debian-mirror-gitlab/app/controllers/uploads_controller.rb

73 lines
1.5 KiB
Ruby
Raw Normal View History

2015-04-26 12:48:37 +05:30
class UploadsController < ApplicationController
2015-09-11 14:41:01 +05:30
skip_before_action :authenticate_user!
before_action :find_model, :authorize_access!
2015-04-26 12:48:37 +05:30
def show
uploader = @model.send(upload_mount)
unless uploader.file_storage?
return redirect_to uploader.url
end
unless uploader.file && uploader.file.exists?
2015-10-24 18:46:33 +05:30
return render_404
2015-04-26 12:48:37 +05:30
end
disposition = uploader.image? ? 'inline' : 'attachment'
send_file uploader.file.path, disposition: disposition
end
private
def find_model
unless upload_model && upload_mount
2015-10-24 18:46:33 +05:30
return render_404
2015-04-26 12:48:37 +05:30
end
@model = upload_model.find(params[:id])
end
def authorize_access!
2015-09-11 14:41:01 +05:30
authorized =
2015-04-26 12:48:37 +05:30
case @model
when Project
can?(current_user, :read_project, @model)
when Group
can?(current_user, :read_group, @model)
when Note
can?(current_user, :read_project, @model.project)
else
# No authentication required for user avatars.
true
end
return if authorized
if current_user
2015-10-24 18:46:33 +05:30
render_404
2015-04-26 12:48:37 +05:30
else
authenticate_user!
end
end
def upload_model
upload_models = {
2015-09-11 14:41:01 +05:30
"user" => User,
"project" => Project,
"note" => Note,
2016-04-02 18:10:28 +05:30
"group" => Group,
"appearance" => Appearance
2015-04-26 12:48:37 +05:30
}
2015-09-11 14:41:01 +05:30
upload_models[params[:model]]
2015-04-26 12:48:37 +05:30
end
def upload_mount
2016-04-02 18:10:28 +05:30
upload_mounts = %w(avatar attachment file logo header_logo)
2015-04-26 12:48:37 +05:30
if upload_mounts.include?(params[:mounted_as])
params[:mounted_as]
end
end
end