* Split Settings::Authentication from SiteConfig * Move specs * Sort fields * Update settings usages * Update recaptcha usages * Add data update script * Update spec * Rename SiteConfigParams concern * Fixes, new route, new controller * Controller and service refactoring * More controller and service updates * Spec updates * More spec fixes * Move file * Fix FeedbackMessagesController * Update admin/configs_spec * Fix remaining specs in admin/configs_spec * Fix configs API * Formatting * Clean up old service object * Various fixes * Update DUS * Add model argument to admin_config_label * Fix key name * Fix specs * Add distinct request caches for settings classes * Fix e2e tests * Fix remaining system spec * Make DUS idempotent * Move routes block * Cleanup * Switch to ActiveSupport::CurrentAttributes * Pinned rails-settings-cached * Update e2e test * Update lib/data_update_scripts/20210316091354_move_authentication_settings.rb Co-authored-by: rhymes <rhymes@hey.com> * Add guard to DUS * Temporarily re-add two SiteConfig fields * Fix config show view Co-authored-by: rhymes <rhymes@hey.com>
30 lines
797 B
Ruby
30 lines
797 B
Ruby
module Admin
|
|
class SettingsController < Admin::ApplicationController
|
|
MISMATCH_ERROR = "The confirmation key does not match".freeze
|
|
|
|
before_action :extra_authorization_and_confirmation, only: [:create]
|
|
|
|
layout "admin"
|
|
|
|
def create; end
|
|
|
|
def show
|
|
@confirmation_text = confirmation_text
|
|
end
|
|
|
|
private
|
|
|
|
def extra_authorization_and_confirmation
|
|
not_authorized unless current_user.has_role?(:super_admin)
|
|
raise_confirmation_mismatch_error if params.require(:confirmation) != confirmation_text
|
|
end
|
|
|
|
def confirmation_text
|
|
"My username is @#{current_user.username} and this action is 100% safe and appropriate."
|
|
end
|
|
|
|
def raise_confirmation_mismatch_error
|
|
raise ActionController::BadRequest.new, MISMATCH_ERROR
|
|
end
|
|
end
|
|
end
|