]> git.openstreetmap.org Git - rails.git/blob - app/controllers/friendships_controller.rb
Prevent API tokens without write_notes creating attributed comments
[rails.git] / app / controllers / friendships_controller.rb
1 class FriendshipsController < ApplicationController
2   include UserMethods
3
4   layout "site"
5
6   before_action :authorize_web
7   before_action :set_locale
8   before_action :check_database_readable
9
10   authorize_resource
11
12   before_action :check_database_writable, :only => [:make_friend, :remove_friend]
13   before_action :lookup_friend, :only => [:make_friend, :remove_friend]
14
15   def make_friend
16     if request.post?
17       friendship = Friendship.new
18       friendship.befriender = current_user
19       friendship.befriendee = @friend
20       if current_user.friends_with?(@friend)
21         flash[:warning] = t ".already_a_friend", :name => @friend.display_name
22       elsif current_user.friendships.where("created_at >= ?", Time.now.utc - 1.hour).count >= current_user.max_friends_per_hour
23         flash.now[:error] = t ".limit_exceeded"
24       elsif friendship.save
25         flash[:notice] = t ".success", :name => @friend.display_name
26         UserMailer.friendship_notification(friendship).deliver_later
27       else
28         friendship.add_error(t(".failed", :name => @friend.display_name))
29       end
30
31       referer = safe_referer(params[:referer]) if params[:referer]
32
33       redirect_to referer || user_path
34     end
35   end
36
37   def remove_friend
38     if request.post?
39       if current_user.friends_with?(@friend)
40         Friendship.where(:befriender => current_user, :befriendee => @friend).delete_all
41         flash[:notice] = t ".success", :name => @friend.display_name
42       else
43         flash[:error] = t ".not_a_friend", :name => @friend.display_name
44       end
45
46       referer = safe_referer(params[:referer]) if params[:referer]
47
48       redirect_to referer || user_path
49     end
50   end
51
52   private
53
54   ##
55   # ensure that there is a "friend" instance variable
56   def lookup_friend
57     @friend = User.active.find_by!(:display_name => params[:display_name])
58   rescue ActiveRecord::RecordNotFound
59     render_unknown_user params[:display_name]
60   end
61 end