demarches-normaliennes/app/controllers/users/profil_controller.rb

91 lines
2.6 KiB
Ruby
Raw Normal View History

2019-07-02 18:15:03 +02:00
module Users
class ProfilController < UserController
before_action :ensure_update_email_is_authorized, only: :update_email
2018-08-23 18:53:35 +02:00
def show
2021-10-26 13:22:51 +02:00
@waiting_merge_emails = waiting_merge_emails
@waiting_transfers = current_user.dossiers.joins(:transfer).group('dossier_transfers.email').count.to_a
2018-08-23 18:53:35 +02:00
end
def renew_api_token
@token = current_administrateur.renew_api_token
2018-08-24 14:19:44 +02:00
flash.now.notice = 'Votre jeton a été regénéré.'
render :show
2018-08-23 18:53:35 +02:00
end
def update_email
2021-10-26 13:36:14 +02:00
requested_user = User.find_by(email: requested_email)
if requested_user.present?
current_user.ask_for_merge(requested_user)
2021-10-26 16:18:12 +02:00
current_user.update(unconfirmed_email: nil)
flash.notice = t('devise.registrations.update_needs_confirmation')
2021-10-26 13:36:14 +02:00
elsif current_user.update(update_email_params)
2021-10-26 16:18:12 +02:00
current_user.update(requested_merge_into: nil)
flash.notice = t('devise.registrations.update_needs_confirmation')
else
2019-12-09 16:50:30 +01:00
flash.alert = current_user.errors.full_messages
end
redirect_to profil_path
end
2021-09-20 13:14:03 +02:00
def transfer_all_dossiers
DossierTransfer.initiate(next_owner_email, current_user.dossiers)
flash.notice = t('.new_transfer', count: current_user.dossiers.count, email: next_owner_email)
redirect_to profil_path
end
2021-10-26 13:22:51 +02:00
def accept_merge
users_requesting_merge.each { |user| current_user.merge(user) }
users_requesting_merge.update_all(requested_merge_into_id: nil)
flash.notice = "Vous avez absorbé le compte #{waiting_merge_emails.join(', ')}"
redirect_to profil_path
end
def refuse_merge
users = users_requesting_merge
users.update_all(requested_merge_into_id: nil)
flash.notice = 'La fusion a été refusé'
redirect_to profil_path
end
private
2021-10-26 13:22:51 +02:00
def waiting_merge_emails
users_requesting_merge.pluck(:email)
end
def users_requesting_merge
2021-11-04 15:51:54 +01:00
@requesting_merge ||= current_user.requested_merge_from
2021-10-26 13:22:51 +02:00
end
def ensure_update_email_is_authorized
if current_user.instructeur? && !target_email_allowed?
flash.alert = t('users.profil.ensure_update_email_is_authorized.email_not_allowed', contact_email: CONTACT_EMAIL, requested_email: requested_email)
redirect_to profil_path
end
end
def update_email_params
params.require(:user).permit(:email)
end
def requested_email
update_email_params[:email]
end
def target_email_allowed?
LEGIT_ADMIN_DOMAINS.any? { |d| requested_email.end_with?(d) }
end
2021-09-20 13:14:03 +02:00
def next_owner_email
params[:next_owner]
end
2018-08-23 18:53:35 +02:00
end
end