mirror of
https://github.com/maybe-finance/maybe.git
synced 2025-07-18 20:59:39 +02:00
* Initial impersonation * Impersonation audit * Keep super admin separate * Remove vscode settings * Comment cleanup * Comment out impersonation fixtures for now * Remove unused controlelr * Add impersonation testing (#1326) * Add impersonation testing * Remove unused method * Update schema.rb * Update brakeman --------- Co-authored-by: Zach Gollwitzer <zach@maybe.co>
58 lines
1.8 KiB
Ruby
58 lines
1.8 KiB
Ruby
class ImpersonationSessionsController < ApplicationController
|
|
before_action :require_super_admin!, only: [ :create, :join, :leave ]
|
|
before_action :set_impersonation_session, only: [ :approve, :reject, :complete ]
|
|
|
|
def create
|
|
Current.true_user.request_impersonation_for(session_params[:impersonated_id])
|
|
redirect_to root_path, notice: t(".success")
|
|
end
|
|
|
|
def join
|
|
@impersonation_session = Current.true_user.impersonator_support_sessions.find_by(id: params[:impersonation_session_id])
|
|
Current.session.update!(active_impersonator_session: @impersonation_session)
|
|
redirect_to root_path, notice: t(".success")
|
|
end
|
|
|
|
def leave
|
|
Current.session.update!(active_impersonator_session: nil)
|
|
redirect_to root_path, notice: t(".success")
|
|
end
|
|
|
|
def approve
|
|
raise_unauthorized! unless @impersonation_session.impersonated == Current.true_user
|
|
|
|
@impersonation_session.approve!
|
|
redirect_to root_path, notice: t(".success")
|
|
end
|
|
|
|
def reject
|
|
raise_unauthorized! unless @impersonation_session.impersonated == Current.true_user
|
|
|
|
@impersonation_session.reject!
|
|
redirect_to root_path, notice: t(".success")
|
|
end
|
|
|
|
def complete
|
|
@impersonation_session.complete!
|
|
redirect_to root_path, notice: t(".success")
|
|
end
|
|
|
|
private
|
|
def session_params
|
|
params.require(:impersonation_session).permit(:impersonated_id)
|
|
end
|
|
|
|
def set_impersonation_session
|
|
@impersonation_session =
|
|
Current.true_user.impersonated_support_sessions.find_by(id: params[:id]) ||
|
|
Current.true_user.impersonator_support_sessions.find_by(id: params[:id])
|
|
end
|
|
|
|
def require_super_admin!
|
|
raise_unauthorized! unless Current.true_user&.super_admin?
|
|
end
|
|
|
|
def raise_unauthorized!
|
|
raise ActionController::RoutingError.new("Not Found")
|
|
end
|
|
end
|