]> git.openstreetmap.org Git - rails.git/blobdiff - app/controllers/oauth_clients_controller.rb
Only the sender of a message should be able to mark it as read/unread
[rails.git] / app / controllers / oauth_clients_controller.rb
index 56f19dbda17845feca7af722d45244b72806aeb0..42b0921f1f62eedfa6c162cc6b0de5ea613e13fd 100644 (file)
@@ -1,54 +1,75 @@
 class OauthClientsController < ApplicationController
 class OauthClientsController < ApplicationController
-  layout 'site'
+  layout "site"
 
 
-  before_filter :authorize_web
-  before_filter :set_locale
-  before_filter :require_user
+  before_action :authorize_web
+  before_action :set_locale
+
+  authorize_resource :class => ClientApplication
 
   def index
 
   def index
-    @client_applications = @user.client_applications
-    @tokens = @user.oauth_tokens.authorized
+    @client_applications = current_user.client_applications
+    @tokens = current_user.oauth_tokens.authorized
   end
 
   end
 
-  def new
-    @client_application = ClientApplication.new
+  def show
+    @client_application = current_user.client_applications.find(params[:id])
+  rescue ActiveRecord::RecordNotFound
+    @type = "client application"
+    render :action => "not_found", :status => :not_found
   end
 
   end
 
-  def create
-    @client_application = @user.client_applications.build(params[:client_application])
-    if @client_application.save
-      flash[:notice] = t'oauth_clients.create.flash'
-      redirect_to :action => "show", :id => @client_application.id
+  def new
+    if Settings.oauth_10_registration
+      @client_application = ClientApplication.new
     else
     else
-      render :action => "new"
+      flash[:error] = t ".disabled"
+      redirect_to :action => "index"
     end
   end
 
     end
   end
 
-  def show
-    @client_application = @user.client_applications.find(params[:id])
+  def edit
+    @client_application = current_user.client_applications.find(params[:id])
   rescue ActiveRecord::RecordNotFound
     @type = "client application"
     render :action => "not_found", :status => :not_found
   end
 
   rescue ActiveRecord::RecordNotFound
     @type = "client application"
     render :action => "not_found", :status => :not_found
   end
 
-  def edit
-    @client_application = @user.client_applications.find(params[:id])
+  def create
+    @client_application = current_user.client_applications.build(application_params)
+    if @client_application.save
+      flash[:notice] = t ".flash"
+      redirect_to :action => "show", :id => @client_application.id
+    else
+      render :action => "new"
+    end
   end
 
   def update
   end
 
   def update
-    @client_application = @user.client_applications.find(params[:id])
-    if @client_application.update_attributes(params[:client_application])
-      flash[:notice] = t'oauth_clients.update.flash'
+    @client_application = current_user.client_applications.find(params[:id])
+    if @client_application.update(application_params)
+      flash[:notice] = t ".flash"
       redirect_to :action => "show", :id => @client_application.id
     else
       render :action => "edit"
     end
       redirect_to :action => "show", :id => @client_application.id
     else
       render :action => "edit"
     end
+  rescue ActiveRecord::RecordNotFound
+    @type = "client application"
+    render :action => "not_found", :status => :not_found
   end
 
   def destroy
   end
 
   def destroy
-    @client_application = @user.client_applications.find(params[:id])
+    @client_application = current_user.client_applications.find(params[:id])
     @client_application.destroy
     @client_application.destroy
-    flash[:notice] = t'oauth_clients.destroy.flash'
+    flash[:notice] = t ".flash"
     redirect_to :action => "index"
     redirect_to :action => "index"
+  rescue ActiveRecord::RecordNotFound
+    @type = "client application"
+    render :action => "not_found", :status => :not_found
+  end
+
+  private
+
+  def application_params
+    params.require(:client_application).permit(:name, :url, :callback_url, :support_url, ClientApplication.all_permissions)
   end
 end
   end
 end