Sha256: 90ed0ffe1db8b89b896523c7bb1d845cec31592bc116583b11d930a03e145da2

Contents?: true

Size: 1.18 KB

Versions: 8

Compression:

Stored size: 1.18 KB

Contents

module Spree
  module Admin
    class SearchController < Spree::Admin::BaseController
      # http://spreecommerce.com/blog/2010/11/02/json-hijacking-vulnerability/
      before_action :check_json_authenticity, only: :index
      respond_to :json

      # TODO: Clean this up by moving searching out to user_class_extensions
      # And then JSON building with something like Active Model Serializers
      def users
        if params[:ids]
          @users = Spree.user_class.where(:id => params[:ids].split(','))
        else
          @users = Spree.user_class.ransack({
            :m => 'or',
            :email_start => params[:q],
            :addresses_firstname_start => params[:q],
            :addresses_lastname_start => params[:q]
          }).result.limit(10)
        end
      end

      def products
        if params[:ids]
          @products = Product.where(:id => params[:ids].split(","))
        else
          @products = Product.ransack(params[:q]).result
        end

        @products = @products.distinct.page(params[:page]).per(params[:per_page])
        expires_in 15.minutes, :public => true
        headers['Surrogate-Control'] = "max-age=#{15.minutes}"
      end
    end
  end
end

Version data entries

8 entries across 8 versions & 1 rubygems

Version Path
solidus_backend-1.1.4 app/controllers/spree/admin/search_controller.rb
solidus_backend-1.1.3 app/controllers/spree/admin/search_controller.rb
solidus_backend-1.1.2 app/controllers/spree/admin/search_controller.rb
solidus_backend-1.1.1 app/controllers/spree/admin/search_controller.rb
solidus_backend-1.1.0 app/controllers/spree/admin/search_controller.rb
solidus_backend-1.1.0.pre2 app/controllers/spree/admin/search_controller.rb
solidus_backend-1.1.0.pre1 app/controllers/spree/admin/search_controller.rb
solidus_backend-1.1.0.beta1 app/controllers/spree/admin/search_controller.rb