2014-02-03 19:24:49 +00:00
|
|
|
# Copyright (C) 2012-2014 Zammad Foundation, http://zammad-foundation.org/
|
2013-06-12 15:59:58 +00:00
|
|
|
|
2012-04-10 14:06:46 +00:00
|
|
|
class SettingsController < ApplicationController
|
2016-08-12 16:39:09 +00:00
|
|
|
before_action { authentication_check(permission: 'admin.*') }
|
2012-04-10 14:06:46 +00:00
|
|
|
|
|
|
|
# GET /settings
|
|
|
|
def index
|
2016-08-26 10:06:27 +00:00
|
|
|
list = []
|
|
|
|
Setting.all.each { |setting|
|
|
|
|
next if setting.preferences[:permission] && !current_user.permissions?(setting.preferences[:permission])
|
|
|
|
list.push setting
|
|
|
|
}
|
|
|
|
render json: list, status: :ok
|
2012-04-10 14:06:46 +00:00
|
|
|
end
|
|
|
|
|
|
|
|
# GET /settings/1
|
|
|
|
def show
|
2016-08-26 10:06:27 +00:00
|
|
|
check_access('read')
|
2012-09-20 12:08:02 +00:00
|
|
|
model_show_render(Setting, params)
|
2012-04-10 14:06:46 +00:00
|
|
|
end
|
|
|
|
|
|
|
|
# POST /settings
|
|
|
|
def create
|
2016-08-26 10:06:27 +00:00
|
|
|
raise Exceptions::NotAuthorized, 'Not authorized (feature not possible)'
|
2012-04-10 14:06:46 +00:00
|
|
|
end
|
|
|
|
|
|
|
|
# PUT /settings/1
|
|
|
|
def update
|
2016-08-26 10:06:27 +00:00
|
|
|
check_access('write')
|
|
|
|
clean_params = keep_certain_attributes
|
|
|
|
model_update_render(Setting, clean_params)
|
2012-04-10 14:06:46 +00:00
|
|
|
end
|
|
|
|
|
2015-07-12 01:32:40 +00:00
|
|
|
# PUT /settings/image/:id
|
|
|
|
def update_image
|
2016-08-26 10:06:27 +00:00
|
|
|
check_access('write')
|
|
|
|
clean_params = keep_certain_attributes
|
2015-07-12 01:32:40 +00:00
|
|
|
|
2016-08-26 10:06:27 +00:00
|
|
|
if !clean_params[:logo]
|
2015-07-12 01:32:40 +00:00
|
|
|
render json: {
|
|
|
|
result: 'invalid',
|
|
|
|
message: 'Need logo param',
|
|
|
|
}
|
|
|
|
return
|
|
|
|
end
|
|
|
|
|
|
|
|
# validate image
|
2016-08-26 10:06:27 +00:00
|
|
|
if clean_params[:logo] !~ /^data:image/i
|
2015-07-12 01:32:40 +00:00
|
|
|
render json: {
|
|
|
|
result: 'invalid',
|
|
|
|
message: 'Invalid payload, need data:image in logo param',
|
|
|
|
}
|
|
|
|
return
|
|
|
|
end
|
|
|
|
|
|
|
|
# process image
|
2016-08-26 10:06:27 +00:00
|
|
|
file = StaticAssets.data_url_attributes(clean_params[:logo])
|
2015-07-12 01:32:40 +00:00
|
|
|
if !file[:content] || !file[:mime_type]
|
|
|
|
render json: {
|
|
|
|
result: 'invalid',
|
|
|
|
message: 'Unable to process image upload.',
|
|
|
|
}
|
|
|
|
return
|
|
|
|
end
|
|
|
|
|
|
|
|
# store image 1:1
|
|
|
|
StaticAssets.store_raw(file[:content], file[:mime_type])
|
|
|
|
|
|
|
|
# store resized image 1:1
|
2016-08-26 10:06:27 +00:00
|
|
|
setting = Setting.lookup(name: 'product_logo')
|
2015-07-12 01:32:40 +00:00
|
|
|
if params[:logo_resize] && params[:logo_resize] =~ /^data:image/i
|
|
|
|
|
|
|
|
# data:image/png;base64
|
2016-05-10 13:06:51 +00:00
|
|
|
file = StaticAssets.data_url_attributes(params[:logo_resize])
|
2015-07-12 01:32:40 +00:00
|
|
|
|
|
|
|
# store image 1:1
|
2016-05-25 07:19:45 +00:00
|
|
|
setting.state = StaticAssets.store(file[:content], file[:mime_type])
|
2016-08-26 10:06:27 +00:00
|
|
|
setting.save!
|
2015-07-12 01:32:40 +00:00
|
|
|
end
|
|
|
|
|
|
|
|
render json: {
|
|
|
|
result: 'ok',
|
|
|
|
settings: [setting],
|
|
|
|
}
|
|
|
|
end
|
|
|
|
|
2012-04-10 14:06:46 +00:00
|
|
|
# DELETE /settings/1
|
|
|
|
def destroy
|
2016-08-26 10:06:27 +00:00
|
|
|
raise Exceptions::NotAuthorized, 'Not authorized (feature not possible)'
|
2012-04-10 14:06:46 +00:00
|
|
|
end
|
2015-07-16 13:36:59 +00:00
|
|
|
|
|
|
|
private
|
|
|
|
|
2016-08-26 10:06:27 +00:00
|
|
|
def keep_certain_attributes
|
2015-07-16 13:36:59 +00:00
|
|
|
setting = Setting.find(params[:id])
|
2016-08-26 10:06:27 +00:00
|
|
|
[:name, :area, :state_initial, :frontend, :options].each { |key|
|
|
|
|
params.delete(key)
|
|
|
|
}
|
2016-08-26 15:08:49 +00:00
|
|
|
if !params[:preferences].empty?
|
|
|
|
[:online_service_disable, :permission, :render].each { |key|
|
|
|
|
params[:preferences].delete(key)
|
|
|
|
}
|
|
|
|
params[:preferences].merge!(setting.preferences)
|
|
|
|
end
|
2016-08-26 10:06:27 +00:00
|
|
|
params
|
|
|
|
end
|
|
|
|
|
|
|
|
def check_access(type)
|
|
|
|
setting = Setting.lookup(id: params[:id])
|
|
|
|
|
|
|
|
if setting.preferences[:permission] && !current_user.permissions?(setting.preferences[:permission])
|
|
|
|
raise Exceptions::NotAuthorized, "Not authorized (required #{setting.preferences[:permission].inspect})"
|
|
|
|
end
|
|
|
|
|
|
|
|
if type == 'write'
|
|
|
|
return true if !Setting.get('system_online_service')
|
|
|
|
if setting.preferences && setting.preferences[:online_service_disable]
|
|
|
|
raise Exceptions::NotAuthorized, 'Not authorized (service disabled)'
|
|
|
|
end
|
|
|
|
end
|
|
|
|
true
|
2015-07-16 13:36:59 +00:00
|
|
|
end
|
2012-04-10 14:06:46 +00:00
|
|
|
end
|