X-Git-Url: https://git.arvados.org/arvados.git/blobdiff_plain/b333125afe1ea130c7ea2438844983fcd7f08f1f..cc527a74c89f44267c50a52194ec0560484a72a0:/apps/workbench/app/controllers/application_controller.rb diff --git a/apps/workbench/app/controllers/application_controller.rb b/apps/workbench/app/controllers/application_controller.rb index 126dbbe14e..27a4f79c42 100644 --- a/apps/workbench/app/controllers/application_controller.rb +++ b/apps/workbench/app/controllers/application_controller.rb @@ -1,8 +1,11 @@ class ApplicationController < ActionController::Base + respond_to :html, :json, :js protect_from_forgery around_filter :thread_clear around_filter :thread_with_api_token, :except => [:render_exception, :render_not_found] before_filter :find_object_by_uuid, :except => [:index, :render_exception, :render_not_found] + before_filter :check_user_agreements, :except => [:render_exception, :render_not_found] + theme :select_theme begin rescue_from Exception, @@ -25,8 +28,12 @@ class ApplicationController < ActionController::Base def render_error(opts) respond_to do |f| - f.html { render opts.merge(controller: 'application', action: 'error') } + # json must come before html here, so it gets used as the + # default format when js is requested by the client. This lets + # ajax:error callback parse the response correctly, even though + # the browser can't. f.json { render opts.merge(json: {success: false, errors: @errors}) } + f.html { render opts.merge(controller: 'application', action: 'error') } end end @@ -36,7 +43,7 @@ class ApplicationController < ActionController::Base if @object.andand.errors.andand.full_messages.andand.any? @errors = @object.errors.full_messages else - @errors = [e.inspect] + @errors = [e.to_s] end self.render_error status: 422 end @@ -47,12 +54,12 @@ class ApplicationController < ActionController::Base self.render_error status: 404 end - def index - @objects ||= model_class.all + @objects ||= model_class.limit(1000).all respond_to do |f| f.json { render json: @objects } f.html { render } + f.js { render } end end @@ -62,7 +69,14 @@ class ApplicationController < ActionController::Base end respond_to do |f| f.json { render json: @object } - f.html { render } + f.html { + if request.method == 'GET' + render + else + redirect_to params[:return_to] || @object + end + } + f.js { render } end end @@ -93,12 +107,17 @@ class ApplicationController < ActionController::Base def create @object ||= model_class.new params[model_class.to_s.singularize.to_sym] @object.save! - redirect_to @object + redirect_to(params[:return_to] || @object) end def destroy if @object.destroy - redirect_to(params[:return_to] || :back) + respond_to do |f| + f.html { + redirect_to(params[:return_to] || :back) + } + f.js { render } + end else self.render_error status: 422 end @@ -117,6 +136,11 @@ class ApplicationController < ActionController::Base controller_name.classify.constantize end + def breadcrumb_page_name + (@breadcrumb_page_name || + (@object.friendly_link_name if @object.respond_to? :friendly_link_name)) + end + protected def find_object_by_uuid @@ -133,10 +157,12 @@ class ApplicationController < ActionController::Base def thread_clear Thread.current[:arvados_api_token] = nil Thread.current[:user] = nil + Rails.cache.delete_matched(/^request_#{Thread.current.object_id}_/) yield + Rails.cache.delete_matched(/^request_#{Thread.current.object_id}_/) end - def thread_with_api_token + def thread_with_api_token(login_optional = false) begin try_redirect_to_login = true if params[:api_token] @@ -174,19 +200,25 @@ class ApplicationController < ActionController::Base logger.debug "No token received, session is #{session.inspect}" end if try_redirect_to_login - respond_to do |f| - f.html { - if request.method == 'GET' - redirect_to $arvados_api_client.arvados_login_url(return_to: request.url) - else - flash[:error] = "Either you are not logged in, or your session has timed out. I can't automatically log you in and re-attempt this request." - redirect_to :back - end - } - f.json { - @errors = ['You do not seem to be logged in. You did not supply an API token with this request, and your session (if any) has timed out.'] - self.render_error status: 422 - } + unless login_optional + respond_to do |f| + f.html { + if request.method == 'GET' + redirect_to $arvados_api_client.arvados_login_url(return_to: request.url) + else + flash[:error] = "Either you are not logged in, or your session has timed out. I can't automatically log you in and re-attempt this request." + redirect_to :back + end + } + f.json { + @errors = ['You do not seem to be logged in. You did not supply an API token with this request, and your session (if any) has timed out.'] + self.render_error status: 422 + } + end + else + # login is optional for this route so go on to the regular controller + Thread.current[:arvados_api_token] = nil + yield end end ensure @@ -195,6 +227,12 @@ class ApplicationController < ActionController::Base end end + def thread_with_optional_api_token + thread_with_api_token(true) do + yield + end + end + def verify_api_token begin Link.where(uuid: 'just-verifying-my-api-token') @@ -210,4 +248,32 @@ class ApplicationController < ActionController::Base self.render_error status: 401 end end + + def check_user_agreements + if current_user && !current_user.is_active && current_user.is_invited + signatures = UserAgreement.signatures + @signed_ua_uuids = UserAgreement.signatures.map &:head_uuid + @required_user_agreements = UserAgreement.all.map do |ua| + if not @signed_ua_uuids.index ua.uuid + Collection.find(ua.uuid) + end + end.compact + if @required_user_agreements.empty? + # No agreements to sign. Perhaps we just need to ask? + current_user.activate + if !current_user.is_active + logger.warn "#{current_user.uuid.inspect}: " + + "No user agreements to sign, but activate failed!" + end + end + if !current_user.is_active + render 'user_agreements/index' + end + end + true + end + + def select_theme + return Rails.configuration.arvados_theme + end end