The belongs_to_creator macro was used to initialize the creator_id field to the CurrentUser. This made tests complicated because it meant you had to create and set the current user every time you wanted to create an object, when lead to the current user being set over and over again. It also meant you had to constantly be aware of what the CurrentUser was in many different contexts, which was often confusing. Setting creators explicitly simplifies everything greatly.
52 lines
1.5 KiB
Ruby
52 lines
1.5 KiB
Ruby
class UserFeedbacksController < ApplicationController
|
|
before_action :gold_only, :only => [:new, :edit, :create, :update]
|
|
respond_to :html, :xml, :json, :js
|
|
|
|
def new
|
|
@user_feedback = UserFeedback.new(user_feedback_params(:create))
|
|
respond_with(@user_feedback)
|
|
end
|
|
|
|
def edit
|
|
@user_feedback = UserFeedback.visible.find(params[:id])
|
|
check_privilege(@user_feedback)
|
|
respond_with(@user_feedback)
|
|
end
|
|
|
|
def show
|
|
@current_item = @user_feedback = UserFeedback.visible.find(params[:id])
|
|
respond_with(@user_feedback)
|
|
end
|
|
|
|
def index
|
|
@user_feedbacks = UserFeedback.includes(:user, :creator).paginated_search(params, count_pages: true)
|
|
respond_with(@user_feedbacks)
|
|
end
|
|
|
|
def create
|
|
@user_feedback = UserFeedback.create(user_feedback_params(:create).merge(creator: CurrentUser.user))
|
|
respond_with(@user_feedback)
|
|
end
|
|
|
|
def update
|
|
@user_feedback = UserFeedback.visible.find(params[:id])
|
|
check_privilege(@user_feedback)
|
|
@user_feedback.update(user_feedback_params(:update, @user_feedback))
|
|
respond_with(@user_feedback)
|
|
end
|
|
|
|
private
|
|
|
|
def check_privilege(user_feedback)
|
|
raise User::PrivilegeError unless user_feedback.editable_by?(CurrentUser.user)
|
|
end
|
|
|
|
def user_feedback_params(context, user_feedback = nil)
|
|
permitted_params = %i[body category]
|
|
permitted_params += %i[user_id user_name] if context == :create
|
|
permitted_params += %i[is_deleted] if context == :update && user_feedback.deletable_by?(CurrentUser.user)
|
|
|
|
params.fetch(:user_feedback, {}).permit(permitted_params)
|
|
end
|
|
end
|