mirror of
https://github.com/Growstuff/growstuff.git
synced 2026-10-01 10:24:30 -04:00
- Configure Allow2Ban in Rack::Attack to ban IPs requesting >500 pages per day for 1 week (7 days). - Add honeypot route /dont-crawl-me disallowed in robots.txt and configure Fail2Ban in Rack::Attack to ban IPs visiting it for 7 days upon 1 hit. - Update PhotosController#index to raise ActiveRecord::RecordNotFound when page parameter is out of bounds, returning 404 Not Found to crawlers instead of 200 OK. - Add request and controller specs for Rack::Attack rules and pagination 404 responses. Co-authored-by: CloCkWeRX <365751+CloCkWeRX@users.noreply.github.com>
130 lines
3.3 KiB
Ruby
130 lines
3.3 KiB
Ruby
# frozen_string_literal: true
|
|
|
|
class PhotosController < ApplicationController
|
|
before_action :authenticate_member!, except: %i(index show)
|
|
before_action :set_crop_and_planting, only: :index
|
|
after_action :expire_homepage, only: %i(create destroy)
|
|
load_and_authorize_resource
|
|
respond_to :html, :json
|
|
responders :flash
|
|
|
|
def index
|
|
@photos = if @crop
|
|
@crop.photos
|
|
elsif @planting
|
|
@planting.photos
|
|
else
|
|
Photo.all
|
|
end
|
|
|
|
@photos = @photos.includes(:owner)
|
|
.order(created_at: :desc)
|
|
.paginate(page: params[:page], per_page: Photo.per_page)
|
|
|
|
raise ActiveRecord::RecordNotFound if @photos.out_of_bounds?
|
|
|
|
respond_with(@photos)
|
|
end
|
|
|
|
def show
|
|
@crops = Crop.distinct.joins(:photo_associations).where(photo_associations: { photo: @photo })
|
|
@comment = Comment.new(commentable: @photo)
|
|
respond_with(@photo)
|
|
end
|
|
|
|
def new
|
|
@photo = Photo.new
|
|
@item = item_to_link_to
|
|
@type = params[:type]
|
|
@id = params[:id]
|
|
retrieve_from_flickr
|
|
respond_with @photo
|
|
end
|
|
|
|
def edit
|
|
respond_with @photo
|
|
end
|
|
|
|
def create
|
|
ActiveRecord::Base.transaction do
|
|
@photo = find_or_create_photo_from_flickr_photo
|
|
@item = item_to_link_to
|
|
raise "Could not find this #{type} owned by you" unless @item
|
|
|
|
@item.photos << @photo unless @item.photos.include? @photo
|
|
@photo.save! if @photo.present?
|
|
end
|
|
respond_with @photo
|
|
end
|
|
|
|
def update
|
|
@photo.update(photo_params)
|
|
respond_with @photo
|
|
end
|
|
|
|
def destroy
|
|
@photo.destroy
|
|
respond_with @photo
|
|
end
|
|
|
|
private
|
|
|
|
def photo_params
|
|
params.require(:photo).permit(:source_id, :source, :title, :license_name,
|
|
:license_url, :thumbnail_url, :fullsize_url, :link_url, :date_taken)
|
|
end
|
|
|
|
# Item with photos attached
|
|
def item_to_link_to
|
|
raise "No item id provided" if params[:id].nil?
|
|
raise "No item type provided" if params[:type].nil?
|
|
|
|
item_class = params[:type].capitalize
|
|
raise "Photos not supported" unless Photo::PHOTO_CAPABLE.include? item_class
|
|
|
|
item_class.constantize.find(params[:id])
|
|
end
|
|
|
|
#
|
|
# Flickr retrieval
|
|
def find_or_create_photo_from_flickr_photo
|
|
photo = Photo.find_or_initialize_by(
|
|
source_id: photo_params[:source_id],
|
|
source: 'flickr'
|
|
)
|
|
photo.update(photo_params)
|
|
photo.owner_id = current_member.id
|
|
photo.set_flickr_metadata!
|
|
photo
|
|
end
|
|
|
|
def retrieve_from_flickr
|
|
@flickr_auth = current_member.auth('flickr')
|
|
return if @flickr_auth.nil?
|
|
|
|
unless current_member.flickr_auth_valid?
|
|
current_member.remove_stale_flickr_auth
|
|
@please_reconnect_flickr = true
|
|
return
|
|
end
|
|
|
|
@current_set = params[:set]
|
|
@current_tag = params[:tag]
|
|
|
|
page = params[:page] || 1
|
|
|
|
@sets = current_member.flickr_sets
|
|
photos, total = current_member.flickr_photos(page, @current_set, @current_tag)
|
|
|
|
@photos = WillPaginate::Collection.create(page, 30, total) do |pager|
|
|
pager.replace photos
|
|
end
|
|
end
|
|
|
|
def set_crop_and_planting
|
|
@crop = Crop.find params[:crop_slug] if params[:crop_slug]
|
|
@planting = Planting.find params[:planting_id] if params[:planting_id]
|
|
@planting ||= Planting.find params[:planting_slug] if params[:planting_slug]
|
|
end
|
|
end
|