Files
openfoodnetwork/app/controllers/cart_controller.rb
Matt-Yorkley 9f49a84e7f Clarify use of access tokens used for viewing order details as a guest user
There are 4 or 5 different places in the app where we reference a :token and params[:token] for completely different purposes (they're not even vaguely the *same* token).

This is an attempt to clarify the places in the app where we use params[:token] in relation to *orders*, for allowing guest users (who are not logged in) to view details of an order they have placed (like after checkout completion), and differentiate it from the various other places where params[:token] can actually be used for something entirely different!
2021-12-16 13:35:55 +00:00

41 lines
1.1 KiB
Ruby

# frozen_string_literal: true
class CartController < BaseController
before_action :check_authorization
def populate
order = current_order(true)
cart_service = CartService.new(order)
if cart_service.populate(params.slice(:variants, :quantity))
order.cap_quantity_at_stock!
order.recreate_all_fees!
render json: { error: false, stock_levels: stock_levels(order) }, status: :ok
else
render json: { error: cart_service.errors.full_messages.join(",") },
status: :precondition_failed
end
end
private
def stock_levels(order)
variants_in_cart = order.line_items.pluck(:variant_id)
variants_in_request = raw_params[:variants]&.map(&:first) || []
VariantsStockLevels.new.call(order, (variants_in_cart + variants_in_request).uniq)
end
def check_authorization
session[:access_token] ||= params[:order_token]
order = Spree::Order.find_by(number: params[:id]) || current_order
if order
authorize! :edit, order, session[:access_token]
else
authorize! :create, Spree::Order
end
end
end