When customizing CONSUL, one of the most common actions is adding a new
field to a form.
This requires modifying the permitted/allowed parameters. However, in
most cases, the method returning these parameters returned an instance
of `ActionController::Parameters`, so adding more parameters to it
wasn't easy.
So customizing the code required copying the method returning those
parameters and adding the new ones. For example:
```
def something_params
params.require(:something).permit(
:one_consul_attribute,
:another_consul_attribute,
:my_custom_attribute
)
end
```
This meant that, if the `something_params` method changed in CONSUL, the
customization of this method had to be updated as well.
So we're extracting the logic returning the parameters to a method which
returns an array. Now this code can be customized without copying the
original method:
```
alias_method :consul_allowed_params, :allowed_params
def allowed_params
consul_allowed_params + [:my_custom_attribute]
end
```
41 lines
1.3 KiB
Ruby
41 lines
1.3 KiB
Ruby
class DirectUploadsController < ApplicationController
|
|
include DirectUploadsHelper
|
|
include ActionView::Helpers::UrlHelper
|
|
before_action :authenticate_user!
|
|
|
|
skip_authorization_check only: :create
|
|
|
|
helper_method :render_destroy_upload_link
|
|
|
|
def create
|
|
@direct_upload = DirectUpload.new(direct_upload_params.merge(user: current_user, attachment: params[:attachment]))
|
|
|
|
if @direct_upload.valid?
|
|
@direct_upload.save_attachment
|
|
@direct_upload.relation.set_cached_attachment_from_attachment
|
|
|
|
render json: { cached_attachment: @direct_upload.relation.cached_attachment,
|
|
filename: @direct_upload.relation.attachment_file_name,
|
|
destroy_link: render_destroy_upload_link(@direct_upload),
|
|
attachment_url: polymorphic_path(@direct_upload.relation.attachment) }
|
|
else
|
|
render json: { errors: @direct_upload.errors[:attachment].join(", ") },
|
|
status: :unprocessable_entity
|
|
end
|
|
end
|
|
|
|
private
|
|
|
|
def direct_upload_params
|
|
params.require(:direct_upload)
|
|
.permit(allowed_params)
|
|
end
|
|
|
|
def allowed_params
|
|
[
|
|
:resource, :resource_type, :resource_id, :resource_relation,
|
|
:attachment, :cached_attachment, attachment_attributes: []
|
|
]
|
|
end
|
|
end
|