docbrown/app
Daniel Uber d48587721a
Only permit valid class names as sponsorable type (#14387)
* Only permit valid class names as sponsorable type

https://github.com/forem/forem/issues/14386 identified an error could
arise if input was provide to the sponsorable_type field in the admin
creation form, but it was not a valid constant (since we include the
related model in the index when loading @sponsorships, this permits
creating a sponsorship that can't easily be managed or deleted).

Add a validation to ensure when the sponsorable type is present, it's
a class (really, we probably want to also ensure it's available as an
associated model type, since we'll be looking it up with find(:sponsorable_id), but this
is an initial attempt at adding some guard rails to this form).

A more realistic solution would be to add a `Sponsorship::SPONSORABLE_TYPES` constant
to the class, and validate the supplied sponsorable type is in
`SPONSORABLE_TYPES.map(&:name)`. That requires more domain knowledge
about what kind of things can be sponsored than I have, it would
certainly include at least ActsAsTaggableOn::Tag but may include other
classes (or why would it be polymorphic).

* Explicitly list the allowed types for sponsorship

I see we can sponsor tags, and suspect that's all we can sponsor
meaningfully (the view only shows details when it is a tag).

* Use inclusion validation with options to replicate custom method

And remove the code, we don't need it any more.

* Update app/models/sponsorship.rb

Co-authored-by: Michael Kohl <citizen428@dev.to>

Co-authored-by: Michael Kohl <citizen428@dev.to>
2021-11-05 12:25:35 -05:00
..
assets Remove optional chaining syntax from comments page initializer (#15277) 2021-11-03 12:04:28 -05:00
black_box Make Rubocop happy again (#14729) 2021-09-14 09:15:01 -05:00
components/admin/users Small change to make the tools section of member details mobile friendly. (#15159) 2021-10-22 18:47:20 +02:00
controllers Bug Fix: Following an organization from article's sidebar creates an incorrect follow record (#15093) 2021-11-05 12:40:20 -04:00
decorators Theming changes part 1: Rename default and night_theme (#15176) 2021-10-28 07:55:46 -04:00
errors When a user is blocked from commenting on an article, show correct error message (#15009) 2021-10-14 07:42:08 -06:00
helpers Bug Fix: Following an organization from article's sidebar creates an incorrect follow record (#15093) 2021-11-05 12:40:20 -04:00
javascript [Small Wins] Show character limits for profile inputs (#15255) 2021-11-05 09:11:42 -04:00
lib Tokenize settings menu and add French translations (#14905) 2021-10-06 17:53:58 +02:00
liquid_tags Remove redundant freeze calls (#14596) 2021-08-26 10:01:08 -04:00
mailers Re-add dynamic delivery_method for ApplicationMailer (#13994) 2021-06-23 15:17:27 -04:00
models Only permit valid class names as sponsorable type (#14387) 2021-11-05 12:25:35 -05:00
policies When a user is blocked from commenting on an article, show correct error message (#15009) 2021-10-14 07:42:08 -06:00
queries Adds validations to avoid creating unnecessary PNs (#14621) 2021-08-31 15:00:30 -06:00
refinements Drop profile columns from user (#10707) 2020-12-03 08:14:38 +07:00
sanitizers Remove redundant freeze calls (#14596) 2021-08-26 10:01:08 -04:00
serializers Remove duplicated work display from header / profile work (#14210) 2021-07-30 12:28:40 +02:00
services Disable all providers when providers_to_enable param is blank (#15260) 2021-11-02 21:20:26 -04:00
uploaders ✂✂✂ Remove events (#15062) 2021-10-15 09:31:08 -04:00
validators Remove redundant freeze calls (#14596) 2021-08-26 10:01:08 -04:00
view_objects Upgrade to Ruby 3.0.2 (#12103) 2021-08-25 14:26:33 -04:00
views [Small Wins] Show character limits for profile inputs (#15255) 2021-11-05 09:11:42 -04:00
workers Add PGHero for more insights into the DB (#15073) 2021-11-05 12:25:02 -04:00