AdminsController.approve()   A
last analyzed

Complexity

Conditions 1

Size

Total Lines 7

Duplication

Lines 0
Ratio 0 %

Importance

Changes 0
Metric Value
cc 1
dl 0
loc 7
rs 10
c 0
b 0
f 0
1
# frozen_string_literal: true
2
3
# BigBlueButton open source conferencing system - http://www.bigbluebutton.org/.
4
#
5
# Copyright (c) 2018 BigBlueButton Inc. and by respective authors (see below).
6
#
7
# This program is free software; you can redistribute it and/or modify it under the
8
# terms of the GNU Lesser General Public License as published by the Free Software
9
# Foundation; either version 3.0 of the License, or (at your option) any later
10
# version.
11
#
12
# BigBlueButton is distributed in the hope that it will be useful, but WITHOUT ANY
13
# WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A
14
# PARTICULAR PURPOSE. See the GNU Lesser General Public License for more details.
15
#
16
# You should have received a copy of the GNU Lesser General Public License along
17
# with BigBlueButton; if not, see <http://www.gnu.org/licenses/>.
18
19
class AdminsController < ApplicationController
20
  include Pagy::Backend
21
  include Themer
22
  include Emailer
23
  include Recorder
24
  include Rolify
25
26
  manage_users = [:edit_user, :promote, :demote, :ban_user, :unban_user, :approve, :reset]
27
  manage_deleted_users = [:undelete]
28
  authorize_resource class: false
29
  before_action :find_user, only: manage_users
30
  before_action :find_deleted_user, only: manage_deleted_users
31
  before_action :verify_admin_of_user, only: [manage_users, manage_deleted_users]
32
33
  # GET /admins
34
  def index
35
    # Initializa the data manipulation variables
36
    @search = params[:search] || ""
37
    @order_column = params[:column] && params[:direction] != "none" ? params[:column] : "created_at"
38
    @order_direction = params[:direction] && params[:direction] != "none" ? params[:direction] : "DESC"
39
40
    @role = params[:role] ? Role.find_by(name: params[:role], provider: @user_domain) : nil
41
    @tab = params[:tab] || "active"
42
43
    @pagy, @users = pagy(user_list)
44
  end
45
46
  # GET /admins/site_settings
47
  def site_settings
48
  end
49
50
  # GET /admins/server_recordings
51
  def server_recordings
52
    server_rooms = if Rails.configuration.loadbalanced_configuration
53
      Room.includes(:owner).where(users: { provider: @user_domain }).pluck(:bbb_id)
54
    else
55
      Room.pluck(:bbb_id)
56
    end
57
58
    @search, @order_column, @order_direction, recs =
59
      all_recordings(server_rooms, params.permit(:search, :column, :direction), true, true)
60
61
    @pagy, @recordings = pagy_array(recs)
62
  end
63
64
  # MANAGE USERS
65
66
  # GET /admins/edit/:user_uid
67
  def edit_user
68
  end
69
70
  # POST /admins/ban/:user_uid
71
  def ban_user
72
    @user.roles = []
73
    @user.add_role :denied
74
    redirect_to admins_path, flash: { success: I18n.t("administrator.flash.banned") }
75
  end
76
77
  # POST /admins/unban/:user_uid
78
  def unban_user
79
    @user.remove_role :denied
80
    @user.add_role :user
81
    redirect_to admins_path, flash: { success: I18n.t("administrator.flash.unbanned") }
82
  end
83
84
  # POST /admins/approve/:user_uid
85
  def approve
86
    @user.remove_role :pending
87
88
    send_user_approved_email(@user)
89
90
    redirect_to admins_path, flash: { success: I18n.t("administrator.flash.approved") }
91
  end
92
93
  # POST /admins/approve/:user_uid
94
  def undelete
95
    # Undelete the user and all of his rooms
96
    @user.undelete!
97
    @user.rooms.deleted.each(&:undelete!)
98
99
    redirect_to admins_path, flash: { success: I18n.t("administrator.flash.restored") }
100
  end
101
102
  # POST /admins/invite
103
  def invite
104
    emails = params[:invite_user][:email].split(",")
105
106
    emails.each do |email|
107
      invitation = create_or_update_invite(email)
108
109
      send_invitation_email(current_user.name, email, invitation.invite_token)
110
    end
111
112
    redirect_to admins_path
113
  end
114
115
  # GET /admins/reset
116
  def reset
117
    @user.create_reset_digest
118
119
    send_password_reset_email(@user)
120
121
    redirect_to admins_path, flash: { success: I18n.t("administrator.flash.reset_password") }
122
  end
123
  # SITE SETTINGS
124
125
  # POST /admins/update_settings
126
  def update_settings
127
    @settings.update_value(params[:setting], params[:value])
128
129
    flash_message = I18n.t("administrator.flash.settings")
130
131
    if params[:value] == "Default Recording Visibility"
132
      flash_message += ". " + I18n.t("administrator.site_settings.recording_visibility.warning")
133
    end
134
135
    redirect_to admin_site_settings_path, flash: { success: flash_message }
136
  end
137
138
  # POST /admins/color
139
  def coloring
140
    @settings.update_value("Primary Color", params[:value])
141
    @settings.update_value("Primary Color Lighten", color_lighten(params[:value]))
142
    @settings.update_value("Primary Color Darken", color_darken(params[:value]))
143
    redirect_to admin_site_settings_path, flash: { success: I18n.t("administrator.flash.settings") }
144
  end
145
146
  # POST /admins/registration_method/:method
147
  def registration_method
148
    new_method = Rails.configuration.registration_methods[params[:value].to_sym]
149
150
    # Only allow change to Join by Invitation if user has emails enabled
151
    if !Rails.configuration.enable_email_verification && new_method == Rails.configuration.registration_methods[:invite]
152
      redirect_to admin_site_settings_path,
153
        flash: { alert: I18n.t("administrator.flash.invite_email_verification") }
154
    else
155
      @settings.update_value("Registration Method", new_method)
156
      redirect_to admin_site_settings_path,
157
        flash: { success: I18n.t("administrator.flash.registration_method_updated") }
158
    end
159
  end
160
161
  # POST /admins/clear_cache
162
  def clear_cache
163
    Rails.cache.delete("#{@user_domain}/getUser")
164
    Rails.cache.delete("#{@user_domain}/getUserGreenlightCredentials")
165
166
    redirect_to admin_site_settings_path, flash: { success: I18n.t("administrator.flash.settings") }
167
  end
168
169
  # ROLES
170
171
  # GET /admins/roles
172
  def roles
173
    @roles = all_roles(params[:selected_role])
174
  end
175
176
  # POST /admins/role
177
  # This method creates a new role scoped to the users provider
178
  def new_role
179
    new_role = create_role(params[:role][:name])
180
181
    return redirect_to admin_roles_path, flash: { alert: I18n.t("administrator.roles.invalid_create") } if new_role.nil?
182
183
    redirect_to admin_roles_path(selected_role: new_role.id)
184
  end
185
186
  # PATCH /admin/roles/order
187
  # This updates the priority of a site's roles
188
  # Note: A lower priority role will always get used before a higher priority one
189
  def change_role_order
190
    unless update_priority(params[:role])
191
      redirect_to admin_roles_path, flash: { alert: I18n.t("administrator.roles.invalid_order") }
192
    end
193
  end
194
195
  # POST /admin/role/:role_id
196
  # This method updates the permissions assigned to a role
197
  def update_role
198
    role = Role.find(params[:role_id])
199
    flash[:alert] = I18n.t("administrator.roles.invalid_update") unless update_permissions(role)
200
    redirect_to admin_roles_path(selected_role: role.id)
201
  end
202
203
  # DELETE admins/role/:role_id
204
  # This deletes a role
205
  def delete_role
206
    role = Role.find(params[:role_id])
207
208
    # Make sure no users are assigned to the role and the role isn't a reserved role
209
    # before deleting
210
    if role.users.count.positive?
211
      flash[:alert] = I18n.t("administrator.roles.role_has_users", user_count: role.users.count)
212
      return redirect_to admin_roles_path(selected_role: role.id)
213
    elsif Role::RESERVED_ROLE_NAMES.include?(role) || role.provider != @user_domain ||
214
          role.priority <= current_user.highest_priority_role.priority
215
      return redirect_to admin_roles_path(selected_role: role.id)
216
    else
217
      role.role_permissions.delete_all
218
      role.delete
219
    end
220
221
    redirect_to admin_roles_path
222
  end
223
224
  private
225
226
  def find_user
227
    @user = User.where(uid: params[:user_uid]).includes(:roles).first
228
  end
229
230
  def find_deleted_user
231
    @user = User.deleted.where(uid: params[:user_uid]).includes(:roles).first
232
  end
233
234
  # Verifies that admin is an administrator of the user in the action
235
  def verify_admin_of_user
236
    redirect_to admins_path,
237
      flash: { alert: I18n.t("administrator.flash.unauthorized") } unless current_user.admin_of?(@user)
238
  end
239
240
  # Gets the list of users based on your configuration
241
  def user_list
242
    current_role = @role
243
244
    initial_user = case @tab
245
      when "active"
246
        User.without_role(:pending).without_role(:denied)
247
      when "deleted"
248
        User.deleted
249
      else
250
        User
251
    end
252
253
    current_role = Role.find_by(name: @tab, provider: @user_domain) if @tab == "pending" || @tab == "denied"
254
255
    initial_list = if current_user.has_role? :super_admin
256
      initial_user.where.not(id: current_user.id)
257
    else
258
      initial_user.without_role(:super_admin).where.not(id: current_user.id)
259
    end
260
261
    if Rails.configuration.loadbalanced_configuration
262
      initial_list.where(provider: @user_domain)
263
                  .admins_search(@search, current_role)
264
                  .admins_order(@order_column, @order_direction)
265
    else
266
      initial_list.admins_search(@search, current_role)
267
                  .admins_order(@order_column, @order_direction)
268
    end
269
  end
270
271
  # Creates the invite if it doesn't exist, or updates the updated_at time if it does
272
  def create_or_update_invite(email)
273
    invite = Invitation.find_by(email: email, provider: @user_domain)
274
275
    # Invite already exists
276
    if invite.present?
277
      # Updates updated_at to now
278
      invite.touch
279
    else
280
      # Creates invite
281
      invite = Invitation.create(email: email, provider: @user_domain)
282
    end
283
284
    invite
285
  end
286
end
287