* Switch from deprecated honeycomb-rails to honeycomb-beeline * Improve error handling, tests and add refactoring * Fix multiple fetching test and add one more The test wasn't actually testing the correct behavior, because the class by default force fetches. It worked because it wasn't reloading the user from the database. * Test that Honeycomb's client is doing its thing * Use some defensive programming to avoid any possible problem during shutdown * Fix typo * Use the new API to add fields to the current measured event * Use default instrumentation and add user info to event * Replace user.email with user.username, less personal data around * Use mocking instead of calling Honeycomb.init * Freeze time before traveling * Remove a flaky test dependent on rand
81 lines
2.4 KiB
Ruby
81 lines
2.4 KiB
Ruby
class ApplicationController < ActionController::Base
|
|
protect_from_forgery with: :exception, prepend: true
|
|
|
|
include Pundit
|
|
include Instrumentation
|
|
|
|
def require_http_auth
|
|
authenticate_or_request_with_http_basic do |username, password|
|
|
username == ApplicationConfig["APP_NAME"] && password == ApplicationConfig["APP_PASSWORD"]
|
|
end
|
|
end
|
|
|
|
def not_found
|
|
raise ActiveRecord::RecordNotFound, "Not Found"
|
|
end
|
|
|
|
def not_authorized
|
|
render json: "Error: not authorized", status: :unauthorized
|
|
raise NotAuthorizedError, "Unauthorized"
|
|
end
|
|
|
|
def efficient_current_user_id
|
|
session["warden.user.user.key"].flatten[0] if session["warden.user.user.key"].present?
|
|
end
|
|
|
|
def authenticate_user!
|
|
return if current_user
|
|
|
|
respond_to do |format|
|
|
format.html { redirect_to "/enter" }
|
|
format.json { render json: { error: "Please sign in" }, status: 401 }
|
|
end
|
|
end
|
|
|
|
def customize_params
|
|
params[:signed_in] = user_signed_in?.to_s
|
|
end
|
|
|
|
def after_sign_in_path_for(resource)
|
|
location = request.env["omniauth.origin"] || stored_location_for(resource) || "/dashboard"
|
|
context_param = resource.created_at > 40.seconds.ago ? "?newly-registered-user=true" : "?returning-user=true"
|
|
location + context_param
|
|
end
|
|
|
|
def raise_banned
|
|
raise "BANNED" if current_user&.banned
|
|
end
|
|
|
|
def internal_navigation?
|
|
params[:i] == "i"
|
|
end
|
|
helper_method :internal_navigation?
|
|
|
|
def valid_request_origin?
|
|
# This manually does what it was supposed to do on its own.
|
|
# We were getting this issue:
|
|
# HTTP Origin header (https://dev.to) didn't match request.base_url (http://dev.to)
|
|
# Not sure why, but once we work it out, we can delete this method.
|
|
# We are at least secure for now.
|
|
return if Rails.env.test?
|
|
|
|
if request.referer.present?
|
|
request.referer.start_with?(ApplicationConfig["APP_PROTOCOL"].to_s + ApplicationConfig["APP_DOMAIN"].to_s)
|
|
else
|
|
logger.info "**REQUEST ORIGIN CHECK** #{request.origin}"
|
|
raise InvalidAuthenticityToken, NULL_ORIGIN_MESSAGE if request.origin == "null"
|
|
|
|
request.origin.nil? || request.origin.gsub("https", "http") == request.base_url.gsub("https", "http")
|
|
end
|
|
end
|
|
|
|
def set_no_cache_header
|
|
response.headers["Cache-Control"] = "no-cache, no-store"
|
|
response.headers["Pragma"] = "no-cache"
|
|
response.headers["Expires"] = "Fri, 01 Jan 1990 00:00:00 GMT"
|
|
end
|
|
|
|
def touch_current_user
|
|
current_user.touch
|
|
end
|
|
end
|