Files
docuseal/app/controllers/users_controller.rb
T

128 lines
4.0 KiB
Ruby
Raw Normal View History

2023-05-21 17:59:36 +03:00
# frozen_string_literal: true
class UsersController < ApplicationController
2025-09-06 09:52:35 +03:00
load_and_authorize_resource :user, only: %i[index edit update destroy]
2023-09-17 00:45:57 +03:00
2024-04-28 10:27:44 +03:00
before_action :build_user, only: %i[new create]
authorize_resource :user, only: %i[new create]
2023-05-21 17:59:36 +03:00
def index
2024-04-19 16:08:12 +03:00
@users =
if params[:status] == 'archived'
2024-10-24 20:09:57 +03:00
@users.archived.where.not(role: 'integration')
elsif params[:status] == 'integration'
@users.active.where(role: 'integration')
2024-04-19 16:08:12 +03:00
else
2024-10-24 20:09:57 +03:00
@users.active.where.not(role: 'integration')
2024-04-19 16:08:12 +03:00
end
2026-04-08 11:23:59 +03:00
@users = @users.preload(account: :account_accesses).where(account: current_account).order(id: :desc)
respond_to do |format|
format.html do
@pagy, @users = pagy(@users)
end
if current_ability.can?(:manage, current_account)
format.csv do
send_data Users.generate_csv(@users), filename: "users-#{Time.current.iso8601}.csv", type: 'text/csv'
end
end
end
2023-05-21 17:59:36 +03:00
end
2023-09-17 00:45:57 +03:00
def new; end
2023-05-21 17:59:36 +03:00
def edit; end
def create
2025-11-12 20:19:57 +02:00
existing_user = User.accessible_by(current_ability).find_by(email: @user.email)
2024-04-19 16:08:12 +03:00
2025-11-12 20:19:57 +02:00
if existing_user
2025-11-17 10:21:38 +02:00
if existing_user.archived_at? &&
current_ability.can?(:manage, existing_user) && current_ability.can?(:manage, @user.account)
2025-11-12 20:19:57 +02:00
existing_user.assign_attributes(@user.slice(:first_name, :last_name, :role, :account_id))
existing_user.archived_at = nil
@user = existing_user
else
@user.errors.add(:email, I18n.t('already_exists'))
return render turbo_stream: turbo_stream.replace(:modal, template: 'users/new'), status: :unprocessable_content
end
2024-04-19 16:08:12 +03:00
end
2025-09-06 11:10:45 +03:00
@user.password = SecureRandom.hex if @user.password.blank?
2024-12-08 15:10:38 +02:00
@user.role = User::ADMIN_ROLE unless role_valid?(@user.role)
2023-05-21 17:59:36 +03:00
if @user.save
UserMailer.invitation_email(@user).deliver_later!
2024-09-18 19:47:47 +03:00
redirect_back fallback_location: settings_users_path, notice: I18n.t('user_has_been_invited')
2023-05-21 17:59:36 +03:00
else
2025-08-14 09:25:35 +03:00
render turbo_stream: turbo_stream.replace(:modal, template: 'users/new'), status: :unprocessable_content
2023-05-21 17:59:36 +03:00
end
end
def update
2024-09-18 19:47:47 +03:00
return redirect_to settings_users_path, notice: I18n.t('unable_to_update_user') if Docuseal.demo?
2023-07-09 16:27:31 +03:00
2025-12-07 14:57:21 +02:00
attrs = user_params.compact_blank
attrs = attrs.merge(user_params.slice(:archived_at)) if current_ability.can?(:create, @user)
2023-10-07 15:03:53 +03:00
2024-06-14 22:59:11 +03:00
if params.dig(:user, :account_id).present?
2025-02-26 21:45:22 +02:00
account = Account.accessible_by(current_ability).find(params.dig(:user, :account_id))
2024-06-14 22:59:11 +03:00
authorize!(:manage, account)
@user.account = account
2026-08-09 18:37:53 +03:00
authorize!(:create, @user)
2024-06-14 22:59:11 +03:00
end
2025-09-06 10:41:51 +03:00
if @user.update(attrs.except(*(current_user == @user ? %i[password otp_required_for_login role] : %i[password])))
2025-11-26 14:12:08 +02:00
if @user.try(:pending_reconfirmation?) && @user.previous_changes.key?(:unconfirmed_email)
2025-11-30 16:00:13 +02:00
SendConfirmationInstructionsJob.perform_async('user_id' => @user.id)
2025-11-26 14:12:08 +02:00
redirect_back fallback_location: settings_users_path,
notice: I18n.t('a_confirmation_email_has_been_sent_to_the_new_email_address')
else
redirect_back fallback_location: settings_users_path, notice: I18n.t('user_has_been_updated')
end
2023-05-21 17:59:36 +03:00
else
2025-08-14 09:25:35 +03:00
render turbo_stream: turbo_stream.replace(:modal, template: 'users/edit'), status: :unprocessable_content
2023-05-21 17:59:36 +03:00
end
end
def destroy
2023-07-09 16:27:31 +03:00
if Docuseal.demo? || @user.id == current_user.id
2024-09-18 19:47:47 +03:00
return redirect_to settings_users_path, notice: I18n.t('unable_to_remove_user')
2023-07-09 16:27:31 +03:00
end
2023-12-30 00:37:03 +02:00
@user.update!(archived_at: Time.current)
2023-05-21 17:59:36 +03:00
2024-09-18 19:47:47 +03:00
redirect_back fallback_location: settings_users_path, notice: I18n.t('user_has_been_removed')
2023-05-21 17:59:36 +03:00
end
private
2023-12-30 22:51:26 +02:00
def role_valid?(role)
User::ROLES.include?(role)
end
2023-09-17 00:45:57 +03:00
def build_user
2024-12-10 23:18:07 +02:00
@user = current_account.users.new(user_params)
2023-05-21 17:59:36 +03:00
end
def user_params
2024-04-28 10:27:44 +03:00
if params.key?(:user)
2025-09-04 21:19:43 +03:00
permitted_params = %i[email first_name last_name password archived_at otp_required_for_login]
2025-02-26 21:45:22 +02:00
permitted_params << :role if role_valid?(params.dig(:user, :role))
params.require(:user).permit(permitted_params)
2024-04-28 10:27:44 +03:00
else
{}
end
2023-05-21 17:59:36 +03:00
end
end