Class: Admin::NotificationsController

Inherits:
BaseController
  • Object
show all
Defined in:
lib/generators/open_loam/install/templates/admin/notifications_controller.rb

Overview

The bell. Every query here is scoped to the current actor, so there is no "read someone else's notifications" path to authorize and no per-record policy to write: tenancy is structural (OpenLoam::Notification is a OpenLoam::TenantRecord) and BaseController has already established that this actor is signed in to this tenant. Recipient scoping is the whole rule.

Constant Summary

Constants included from Pagination

Pagination::PER_PAGE

Instance Method Summary collapse

Methods inherited from BaseController

skip_authorization!

Methods included from Pagination

#paginate

Instance Method Details

#index ⇒ Object



10
11
12
# File 'lib/generators/open_loam/install/templates/admin/notifications_controller.rb', line 10

def index
  @records = notifications.order(created_at: :desc).limit(100)
end

#mark_read ⇒ Object



14
15
16
17
# File 'lib/generators/open_loam/install/templates/admin/notifications_controller.rb', line 14

def mark_read
  notifications.find(params[:id]).mark_read!
  redirect_to admin_notifications_path
end