]> git.openstreetmap.org Git - rails.git/blob - app/controllers/friendships_controller.rb
Lookup friend user before make/remove friend action
[rails.git] / app / controllers / friendships_controller.rb
1 class FriendshipsController < ApplicationController
2   layout "site"
3
4   before_action :authorize_web
5   before_action :set_locale
6   before_action :check_database_readable
7
8   authorize_resource
9
10   before_action :check_database_writable, :only => [:make_friend, :remove_friend]
11   before_action :lookup_friend, :only => [:make_friend, :remove_friend]
12
13   def make_friend
14     if request.post?
15       friendship = Friendship.new
16       friendship.befriender = current_user
17       friendship.befriendee = @friend
18       if current_user.friends_with?(@friend)
19         flash[:warning] = t ".already_a_friend", :name => @friend.display_name
20       elsif current_user.friendships.where("created_at >= ?", Time.now.utc - 1.hour).count >= current_user.max_friends_per_hour
21         flash.now[:error] = t ".limit_exceeded"
22       elsif friendship.save
23         flash[:notice] = t ".success", :name => @friend.display_name
24         UserMailer.friendship_notification(friendship).deliver_later
25       else
26         friendship.add_error(t(".failed", :name => @friend.display_name))
27       end
28
29       referer = safe_referer(params[:referer]) if params[:referer]
30
31       redirect_to referer || user_path
32     end
33   end
34
35   def remove_friend
36     if request.post?
37       if current_user.friends_with?(@friend)
38         Friendship.where(:befriender => current_user, :befriendee => @friend).delete_all
39         flash[:notice] = t ".success", :name => @friend.display_name
40       else
41         flash[:error] = t ".not_a_friend", :name => @friend.display_name
42       end
43
44       referer = safe_referer(params[:referer]) if params[:referer]
45
46       redirect_to referer || user_path
47     end
48   end
49
50   private
51
52   ##
53   # ensure that there is a "friend" instance variable
54   def lookup_friend
55     @friend = User.active.find_by!(:display_name => params[:display_name])
56   rescue ActiveRecord::RecordNotFound
57     render_unknown_user params[:display_name]
58   end
59 end