docbrown/app/controllers/admin/spaces_controller.rb
Jeremy Friesen 88f4daf952
Penciling in a Default Spaces section (#16897)
* Penciling in a Default Spaces section

This delivers two primary things:

1.  Extracting shared policy examples
2.  Providing a functioning skeleton for toggling on the
    "limit_post_creation_to_admins" feature.

Important is that once merged, it would be possible for this code to
"leak" out.  But how that leaks out is also how you can test that the
feature works.

First, to orient, there is a constraint for a new route.  That
constraint checks if the feature flag exists (e.g. has been explicitly
enabled or explicitly disabled).  In other words, at this point, you
can't accidentally enable the feature via the UI.  But once you have
enabled the feature, you can then toggle the feature on and off.

So, to test this in the browser:

1. Pull down this branch
2. Run `rails runner "FeatureFlag.disable(:limit_post_creation_to_admins)"`
3. Startup your the web server.
4. Login as an administrator
5. Goto /admin/content_manager/spaces
   a. Bask in the glory of a plain HTML form
6. With another browser, login as another non-admin user
7. Go to /settings/extensions, you should see a section Publishing from RSS.
8. Now with the admin's session, update the form to turn on
  "limit_post_creation_to_admins"
9. Back to the non-admin browser, refresh /settings/extensions, you
   should no longer see the section Publishing from RSS.

Note: I have not included an admin menu item as that is related to and
dependent on some refactors I'm working on (see forem/forem#16888 and
forem/forem#16847).  So a bit of "security through obsurity"

Note: In the future, once we resolve forem/forem#16490, we'll start
toggling the "Create a Post" button.

Note: I am not including Cypress tests nor request tests for this
feature because the implementation details related to the testing via
that approach are a little too volitale.

Related to forem/forem#16842

* Updating copy based on forem/forem#16893

* styles

* styles

* dark styles

Co-authored-by: Paweł Ludwiczak <ludwiczakpawel@gmail.com>
2022-03-21 09:56:12 -04:00

49 lines
1.6 KiB
Ruby

module Admin
# @note The ./config/routes/admin.rb file has a constraint around this controller
#
# @see https://github.com/orgs/forem/projects/46/views/1 project
class SpacesController < Admin::ApplicationController
layout "admin"
# TODO: What kind of logging do we need? Any? Looking for guidance. I can assume we want to
# log changes to a space.
#
# after_action only: %i[update] { Audit::Logger.log(:moderator, current_user, params.dup) }
# @note I'm instantiating the @space because in the index view I'm rendering a form that then
# PUTs to the update action.
def index
authorize(Space)
@space = Space.new
end
# @note The initial implementation of Spaces is simply exposing a means of toggling on or off a
# feature flag. Further, the Space model is an ApplicationRecord model, but instead is
# the bare bones for a quick yet verbose implementation of the [Authorization System: use
# case 1-1](see https://github.com/orgs/forem/projects/46/views/1)
def update
# NOTE: We're not trying to find a space, we simply are treating this as a singleton type
# resource.
@space = Space.new(space_params)
authorize(@space)
# NOTE: As of <2022-03-16 Wed> we don't have validation on a space.
@space.save
respond_to do |wants|
wants.html do
redirect_to admin_spaces_path
end
wants.json do
render json: @space, status: :ok
end
end
end
private
def space_params
params.fetch(:space).permit(:limit_post_creation_to_admins)
end
end
end