Compare commits
4 Commits
master
...
enable-big
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
057bdfe882 | ||
|
|
545d12f427 | ||
|
|
ac7e67c20e | ||
|
|
9bafbe36db |
@@ -1,4 +1,5 @@
|
|||||||
class AccountSessionsController < ApplicationController
|
class AccountSessionsController < ApplicationController
|
||||||
|
skip_before_action :redirect_locked_accounts
|
||||||
def update
|
def update
|
||||||
authorize :account_session, :update?
|
authorize :account_session, :update?
|
||||||
session[:active_account] = account_session_params[:account_id]
|
session[:active_account] = account_session_params[:account_id]
|
||||||
|
|||||||
31
app/controllers/admin/account_locks_controller.rb
Normal file
31
app/controllers/admin/account_locks_controller.rb
Normal file
@@ -0,0 +1,31 @@
|
|||||||
|
class Admin::AccountLocksController < Admin::ApplicationController
|
||||||
|
before_action :set_account
|
||||||
|
|
||||||
|
def create
|
||||||
|
authorize :account_lock, :create?
|
||||||
|
@account.update(locked: true)
|
||||||
|
redirect_to admin_accounts_path, notice: 'Account locked'
|
||||||
|
end
|
||||||
|
|
||||||
|
def destroy
|
||||||
|
authorize :account_lock, :destroy?
|
||||||
|
@account.update(locked: false)
|
||||||
|
redirect_to admin_accounts_path, notice: 'Account unlocked'
|
||||||
|
end
|
||||||
|
|
||||||
|
private
|
||||||
|
|
||||||
|
def set_account
|
||||||
|
if params[:account_id].present?
|
||||||
|
@account = Account.find_by(slug: params[:account_id])
|
||||||
|
else
|
||||||
|
failure_redirect
|
||||||
|
end
|
||||||
|
rescue ActiveRecord::RecordNotFound
|
||||||
|
failure_redirect
|
||||||
|
end
|
||||||
|
|
||||||
|
def failure_redirect
|
||||||
|
redirect_to admin_accounts_path, alert: 'Failed to find the account'
|
||||||
|
end
|
||||||
|
end
|
||||||
@@ -13,6 +13,7 @@ class ApplicationController < ActionController::Base
|
|||||||
|
|
||||||
include SetCurrentRequestDetails
|
include SetCurrentRequestDetails
|
||||||
before_action :redirect_accountless
|
before_action :redirect_accountless
|
||||||
|
before_action :redirect_locked_accounts
|
||||||
|
|
||||||
private
|
private
|
||||||
|
|
||||||
@@ -29,6 +30,12 @@ class ApplicationController < ActionController::Base
|
|||||||
end
|
end
|
||||||
end
|
end
|
||||||
|
|
||||||
|
def redirect_locked_accounts
|
||||||
|
if Current.user && !Current.user.admin? && Current.account.present? && Current.account.locked?
|
||||||
|
redirect_to locked_account_path
|
||||||
|
end
|
||||||
|
end
|
||||||
|
|
||||||
def signed_in_as_admin?
|
def signed_in_as_admin?
|
||||||
signed_in? && current_user.admin?
|
signed_in? && current_user.admin?
|
||||||
end
|
end
|
||||||
|
|||||||
10
app/controllers/locked_accounts_controller.rb
Normal file
10
app/controllers/locked_accounts_controller.rb
Normal file
@@ -0,0 +1,10 @@
|
|||||||
|
class LockedAccountsController < ApplicationController
|
||||||
|
skip_before_action :redirect_locked_accounts
|
||||||
|
skip_after_action :verify_policy_scoped
|
||||||
|
|
||||||
|
def index
|
||||||
|
unless Current.account.locked?
|
||||||
|
redirect_to projects_path
|
||||||
|
end
|
||||||
|
end
|
||||||
|
end
|
||||||
9
app/policies/account_lock_policy.rb
Normal file
9
app/policies/account_lock_policy.rb
Normal file
@@ -0,0 +1,9 @@
|
|||||||
|
class AccountLockPolicy < ApplicationPolicy
|
||||||
|
def create?
|
||||||
|
user.admin?
|
||||||
|
end
|
||||||
|
|
||||||
|
def destroy?
|
||||||
|
user.admin?
|
||||||
|
end
|
||||||
|
end
|
||||||
@@ -30,6 +30,11 @@
|
|||||||
<%= link_to fa_icon("arrow-right", text: "Overview"), admin_account_path(account), class: "dropdown-item" %>
|
<%= link_to fa_icon("arrow-right", text: "Overview"), admin_account_path(account), class: "dropdown-item" %>
|
||||||
<%= link_to fa_icon("pencil", text: "Edit"), edit_admin_account_path(account), class: "dropdown-item" %>
|
<%= link_to fa_icon("pencil", text: "Edit"), edit_admin_account_path(account), class: "dropdown-item" %>
|
||||||
<%= link_to fa_icon("arrow-right", text: "Account Managers"), account_auths_path({ account_id: account.id}), class: "dropdown-item" %>
|
<%= link_to fa_icon("arrow-right", text: "Account Managers"), account_auths_path({ account_id: account.id}), class: "dropdown-item" %>
|
||||||
|
<% if account.locked? %>
|
||||||
|
<%= link_to fa_icon("unlock", text: "Unlock Account"), [:admin, account, :lock], method: :delete, class: "dropdown-item" %>
|
||||||
|
<% else %>
|
||||||
|
<%= link_to fa_icon("lock", text: "Lock Account"), [:admin, account, :lock], method: :post, class: "dropdown-item" %>
|
||||||
|
<% end %>
|
||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
</td>
|
</td>
|
||||||
|
|||||||
1
app/views/locked_accounts/index.html.erb
Normal file
1
app/views/locked_accounts/index.html.erb
Normal file
@@ -0,0 +1 @@
|
|||||||
|
<p><%= t '.account_locked_message' %></p>
|
||||||
@@ -1651,3 +1651,6 @@ en:
|
|||||||
edit: Edit
|
edit: Edit
|
||||||
report: Report
|
report: Report
|
||||||
generating: Generating...
|
generating: Generating...
|
||||||
|
locked_accounts:
|
||||||
|
index:
|
||||||
|
account_locked_message: This account is locked. Please contact a BIG admin.
|
||||||
|
|||||||
@@ -705,3 +705,6 @@ es:
|
|||||||
production_elements_logs: Production Elements Logs, and more (ES)
|
production_elements_logs: Production Elements Logs, and more (ES)
|
||||||
reduces_labor_cost: Reduces labor costs (ES)
|
reduces_labor_cost: Reduces labor costs (ES)
|
||||||
simplifies_cue_sheets: Simplifies Music Cue Sheets, Graphic Cue Sheets (ES)
|
simplifies_cue_sheets: Simplifies Music Cue Sheets, Graphic Cue Sheets (ES)
|
||||||
|
locked_accounts:
|
||||||
|
index:
|
||||||
|
account_locked_message: This account is locked. Please contact a BIG admin. (ES)
|
||||||
|
|||||||
@@ -30,7 +30,9 @@ Rails.application.routes.draw do
|
|||||||
namespace :admin do
|
namespace :admin do
|
||||||
mount Sidekiq::Web => '/background_queue', as: :background_queue
|
mount Sidekiq::Web => '/background_queue', as: :background_queue
|
||||||
|
|
||||||
resources :accounts, only: [:index, :new, :create, :edit, :update, :show]
|
resources :accounts, only: [:index, :new, :create, :edit, :update, :show] do
|
||||||
|
resource :account_lock, path: :lock, as: :lock, only: [:create, :destroy]
|
||||||
|
end
|
||||||
resources :users, only: [:index, :new, :create, :edit, :update, :destroy] do
|
resources :users, only: [:index, :new, :create, :edit, :update, :destroy] do
|
||||||
resource :masquerade, only: :create
|
resource :masquerade, only: :create
|
||||||
end
|
end
|
||||||
@@ -48,7 +50,9 @@ Rails.application.routes.draw do
|
|||||||
scope "(:locale)", locale: AVAILABLE_LOCALES_REGEX do
|
scope "(:locale)", locale: AVAILABLE_LOCALES_REGEX do
|
||||||
resource :account_session, only: [:update]
|
resource :account_session, only: [:update]
|
||||||
resource :session, only: [:destroy]
|
resource :session, only: [:destroy]
|
||||||
resource :account, only: [:new, :create, :update]
|
resource :account, only: [:new, :create, :update] do
|
||||||
|
get 'locked' => 'locked_accounts#index'
|
||||||
|
end
|
||||||
resources :account_auths, only: [:index, :create, :update, :destroy]
|
resources :account_auths, only: [:index, :create, :update, :destroy]
|
||||||
resources :projects, shallow: true do
|
resources :projects, shallow: true do
|
||||||
resources :acquired_media_releases, except: [:show], concerns: [:contractable, :notable, :file_uploadable]
|
resources :acquired_media_releases, except: [:show], concerns: [:contractable, :notable, :file_uploadable]
|
||||||
|
|||||||
5
db/migrate/20200908085319_add_locked_to_accounts.rb
Normal file
5
db/migrate/20200908085319_add_locked_to_accounts.rb
Normal file
@@ -0,0 +1,5 @@
|
|||||||
|
class AddLockedToAccounts < ActiveRecord::Migration[6.0]
|
||||||
|
def change
|
||||||
|
add_column :accounts, :locked, :boolean, default: false
|
||||||
|
end
|
||||||
|
end
|
||||||
@@ -95,7 +95,8 @@ CREATE TABLE public.accounts (
|
|||||||
slug character varying,
|
slug character varying,
|
||||||
plan_uid character varying,
|
plan_uid character varying,
|
||||||
created_at timestamp without time zone NOT NULL,
|
created_at timestamp without time zone NOT NULL,
|
||||||
updated_at timestamp without time zone NOT NULL
|
updated_at timestamp without time zone NOT NULL,
|
||||||
|
locked boolean DEFAULT false
|
||||||
);
|
);
|
||||||
|
|
||||||
|
|
||||||
@@ -4027,6 +4028,7 @@ INSERT INTO "schema_migrations" (version) VALUES
|
|||||||
('20200812060406'),
|
('20200812060406'),
|
||||||
('20200819070738'),
|
('20200819070738'),
|
||||||
('20200820082501'),
|
('20200820082501'),
|
||||||
('20200824171649');
|
('20200824171649'),
|
||||||
|
('20200908085319');
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
@@ -30,6 +30,24 @@ feature "Admin managing accounts" do
|
|||||||
expect(page).to have_content "Created at less than a minute ago"
|
expect(page).to have_content "Created at less than a minute ago"
|
||||||
end
|
end
|
||||||
|
|
||||||
|
scenario "locks and unlocks account" do
|
||||||
|
sign_in current_user
|
||||||
|
visit admin_signed_in_root_path
|
||||||
|
expect(Account.last.locked?).to eq false
|
||||||
|
|
||||||
|
click_button "Manage"
|
||||||
|
expect(page).not_to have_content "Unlock Account"
|
||||||
|
click_link "Lock Account"
|
||||||
|
|
||||||
|
expect(Account.last.locked?).to eq true
|
||||||
|
|
||||||
|
click_button "Manage"
|
||||||
|
expect(page).not_to have_content "Lock Account"
|
||||||
|
click_link "Unlock Account"
|
||||||
|
|
||||||
|
expect(Account.last.locked?).to eq false
|
||||||
|
end
|
||||||
|
|
||||||
scenario "sees videos for an account in the system" do
|
scenario "sees videos for an account in the system" do
|
||||||
visit_account_overview_page
|
visit_account_overview_page
|
||||||
|
|
||||||
|
|||||||
34
spec/features/user_managing_locked_account_spec.rb
Normal file
34
spec/features/user_managing_locked_account_spec.rb
Normal file
@@ -0,0 +1,34 @@
|
|||||||
|
require "rails_helper"
|
||||||
|
|
||||||
|
feature "User managing locked account" do
|
||||||
|
let(:user) { create(:user, :account_manager) }
|
||||||
|
let(:project) { create(:project) }
|
||||||
|
|
||||||
|
before do
|
||||||
|
sign_in(user)
|
||||||
|
user.accounts.first.update(locked: true)
|
||||||
|
end
|
||||||
|
|
||||||
|
scenario "user is redirected to custom landing page when opens projects index page" do
|
||||||
|
paths = [
|
||||||
|
projects_path,
|
||||||
|
project_path(project),
|
||||||
|
project_task_requests_path(project),
|
||||||
|
project_contract_templates_path(project),
|
||||||
|
project_broadcasts_path(project),
|
||||||
|
project_videos_path(project),
|
||||||
|
]
|
||||||
|
|
||||||
|
paths.each do |path|
|
||||||
|
visit path
|
||||||
|
|
||||||
|
expect(page).to have_content locked_account_warning
|
||||||
|
end
|
||||||
|
end
|
||||||
|
|
||||||
|
private
|
||||||
|
|
||||||
|
def locked_account_warning
|
||||||
|
t 'locked_accounts.index.account_locked_message'
|
||||||
|
end
|
||||||
|
end
|
||||||
Reference in New Issue
Block a user