamp_impersonation_context, #tab_frame_breakout_request?, #warmlyyours_canada_ip?, #warmlyyours_ip?, #y

Methods included from Controllers::ReturnPathHandling

#check_for_return_path, #redirect_to_return_path_or_default

Methods included from Controllers::AnalyticsEvents

#consume_queued_analytics_events, #registration_lead_type, #track_event

Methods included from Controllers::DeviceDetection

#device_detector, #is_ie?

Methods included from Controllers::SubdomainDetection

#is_crm_request?, #is_www_request?, #json_request?

Methods included from Controllers::TurboSafeRedirect

#redirect_to

Methods included from Controllers::TrackingDetection

#bot_request?, #gdpr_country?, #gdpr_country_data, #prevent_bots, #set_tracking_cookie, #track_visitor?

Methods included from Controllers::AcceleratedFileSending

#send_file_accelerated, #send_upload_accelerated

Methods included from Controllers::ErrorRendering

#excp_string, #mail_to_for_error_reporting, #render_400, #render_404, #render_406, #render_410, #render_500, #render_invalid_authenticity_token, #render_ip_spoof_error, #render_unpermitted_parameters, #safe_referer_or_fallback

Methods included from Controllers::TurnstileVerification

#load_turnstile_script_tag, #turnstile_lazy_widget, #turnstile_script_tag, #turnstile_widget, #validate_turnstile!

Methods included from Controllers::CloudflareCaching

edge_cached, #edge_cached_action?, #reset_cloudflare_cache, #set_cloudflare_cache, #skip_edge_cache!, #skip_session

Methods included from Controllers::Webpackable

#preload_webpack_fonts, #webpack_css_include, #webpack_css_url, #webpack_js_include, #wpd_is_running?

Methods included from Controllers::Localizable

#cloudflare_country_locale, #determine_request_locale, #geocoder_locale, #guest_user_locale_check, #locale_optional_www_auth_path?, #param_locale, #set_locale, #set_request_locale, #skip_localization?, #warmlyyours_ip_locale

Methods included from Controllers::Authenticable

#access_denied, #authenticate_account, #authenticate_account!, #authenticate_account_from_login_token!, #check_is_a_manager, #check_is_a_sales_manager, #check_is_an_admin, #check_is_an_employee, #check_party, #clear_mismatched_guest_user, #create_guest_user, #credentials?, #current_or_guest_user, #current_or_guest_user_id_read_only, #current_user, #devise_mapping, #fully_logged_in?, #generate_bot_id, #guest_user, #identifiable?, #init_current_user, #initialize_guest, #load_context_user, #logging_in, #resource, #resource_name, #restrict_access_for_non_employees, #scrubbed_request_path, #user_object, #warn_on_session_guest_id_leak

Methods included from UrlsHelper

#catalog_breadcrumb_links, #catalog_link, #catalog_link_for_product_line, #catalog_link_for_sku, #cms_link, #delocalized_path, #path_to_sales_product_sku, #path_to_sales_product_sku_for_product_line, #path_to_sales_product_sku_for_product_line_slug, #product_line_from_catalog_link, #protocol_neutral_url, #sanitize_external_url, #valid_external_url?

Instance Attribute Details

#main_tagObject (readonly, protected)

Returns the value of attribute main_tag.



127
128
129
# File 'app/controllers/pages_controller.rb', line 127

def main_tag
  @main_tag
end

Class Method Details

.catalog_rooted_page_idsArray<String>

Returns CMS page IDs whose first path segment matches a catalog
product-line root slug (e.g. "floor-heating/heated-floor-mat").

Logic Details

config/routes/www.rb iterates this list to install explicit
pages#show routes ahead of Www::CatalogController's :root/*path
wildcard. Without those explicit routes, catalog-rooted CMS URLs would
match the wildcard first, return a cms_fallback result, and end up as
a 404 via Www::CatalogController#resolverender_404. Routing them
straight to PagesController#show keeps them on the edge_cached path
that wires up Cloudflare-CDN-Cache-Control.

Computed at boot from the filesystem (no DB), memoized, and frozen.
Adding a new CMS template under app/views/pages/<catalog-root>/
requires a server restart before the router picks it up.

Returns:

  • (Array<String>)

    frozen list of page IDs to route to pages#show

See Also:



97
98
99
100
101
# File 'app/controllers/pages_controller.rb', line 97

def self.catalog_rooted_page_ids
  @catalog_rooted_page_ids ||= page_ids.select do |id|
    CatalogPathResolver::PRODUCT_LINE_ROOT_SLUGS.include?(id.split('/').first)
  end.freeze
end

.page_idsArray<String>

Every routable page id, derived from the CMS template filesystem.

Returns:

  • (Array<String>)

    page ids (template paths relative to
    app/views/pages, minus the .html.erb extension)



72
73
74
75
76
77
# File 'app/controllers/pages_controller.rb', line 72

def self.page_ids
  pages_path = Rails.root.join("app/views", CONTENT_PATH)
  Dir.glob(pages_path.join("**/*.html.erb"))
     .map { |f| f.sub("#{pages_path}/", "").sub(/\.html\.erb$/, "") }
     .reject { |f| f.start_with?("_") || f.include?("/_") }
end

Instance Method Details

#cache_page?Boolean (protected)

Whether this page id is eligible for Cloudflare edge caching (a
denylist of pages that must always be dynamic).

Returns:

  • (Boolean)


116
117
118
# File 'app/controllers/pages_controller.rb', line 116

def cache_page?
  !params[:id].in?(['webinar', 'sales/refurbished', 'sales', 'sales/towel-warmer'])
end

#layout_for_pageString (protected)

The layout for CMS pages.

Returns:

  • (String)

    the layout name



108
109
110
# File 'app/controllers/pages_controller.rb', line 108

def layout_for_page
  'www/cms_page'
end

#set_main_tagvoid (protected)

This method returns an undefined value.

Resolves the page's associated DigitalAsset tag, if any.



123
124
125
# File 'app/controllers/pages_controller.rb', line 123

def set_main_tag
  @main_tag = DigitalAsset.page_tag_for(params[:id]) if params[:id].present?
end

#showvoid

This method returns an undefined value.

Renders the CMS page for params[:id], stashing any OAuth
token/verifier params into cookies for the page to consume.



43
44
45
46
47
48
49
50
51
52
53
54
# File 'app/controllers/pages_controller.rb', line 43

def show
  request.format = :html unless params[:format]&.in?(%i[html])

  if params[:oauth_token].present? && params[:oauth_verifier].present?
    cookies['oauth_token'] = params[:oauth_token]
    cookies['oauth_verifier'] = params[:oauth_verifier]
  end

  respond_to do |format|
    format.html { render(template: current_page, locals: { current_page: current_page }) }
  end
end

#sitemapvoid

This method returns an undefined value.

Lists every page id for the HTML/XML page sitemap.



59
60
61
62
63
64
65
66
# File 'app/controllers/pages_controller.rb', line 59

def sitemap
  @pages = self.class.page_ids
  set_cloudflare_cache(tags: %w[page])
  respond_to do |format|
    format.html
    format.xml
  end
end

#validate_page_idvoid (protected)

This method returns an undefined value.

Rejects malformed, overlong, or suspiciously repetitive page ids
(e.g. path-traversal probes) with a 404 before routing/rendering.



133
134
135
136
137
138
139
# File 'app/controllers/pages_controller.rb', line 133

def validate_page_id
  page_id = params[:id].to_s
  return render_404 unless page_id.match?(%r{\A[a-zA-Z0-9\-/_.]+\z})
  return render_404 if page_id.length > 200

  render_404 if page_id.match?(%r{(\w+)/\1/\1})
end