Files
nairobi/app/controllers/verification/letter_controller.rb
Javi Martín 7ca55c44e0 Apply Rails/SaveBang rubocop rule
Having exceptions is better than having silent bugs.

There are a few methods I've kept the same way they were.

The `RelatedContentScore#score_with_opposite` method is a bit peculiar:
it creates scores for both itself and the opposite related content,
which means the opposite related content will try to create the same
scores as well.

We've already got a test to check `Budget::Ballot#add_investment` when
creating a line fails ("Edge case voting a non-elegible investment").

Finally, the method `User#send_oauth_confirmation_instructions` doesn't
update the record when the email address isn't already present, leading
to the test "Try to register with the email of an already existing user,
when an unconfirmed email was provided by oauth" fo fail if we raise an
exception for an invalid user. That's because updating a user's email
doesn't update the database automatically, but instead a confirmation
email is sent.

There are also a few false positives for classes which don't have bang
methods (like the GraphQL classes) or destroying attachments.

For these reasons, I'm adding the rule with a "Refactor" severity,
meaning it's a rule we can break if necessary.
2019-10-23 14:39:31 +02:00

60 lines
1.5 KiB
Ruby

class Verification::LetterController < ApplicationController
before_action :authenticate_user!, except: [:edit, :update]
before_action :login_via_form, only: :update
before_action :verify_resident!, if: :signed_in?
before_action :verify_phone!, if: :signed_in?
before_action :verify_verified!, if: :signed_in?
before_action :verify_lock, if: :signed_in?
skip_authorization_check
def new
@letter = Verification::Letter.new(user: current_user)
end
def create
@letter = Verification::Letter.new(user: current_user)
@letter.save!
redirect_to letter_path
end
def show
end
def edit
@letter = Verification::Letter.new
end
def update
@letter = Verification::Letter.new(letter_params.merge(user: current_user, verify: true))
if @letter.valid?
current_user.update!(verified_at: Time.current)
redirect_to account_path, notice: t("verification.letter.update.flash.success")
else
Lock.increase_tries(@letter.user) if @letter.user
render :edit
end
end
private
def letter_params
params.require(:verification_letter).permit(:verification_code, :email, :password)
end
def verify_phone!
unless current_user.sms_verified?
redirect_to verified_user_path, alert: t("verification.letter.alert.unconfirmed_code")
end
end
def login_via_form
user = User.find_by email: letter_params[:email]
if user&.valid_password?(letter_params[:password])
sign_in(user)
end
end
end