docbrown/app/controllers/admin/settings_controller.rb
Michael Kohl 5406b0576e
Split Settings::Authentication from SiteConfig (#13095)
* Split Settings::Authentication from SiteConfig

* Move specs

* Sort fields

* Update settings usages

* Update recaptcha usages

* Add data update script

* Update spec

* Rename SiteConfigParams concern

* Fixes, new route, new controller

* Controller and service refactoring

* More controller and service updates

* Spec updates

* More spec fixes

* Move file

* Fix FeedbackMessagesController

* Update admin/configs_spec

* Fix remaining specs in admin/configs_spec

* Fix configs API

* Formatting

* Clean up old service object

* Various fixes

* Update DUS

* Add model argument to admin_config_label

* Fix key name

* Fix specs

* Add distinct request caches for settings classes

* Fix e2e tests

* Fix remaining system spec

* Make DUS idempotent

* Move routes block

* Cleanup

* Switch to ActiveSupport::CurrentAttributes

* Pinned rails-settings-cached

* Update e2e test

* Update lib/data_update_scripts/20210316091354_move_authentication_settings.rb

Co-authored-by: rhymes <rhymes@hey.com>

* Add guard to DUS

* Temporarily re-add two SiteConfig fields

* Fix config show view

Co-authored-by: rhymes <rhymes@hey.com>
2021-04-12 09:41:09 +02:00

30 lines
797 B
Ruby

module Admin
class SettingsController < Admin::ApplicationController
MISMATCH_ERROR = "The confirmation key does not match".freeze
before_action :extra_authorization_and_confirmation, only: [:create]
layout "admin"
def create; end
def show
@confirmation_text = confirmation_text
end
private
def extra_authorization_and_confirmation
not_authorized unless current_user.has_role?(:super_admin)
raise_confirmation_mismatch_error if params.require(:confirmation) != confirmation_text
end
def confirmation_text
"My username is @#{current_user.username} and this action is 100% safe and appropriate."
end
def raise_confirmation_mismatch_error
raise ActionController::BadRequest.new, MISMATCH_ERROR
end
end
end