|
1 | 1 | require 'pundit'
|
2 | 2 |
|
3 | 3 | module JSONAPI
|
| 4 | + |
| 5 | + module ActiveRelation |
| 6 | + |
| 7 | + # Stores relationship paths starting from the resource_klass, consolidating duplicate paths from |
| 8 | + # relationships, filters and sorts. When joins are made the table aliases are tracked in join_details |
| 9 | + class JoinManager |
| 10 | + def perform_joins(records, options) |
| 11 | + join_array = flatten_join_tree_by_depth |
| 12 | + |
| 13 | + join_array.each do |level_joins| |
| 14 | + level_joins.each do |join_details| |
| 15 | + relationship = join_details[:relationship] |
| 16 | + relationship_details = join_details[:relationship_details] |
| 17 | + related_resource_klass = join_details[:related_resource_klass] |
| 18 | + join_type = relationship_details[:join_type] |
| 19 | + |
| 20 | + join_options = { |
| 21 | + relationship: relationship, |
| 22 | + relationship_details: relationship_details, |
| 23 | + related_resource_klass: related_resource_klass, |
| 24 | + } |
| 25 | + |
| 26 | + if relationship == :root |
| 27 | + unless source_relationship |
| 28 | + add_join_details('', {alias: resource_klass._table_name, join_type: :root, join_options: join_options}) |
| 29 | + end |
| 30 | + next |
| 31 | + end |
| 32 | + |
| 33 | + records, join_node = self.class.get_join_arel_node(records, options) {|records, options| |
| 34 | + related_resource_klass.join_relationship( |
| 35 | + records: records, |
| 36 | + resource_type: related_resource_klass._type, |
| 37 | + join_type: join_type, |
| 38 | + relationship: relationship, |
| 39 | + options: options) |
| 40 | + } |
| 41 | + |
| 42 | + details = {alias: self.class.alias_from_arel_node(join_node), join_type: join_type, join_options: join_options} |
| 43 | + |
| 44 | + if relationship == source_relationship |
| 45 | + if relationship.polymorphic? && relationship.belongs_to? |
| 46 | + add_join_details("##{related_resource_klass._type}", details) |
| 47 | + else |
| 48 | + add_join_details('', details) |
| 49 | + end |
| 50 | + end |
| 51 | + |
| 52 | + # We're adding the source alias with two keys. We only want the check for duplicate aliases once. |
| 53 | + # See the note in `add_join_details`. |
| 54 | + check_for_duplicate_alias = !(relationship == source_relationship) |
| 55 | + add_join_details(PathSegment::Relationship.new(relationship: relationship, resource_klass: related_resource_klass), details, check_for_duplicate_alias) |
| 56 | + end |
| 57 | + end |
| 58 | + records |
| 59 | + end |
| 60 | + end |
| 61 | + end |
| 62 | + |
4 | 63 | module Authorization
|
5 | 64 | module PunditScopedResource
|
6 | 65 | extend ActiveSupport::Concern
|
7 | 66 |
|
8 | 67 | module ClassMethods
|
9 | 68 | def records(options = {})
|
10 | 69 | user_context = JSONAPI::Authorization.configuration.user_context(options[:context])
|
11 |
| - ::Pundit.policy_scope!(user_context, _model_class) |
12 |
| - end |
13 |
| - end |
14 |
| - |
15 |
| - def records_for(association_name) |
16 |
| - record_or_records = @model.public_send(association_name) |
17 |
| - relationship = fetch_relationship(association_name) |
18 |
| - |
19 |
| - case relationship |
20 |
| - when JSONAPI::Relationship::ToOne |
21 |
| - record_or_records |
22 |
| - when JSONAPI::Relationship::ToMany |
23 |
| - user_context = JSONAPI::Authorization.configuration.user_context(context) |
24 |
| - ::Pundit.policy_scope!(user_context, record_or_records) |
25 |
| - else |
26 |
| - raise "Unknown relationship type #{relationship.inspect}" |
| 70 | + ::Pundit.policy_scope!(user_context, super) |
27 | 71 | end
|
28 |
| - end |
29 | 72 |
|
30 |
| - private |
31 |
| - |
32 |
| - def fetch_relationship(association_name) |
33 |
| - relationships = self.class._relationships.select do |_k, v| |
34 |
| - v.relation_name(context: context) == association_name |
35 |
| - end |
36 |
| - if relationships.empty? |
37 |
| - nil |
38 |
| - else |
39 |
| - relationships.values.first |
| 73 | + def apply_joins(records, join_manager, options) |
| 74 | + records = super |
| 75 | + join_manager.join_details.each do |k, v| |
| 76 | + next if k == '' || v[:join_type] == :root |
| 77 | + v[:join_options][:relationship_details][:resource_klasses].each_key do |klass| |
| 78 | + next unless klass.included_modules.include?(PunditScopedResource) |
| 79 | + records = records.where(v[:alias] => { klass._primary_key => klass.records(options)}) |
| 80 | + end |
| 81 | + end |
| 82 | + records |
40 | 83 | end
|
41 | 84 | end
|
42 | 85 | end
|
|
0 commit comments