Class: PostCommentsController

Inherits:
ApplicationController show all
Defined in:
app/controllers/post_comments_controller.rb

Overview

== Schema Information

Table name: post_comments

id :integer not null, primary key
post_id :integer
user_id :integer
user_ip :string(255)
user_agent :string(255)
referrer :string(255)
name :string(255)
site_url :string(255)
email :string(255)
body :text
created_at :datetime
blogger_id :string(255)

Public commenting on blog Posts: submission (Turnstile-gated), and
blog-admin-only moderation (edit/update/destroy).

Constant Summary

Constants included from Controllers::AnalyticsEvents

Controllers::AnalyticsEvents::MAX_QUEUED_EVENTS, Controllers::AnalyticsEvents::SESSION_KEY

Constants included from Controllers::ErrorRendering

Controllers::ErrorRendering::NON_CONTENT_PATH_PREFIXES

Instance Method Summary collapse

Methods inherited from ApplicationController

#account_impersonated?, #add_to_flash, #after_sign_in_path_for, #bypass_forgery_protection?, #chat_enabled?, #cloudflare_cleared?, #default_catalog, #default_url_options, #enable_turbo_frames, #find_publication, #fix_invalid_accept_header, #init_js_utils, #is_globals_call?, #layout_by_resource, #locale_store, #redirect_to, #require_employee_for_crm, #set_base_host, #set_real_ip, #should_render_layout?, #skip_layout_for_turbo_frame?, #stamp_impersonation_context, #tab_frame_breakout_request?, #warmlyyours_canada_ip?, #warmlyyours_ip?, #y

Methods included from Controllers::ReturnPathHandling

#check_for_return_path, #redirect_to_return_path_or_default

Methods included from Controllers::AnalyticsEvents

#consume_queued_analytics_events, #registration_lead_type, #track_event

Methods included from Controllers::DeviceDetection

#device_detector, #is_ie?

Methods included from Controllers::SubdomainDetection

#is_crm_request?, #is_www_request?, #json_request?

Methods included from Controllers::TurboSafeRedirect

#redirect_to

Methods included from Controllers::TrackingDetection

#bot_request?, #gdpr_country?, #gdpr_country_data, #prevent_bots, #set_tracking_cookie, #track_visitor?

Methods included from Controllers::AcceleratedFileSending

#send_file_accelerated, #send_upload_accelerated

Methods included from Controllers::ErrorRendering

#excp_string, #mail_to_for_error_reporting, #render_400, #render_404, #render_406, #render_410, #render_500, #render_invalid_authenticity_token, #render_ip_spoof_error, #render_unpermitted_parameters, #safe_referer_or_fallback

Methods included from Controllers::TurnstileVerification

#load_turnstile_script_tag, #turnstile_lazy_widget, #turnstile_script_tag, #turnstile_widget, #validate_turnstile!

Methods included from Controllers::CloudflareCaching

edge_cached, #edge_cached_action?, #reset_cloudflare_cache, #set_cloudflare_cache, #skip_edge_cache!, #skip_session

Methods included from Controllers::Webpackable

#preload_webpack_fonts, #webpack_css_include, #webpack_css_url, #webpack_js_include, #wpd_is_running?

Methods included from Controllers::Localizable

#cloudflare_country_locale, #determine_request_locale, #geocoder_locale, #guest_user_locale_check, #locale_optional_www_auth_path?, #param_locale, #set_locale, #set_request_locale, #skip_localization?, #warmlyyours_ip_locale

Methods included from Controllers::Authenticable

#access_denied, #authenticate_account, #authenticate_account!, #authenticate_account_from_login_token!, #check_is_a_manager, #check_is_a_sales_manager, #check_is_an_admin, #check_is_an_employee, #check_party, #clear_mismatched_guest_user, #create_guest_user, #credentials?, #current_or_guest_user, #current_or_guest_user_id_read_only, #current_user, #devise_mapping, #fully_logged_in?, #generate_bot_id, #guest_user, #identifiable?, #init_current_user, #initialize_guest, #load_context_user, #logging_in, #resource, #resource_name, #restrict_access_for_non_employees, #scrubbed_request_path, #user_object, #warn_on_session_guest_id_leak

Methods included from UrlsHelper

#catalog_breadcrumb_links, #catalog_link, #catalog_link_for_product_line, #catalog_link_for_sku, #cms_link, #delocalized_path, #path_to_sales_product_sku, #path_to_sales_product_sku_for_product_line, #path_to_sales_product_sku_for_product_line_slug, #product_line_from_catalog_link, #protocol_neutral_url, #sanitize_external_url, #valid_external_url?

Instance Method Details

#createvoid

This method returns an undefined value.

Submits a comment for the post (goes to a review queue before
publishing). Anonymous commenters are recorded as "Guest User".



57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
# File 'app/controllers/post_comments_controller.rb', line 57

def create
  # Turnstile validates bot protection via before_action
  # Comments go to review queue, so no additional spam check needed
  @post_comment = @post.post_comments.new(params[:post_comment])
  @post_comment.user_id = current_user.id if current_user
  @post_comment.name = 'Guest User' unless current_user
  @post_comment.request = request

  if @post_comment.save
    respond_to do |format|
      flash[:info] = 'Your comment has been submitted to our review queue, please allow some time for our team to review.'
      format.html { redirect_to cms_link("/posts/#{@post.id}") }
    end
  else
    respond_to do |format|
      format.html do
        @pagy, @post_comments = pagy(@post.post_comments.order(created_at: :desc))
        render template: 'posts/show', layout: 'cms_page_blog'
      end
    end
  end
end

#destroyvoid

This method returns an undefined value.

Deletes a comment, if the current user owns it or is a blog admin.



100
101
102
103
104
105
106
107
108
109
110
111
112
# File 'app/controllers/post_comments_controller.rb', line 100

def destroy
  @post_comment = PostComment.find(params[:id])
  if current_user && ((@post_comment.user == current_user) || current_user.blog_admin?)
    @post_comment.destroy
    flash[:info] = 'The comment has been deleted'
  else
    flash[:error] = 'The comment does not belong to you.'
  end

  respond_to do |format|
    format.html { redirect_to(@post) }
  end
end

#editvoid

This method returns an undefined value.

Loads a comment for editing (blog admins only, via require_admin).



48
49
50
51
# File 'app/controllers/post_comments_controller.rb', line 48

def edit
  @post_comment = @post.post_comments.find(params[:id])
  logger.info "post_comments_controller#edit, @post.id: #{@post.id}, @post_comment.id: #{@post_comment.id}"
end

#indexvoid

This method returns an undefined value.

Redirects to the parent post (comments have no standalone index).



41
42
43
# File 'app/controllers/post_comments_controller.rb', line 41

def index
  redirect_to @post
end

#set_report_errors_forvoid

This method returns an undefined value.

Registers @post_comment as the record whose errors should be
reported by the shared error-reporting concern.



27
28
29
30
# File 'app/controllers/post_comments_controller.rb', line 27

def set_report_errors_for
  @report_errors_for ||= []
  @report_errors_for << @post_comment
end

#updatevoid

This method returns an undefined value.

Updates a comment (blog admins only, via require_admin).



83
84
85
86
87
88
89
90
91
92
93
94
95
# File 'app/controllers/post_comments_controller.rb', line 83

def update
  @post_comment = @post.post_comments.find(params[:id])
  @post_comment.update(params[:post_comment])

  respond_to do |format|
    if @post_comment.update((params[:post] || {}).merge(params[:blog_post] || {}).merge(params[:article_post] || {}))
      flash[:info] = 'Blog Comment was successfully updated.'
      format.html { redirect_to(@post) }
    else
      format.html { render action: 'edit', status: :unprocessable_content }
    end
  end
end