summaryrefslogtreecommitdiff
path: root/app/controllers/reports_controller.rb
blob: a28e61fb546c17e4a33322b92f1cfb4121b7ff59 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
# frozen_string_literal: true

class ReportsController < ApplicationController
  before_action :filter_banned_users, except: [:index]
  before_action :setup_report, only: [:new, :create]

  def index
    @reports = current_user.reports_made.order(created_at: :desc).page(params[:page]).per(20) if current_user
    @title = 'Your Reports'
    authorize! :create, Report
  end

  def new
    authorize! :create, @report
    @title = 'Create Report'
  end

  def create
    reason = params[:category].to_s
    reason += ': ' + params[:report][:reason] if params[:report][:reason].present?
    @report.reason = reason
    authorize! :create, @report

    unless captcha_verified?
      respond_to do |format|
        format.html { flash[:notice] = "Your report hasn't been accepted, please fill in the captcha"; render action: 'new' }
        format.js { render plain: 'Report not received, please fill in the captcha', layout: false }
      end

      return
    end

    # Anti report spam
    if Flipflop.enabled?(:report_limit) && (current_user && current_user.reports_made.where(state: %w[open in_progress]).count >= 5) ||
       Report.where(ip: request.remote_ip, state: %w[open in_progress]).count >= 5
      redirect_back fallback_location: reports_path, notice: 'Due to heavy report spam, you may not have more than 5 open reports at a time. Did you read the reporting tips?'
      return
    end

    # If we're allowed to...
    if @report.save
      @report.update_index
      # NewReportLogger.log(@report)
      respond_to do |format|
        format.html { flash[:notice] = 'Your report has been received and will be checked by an administrator shortly.'; redirect_to reports_path }
        format.js { render plain: 'Report received', layout: false }
      end
    else
      respond_to do |format|
        format.html { flash[:notice] = "Your report hasn't been received."; render action: 'new' }
        format.js { render plain: "Report not receieved. #{@report.errors.to_a.join(' ')}", layout: false }
      end
    end
  end

  private

  def setup_report
    if (@reportable = find_reportable)
      @report = @reportable.reports.new(request_attributes)
    else
      respond_to do |format|
        format.html { flash[:notice] = 'Your report has no associated reportable entity and cannot be received.'; redirect_to reports_path }
        format.js { render plain: 'Report received', layout: false }
      end
    end
  end

  def find_reportable
    reportable_class = params[:reportable_class].capitalize.safe_constantize
    return false unless reportable_class < Reportable

    query = { id: params[:reportable_id] }
    query['hidden_from_users'] = false if reportable_class.column_names.include? 'hidden_from_users'
    @reportable = reportable_class.find_by(query)
  end
end