Class: PostCommentsController
- Inherits:
-
ApplicationController
- Object
- ActionController::Base
- ApplicationController
- PostCommentsController
- Defined in:
- app/controllers/post_comments_controller.rb
Overview
== Schema Information
Table name: post_comments
id :integer not null, primary key
post_id :integer
user_id :integer
user_ip :string(255)
user_agent :string(255)
referrer :string(255)
name :string(255)
site_url :string(255)
email :string(255)
body :text
created_at :datetime
blogger_id :string(255)
Public commenting on blog Posts: submission (Turnstile-gated), and
blog-admin-only moderation (edit/update/destroy).
Constant Summary
Constants included from Controllers::AnalyticsEvents
Controllers::AnalyticsEvents::MAX_QUEUED_EVENTS, Controllers::AnalyticsEvents::SESSION_KEY
Constants included from Controllers::ErrorRendering
Controllers::ErrorRendering::NON_CONTENT_PATH_PREFIXES
Instance Method Summary collapse
-
#create ⇒ void
Submits a comment for the post (goes to a review queue before publishing).
-
#destroy ⇒ void
Deletes a comment, if the current user owns it or is a blog admin.
-
#edit ⇒ void
Loads a comment for editing (blog admins only, via
require_admin). -
#index ⇒ void
Redirects to the parent post (comments have no standalone index).
-
#set_report_errors_for ⇒ void
Registers
@post_commentas the record whose errors should be reported by the shared error-reporting concern. -
#update ⇒ void
Updates a comment (blog admins only, via
require_admin).
Methods inherited from ApplicationController
#account_impersonated?, #add_to_flash, #after_sign_in_path_for, #bypass_forgery_protection?, #chat_enabled?, #cloudflare_cleared?, #default_catalog, #default_url_options, #enable_turbo_frames, #find_publication, #fix_invalid_accept_header, #init_js_utils, #is_globals_call?, #layout_by_resource, #locale_store, #redirect_to, #require_employee_for_crm, #set_base_host, #set_real_ip, #should_render_layout?, #skip_layout_for_turbo_frame?, #stamp_impersonation_context, #tab_frame_breakout_request?, #warmlyyours_canada_ip?, #warmlyyours_ip?, #y
Methods included from Controllers::ReturnPathHandling
#check_for_return_path, #redirect_to_return_path_or_default
Methods included from Controllers::AnalyticsEvents
#consume_queued_analytics_events, #registration_lead_type, #track_event
Methods included from Controllers::DeviceDetection
Methods included from Controllers::SubdomainDetection
#is_crm_request?, #is_www_request?, #json_request?
Methods included from Controllers::TurboSafeRedirect
Methods included from Controllers::TrackingDetection
#bot_request?, #gdpr_country?, #gdpr_country_data, #prevent_bots, #set_tracking_cookie, #track_visitor?
Methods included from Controllers::AcceleratedFileSending
#send_file_accelerated, #send_upload_accelerated
Methods included from Controllers::ErrorRendering
#excp_string, #mail_to_for_error_reporting, #render_400, #render_404, #render_406, #render_410, #render_500, #render_invalid_authenticity_token, #render_ip_spoof_error, #render_unpermitted_parameters, #safe_referer_or_fallback
Methods included from Controllers::TurnstileVerification
#load_turnstile_script_tag, #turnstile_lazy_widget, #turnstile_script_tag, #turnstile_widget, #validate_turnstile!
Methods included from Controllers::CloudflareCaching
edge_cached, #edge_cached_action?, #reset_cloudflare_cache, #set_cloudflare_cache, #skip_edge_cache!, #skip_session
Methods included from Controllers::Webpackable
#preload_webpack_fonts, #webpack_css_include, #webpack_css_url, #webpack_js_include, #wpd_is_running?
Methods included from Controllers::Localizable
#cloudflare_country_locale, #determine_request_locale, #geocoder_locale, #guest_user_locale_check, #locale_optional_www_auth_path?, #param_locale, #set_locale, #set_request_locale, #skip_localization?, #warmlyyours_ip_locale
Methods included from Controllers::Authenticable
#access_denied, #authenticate_account, #authenticate_account!, #authenticate_account_from_login_token!, #check_is_a_manager, #check_is_a_sales_manager, #check_is_an_admin, #check_is_an_employee, #check_party, #clear_mismatched_guest_user, #create_guest_user, #credentials?, #current_or_guest_user, #current_or_guest_user_id_read_only, #current_user, #devise_mapping, #fully_logged_in?, #generate_bot_id, #guest_user, #identifiable?, #init_current_user, #initialize_guest, #load_context_user, #logging_in, #resource, #resource_name, #restrict_access_for_non_employees, #scrubbed_request_path, #user_object, #warn_on_session_guest_id_leak
Methods included from UrlsHelper
#catalog_breadcrumb_links, #catalog_link, #catalog_link_for_product_line, #catalog_link_for_sku, #cms_link, #delocalized_path, #path_to_sales_product_sku, #path_to_sales_product_sku_for_product_line, #path_to_sales_product_sku_for_product_line_slug, #product_line_from_catalog_link, #protocol_neutral_url, #sanitize_external_url, #valid_external_url?
Instance Method Details
#create ⇒ void
This method returns an undefined value.
Submits a comment for the post (goes to a review queue before
publishing). Anonymous commenters are recorded as "Guest User".
57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 |
# File 'app/controllers/post_comments_controller.rb', line 57 def create # Turnstile validates bot protection via before_action # Comments go to review queue, so no additional spam check needed @post_comment = @post.post_comments.new(params[:post_comment]) @post_comment.user_id = current_user.id if current_user @post_comment.name = 'Guest User' unless current_user @post_comment.request = request if @post_comment.save respond_to do |format| flash[:info] = 'Your comment has been submitted to our review queue, please allow some time for our team to review.' format.html { redirect_to cms_link("/posts/#{@post.id}") } end else respond_to do |format| format.html do @pagy, @post_comments = pagy(@post.post_comments.order(created_at: :desc)) render template: 'posts/show', layout: 'cms_page_blog' end end end end |
#destroy ⇒ void
This method returns an undefined value.
Deletes a comment, if the current user owns it or is a blog admin.
100 101 102 103 104 105 106 107 108 109 110 111 112 |
# File 'app/controllers/post_comments_controller.rb', line 100 def destroy @post_comment = PostComment.find(params[:id]) if current_user && ((@post_comment.user == current_user) || current_user.blog_admin?) @post_comment.destroy flash[:info] = 'The comment has been deleted' else flash[:error] = 'The comment does not belong to you.' end respond_to do |format| format.html { redirect_to(@post) } end end |
#edit ⇒ void
This method returns an undefined value.
Loads a comment for editing (blog admins only, via require_admin).
48 49 50 51 |
# File 'app/controllers/post_comments_controller.rb', line 48 def edit @post_comment = @post.post_comments.find(params[:id]) logger.info "post_comments_controller#edit, @post.id: #{@post.id}, @post_comment.id: #{@post_comment.id}" end |
#index ⇒ void
This method returns an undefined value.
Redirects to the parent post (comments have no standalone index).
41 42 43 |
# File 'app/controllers/post_comments_controller.rb', line 41 def index redirect_to @post end |
#set_report_errors_for ⇒ void
This method returns an undefined value.
Registers @post_comment as the record whose errors should be
reported by the shared error-reporting concern.
27 28 29 30 |
# File 'app/controllers/post_comments_controller.rb', line 27 def set_report_errors_for @report_errors_for ||= [] @report_errors_for << @post_comment end |
#update ⇒ void
This method returns an undefined value.
Updates a comment (blog admins only, via require_admin).
83 84 85 86 87 88 89 90 91 92 93 94 95 |
# File 'app/controllers/post_comments_controller.rb', line 83 def update @post_comment = @post.post_comments.find(params[:id]) @post_comment.update(params[:post_comment]) respond_to do |format| if @post_comment.update((params[:post] || {}).merge(params[:blog_post] || {}).merge(params[:article_post] || {})) flash[:info] = 'Blog Comment was successfully updated.' format.html { redirect_to(@post) } else format.html { render action: 'edit', status: :unprocessable_content } end end end |