Class: Www::MasqueradesController
- Inherits:
-
BasePortalController
- Object
- ActionController::Base
- ApplicationController
- BasePortalController
- Www::MasqueradesController
- Defined in:
- app/controllers/www/masquerades_controller.rb
Overview
Receives the signed handoff token minted by Crm::AccountsController#become,
atomically consumes it, signs the employee in (so AuthTrail records the
real actor), then immediately calls pretender's impersonate_account so
current_account returns the customer for the rest of the session.
Lifecycle:
GET /masquerade/new?token= -> sign in employee + impersonate customer
DELETE /masquerade -> stop impersonating + sign out
Cross-subdomain handoff is unavoidable because CRM and WWW have separate
session cookies; pretender alone cannot bridge that gap. AuthTrail logs
the sign-in into login_activities with context: "masquerade" and a
properties payload identifying both accounts (see authtrail.rb).
Constant Summary
Constants included from Controllers::MasqueradeGuarded
Controllers::MasqueradeGuarded::DEFAULT_BLOCK_MESSAGE
Constants included from Controllers::AnalyticsEvents
Controllers::AnalyticsEvents::MAX_QUEUED_EVENTS, Controllers::AnalyticsEvents::SESSION_KEY
Constants included from Controllers::ErrorRendering
Controllers::ErrorRendering::NON_CONTENT_PATH_PREFIXES
Instance Method Summary collapse
-
#destroy ⇒ void
Ends the masquerade session and redirects back to the CRM.
-
#new ⇒ void
Consumes the signed masquerade handoff token and signs the employee in as the impersonated customer.
Methods inherited from BasePortalController
#current_ability, #portal_party, #set_catalog, #set_webpack
Methods included from Controllers::MasqueradeGuarded
block_while_masquerading, #masquerade_blocks?
Methods inherited from ApplicationController
#account_impersonated?, #add_to_flash, #after_sign_in_path_for, #bypass_forgery_protection?, #chat_enabled?, #cloudflare_cleared?, #default_catalog, #default_url_options, #enable_turbo_frames, #find_publication, #fix_invalid_accept_header, #init_js_utils, #is_globals_call?, #layout_by_resource, #locale_store, #redirect_to, #require_employee_for_crm, #set_base_host, #set_real_ip, #set_report_errors_for, #should_render_layout?, #skip_layout_for_turbo_frame?, #stamp_impersonation_context, #tab_frame_breakout_request?, #warmlyyours_canada_ip?, #warmlyyours_ip?, #y
Methods included from Controllers::ReturnPathHandling
#check_for_return_path, #redirect_to_return_path_or_default
Methods included from Controllers::AnalyticsEvents
#consume_queued_analytics_events, #registration_lead_type, #track_event
Methods included from Controllers::DeviceDetection
Methods included from Controllers::SubdomainDetection
#is_crm_request?, #is_www_request?, #json_request?
Methods included from Controllers::TurboSafeRedirect
Methods included from Controllers::TrackingDetection
#bot_request?, #gdpr_country?, #gdpr_country_data, #prevent_bots, #set_tracking_cookie, #track_visitor?
Methods included from Controllers::AcceleratedFileSending
#send_file_accelerated, #send_upload_accelerated
Methods included from Controllers::ErrorRendering
#excp_string, #mail_to_for_error_reporting, #render_400, #render_404, #render_406, #render_410, #render_500, #render_invalid_authenticity_token, #render_ip_spoof_error, #render_unpermitted_parameters, #safe_referer_or_fallback
Methods included from Controllers::TurnstileVerification
#load_turnstile_script_tag, #turnstile_lazy_widget, #turnstile_script_tag, #turnstile_widget, #validate_turnstile!
Methods included from Controllers::CloudflareCaching
edge_cached, #edge_cached_action?, #reset_cloudflare_cache, #set_cloudflare_cache, #skip_edge_cache!, #skip_session
Methods included from Controllers::Webpackable
#preload_webpack_fonts, #webpack_css_include, #webpack_css_url, #webpack_js_include, #wpd_is_running?
Methods included from Controllers::Localizable
#cloudflare_country_locale, #determine_request_locale, #geocoder_locale, #guest_user_locale_check, #locale_optional_www_auth_path?, #param_locale, #set_locale, #set_request_locale, #skip_localization?, #warmlyyours_ip_locale
Methods included from Controllers::Authenticable
#access_denied, #authenticate_account, #authenticate_account!, #authenticate_account_from_login_token!, #check_is_a_manager, #check_is_a_sales_manager, #check_is_an_admin, #check_is_an_employee, #check_party, #clear_mismatched_guest_user, #create_guest_user, #credentials?, #current_or_guest_user, #current_or_guest_user_id_read_only, #current_user, #devise_mapping, #fully_logged_in?, #generate_bot_id, #guest_user, #identifiable?, #init_current_user, #initialize_guest, #load_context_user, #logging_in, #resource, #resource_name, #restrict_access_for_non_employees, #scrubbed_request_path, #user_object, #warn_on_session_guest_id_leak
Methods included from UrlsHelper
#catalog_breadcrumb_links, #catalog_link, #catalog_link_for_product_line, #catalog_link_for_sku, #cms_link, #delocalized_path, #path_to_sales_product_sku, #path_to_sales_product_sku_for_product_line, #path_to_sales_product_sku_for_product_line_slug, #product_line_from_catalog_link, #protocol_neutral_url, #sanitize_external_url, #valid_external_url?
Instance Method Details
#destroy ⇒ void
This method returns an undefined value.
Ends the masquerade session and redirects back to the CRM.
38 39 40 41 |
# File 'app/controllers/www/masquerades_controller.rb', line 38 def destroy end_masquerade_session! respond_with_stop_redirect end |
#new ⇒ void
This method returns an undefined value.
Consumes the signed masquerade handoff token and signs the employee in
as the impersonated customer.
24 25 26 27 28 29 30 31 32 33 |
# File 'app/controllers/www/masquerades_controller.rb', line 24 def new consume_handoff_and_impersonate! rescue Masquerade::HandoffToken::ExpiredTokenError reject_handoff!('This masquerade link has expired. Please ask the employee to start a new session.') rescue Masquerade::HandoffToken::ReplayError reject_handoff!('This masquerade link has already been used. Please ask the employee to start a new session.') rescue Masquerade::HandoffToken::Error, ActiveRecord::RecordNotFound => e Rails.logger.warn("Masquerade handoff rejected: #{e.class}: #{e.}") reject_handoff!('Invalid masquerade link.') end |