Class: UsersController

Inherits:
ApplicationController show all
Includes:
Devise::Controllers::Rememberable
Defined in:
app/controllers/users_controller.rb

Overview

rubocop:disable Metrics/ClassLength

Instance Method Summary collapse

Methods inherited from ApplicationController

#dashboard, #keyboard_tools, #upload

Instance Method Details

#activityObject



213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
# File 'app/controllers/users_controller.rb', line 213

def activity
  @posts = Post.undeleted.where(user: @user).count
  @comments = Comment.joins(:comment_thread, :post).undeleted.where(user: @user, comment_threads: { deleted: false },
                                                                    posts: { deleted: false }).count
  @suggested_edits = SuggestedEdit.where(user: @user).count
  @edits = PostHistory.joins(:post, :post_history_type).where(user: @user, posts: { deleted: false },
                                                              post_history_types: { name: 'post_edited' }).count

  @all_edits = @suggested_edits + @edits

  items = case params[:filter]
          when 'posts'
            Post.undeleted.where(user: @user)
          when 'comments'
            Comment.joins(:comment_thread, :post).undeleted.where(user: @user, comment_threads: { deleted: false },
                                                                  posts: { deleted: false })
          when 'edits'
            SuggestedEdit.where(user: @user) + \
            PostHistory.joins(:post, :post_history_type).where(user: @user, posts: { deleted: false },
                                                               post_history_types: { name: 'post_edited' })
          else
            Post.undeleted.where(user: @user) + \
            Comment.joins(:comment_thread, :post).undeleted.where(user: @user, comment_threads: { deleted: false },
                                                                  posts: { deleted: false }) + \
            SuggestedEdit.where(user: @user).all + \
            PostHistory.joins(:post).where(user: @user, posts: { deleted: false }).all
          end

  @items = items.sort_by(&:created_at).reverse.paginate(page: params[:page], per_page: 50)
  render layout: 'without_sidebar'
end

#annotateObject



566
567
568
569
570
571
572
573
574
575
# File 'app/controllers/users_controller.rb', line 566

def annotate
  @log = AuditLog.user_annotation(event_type: 'annotation', user: current_user, related: @user,
                                  comment: params[:comment])
  if @log.errors.none?
    redirect_to user_annotations_path(@user)
  else
    flash[:danger] = 'Failed to save your annotation.'
    render :annotations
  end
end

#annotationsObject



560
561
562
563
564
# File 'app/controllers/users_controller.rb', line 560

def annotations
  @logs = AuditLog.where(log_type: 'user_annotation', related: @user).order(created_at: :desc)
                  .paginate(page: params[:page], per_page: 20)
  render layout: 'without_sidebar'
end

#avatarObject



599
600
601
602
603
604
605
606
# File 'app/controllers/users_controller.rb', line 599

def avatar
  respond_to do |format|
    format.png do
      size = params[:size]&.to_i&.positive? ? [params[:size]&.to_i, 256].min : 64
      send_data helpers.user_auto_avatar(size, user: @user).to_blob, type: 'image/png', disposition: 'inline'
    end
  end
end

#cleaned_profile_websites(profile_params) ⇒ Object



358
359
360
361
362
363
364
# File 'app/controllers/users_controller.rb', line 358

def cleaned_profile_websites(profile_params)
  sites = profile_params[:user_websites_attributes]

  sites.transform_values do |w|
    w.merge({ label: w[:label].presence, url: w[:url].presence })
  end
end

#confirm_disconnect_ssoObject



622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
# File 'app/controllers/users_controller.rb', line 622

def confirm_disconnect_sso
  if current_user.sso_profile.blank? || !helpers. || !SiteSetting['AllowSsoDisconnect']
    flash[:danger] = 'You cannot disable Single Sign-On.'
    redirect_to edit_user_registration_path
    return
  end

  if current_user.sso_profile.destroy
    current_user.send_reset_password_instructions
    flash[:success] = 'Successfully disconnected from Single Sign-On. Please see your email to set your password.'
    redirect_to edit_user_registration_path
  else
    flash[:danger] = 'Failed to disconnect from Single Sign-On.'
    redirect_to user_disconnect_sso_path
  end
end

#default_filterObject



158
159
160
161
162
163
164
165
166
167
# File 'app/controllers/users_controller.rb', line 158

def default_filter
  if user_signed_in? && params[:category]
    default_filter = helpers.default_filter(current_user.id, params[:category].to_i)
    render json: { status: 'success', success: true, name: default_filter&.name },
           status: 200
  else
    render json: { status: 'failed', success: false },
           status: 400
  end
end

#delete_filterObject



132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
# File 'app/controllers/users_controller.rb', line 132

def delete_filter
  unless params[:name]
    return render json: { status: 'failed', success: false, errors: ['Filter name is required'] },
                  status: 400
  end

  as_user = current_user

  if params[:system] == true
    if current_user&.is_global_admin
      as_user = User.find(-1)
    else
      return render json: { status: 'failed', success: false, errors: ['You do not have permission to delete'] },
                    status: 400
    end
  end

  filter = Filter.find_by(user: as_user, name: params[:name])
  if filter.destroy
    render json: { status: 'success', success: true, filters: filters_json }
  else
    render json: { status: 'failed', success: false, errors: ['Failed to delete'] },
           status: 400
  end
end

#destroyObject



293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
# File 'app/controllers/users_controller.rb', line 293

def destroy
  if @user.votes.count > 100
    render json: { status: 'failed', message: 'Users with more than 100 votes cannot be destroyed.' },
           status: :unprocessable_entity
    return
  end

  if @user.is_admin || @user.is_moderator
    render json: { status: 'failed', message: 'Admins and moderators cannot be destroyed.' },
           status: :unprocessable_entity
    return
  end

  before = @user.attributes_print
  @user.block('user destroyed')

  if @user.destroy
    Post.unscoped.where(user_id: @user.id).update_all(user_id: SiteSetting['SoftDeleteTransferUser'],
                                                      deleted: true, deleted_at: DateTime.now,
                                                      deleted_by_id: SiteSetting['SoftDeleteTransferUser'])
    Comment.unscoped.where(user_id: @user.id).update_all(user_id: SiteSetting['SoftDeleteTransferUser'],
                                                         deleted: true)
    Flag.unscoped.where(user_id: @user.id).update_all(user_id: SiteSetting['SoftDeleteTransferUser'])
    SuggestedEdit.unscoped.where(user_id: @user.id).update_all(user_id: SiteSetting['SoftDeleteTransferUser'])
    AuditLog.moderator_audit(event_type: 'user_destroy', user: current_user, comment: "<<User #{before}>>")
    render json: { status: 'success' }
  else
    render json: { status: 'failed',
                   message: 'Failed to destroy user; ask a dev.' },
           status: :internal_server_error
  end
end

#disconnect_ssoObject



618
619
620
# File 'app/controllers/users_controller.rb', line 618

def disconnect_sso
  render layout: 'without_sidebar'
end

#do_qr_loginObject



544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
# File 'app/controllers/users_controller.rb', line 544

def 
  user = User.find_by(login_token: params[:token])
  if user&.&.present? && user. >= DateTime.now
    flash[:success] = 'You are now signed in.'
    user.update(login_token: nil, login_token_expires_at: nil)
     user
    remember_me user
    AuditLog.user_history(event_type: 'mobile_login', related: user)
    redirect_to (user)
  else
    flash[:danger] = "That login link isn't valid. Codes expire after 5 minutes - if it's been longer than that, " \
                     'get a new code and try again.'
    not_found
  end
end

#edit_profileObject



354
355
356
# File 'app/controllers/users_controller.rb', line 354

def edit_profile
  render layout: 'without_sidebar'
end

#filter_json(filter) ⇒ Object

Helper method to convert it to the form expected by the client



77
78
79
80
81
82
83
84
85
86
87
88
# File 'app/controllers/users_controller.rb', line 77

def filter_json(filter)
  {
    min_score: filter.min_score,
    max_score: filter.max_score,
    min_answers: filter.min_answers,
    max_answers: filter.max_answers,
    include_tags: Tag.where(id: filter.include_tags).map { |tag| [tag.name, tag.id] },
    exclude_tags: Tag.where(id: filter.exclude_tags).map { |tag| [tag.name, tag.id] },
    status: filter.status,
    system: filter.user_id == -1
  }
end

#filtersObject



103
104
105
106
107
108
109
110
111
112
# File 'app/controllers/users_controller.rb', line 103

def filters
  respond_to do |format|
    format.html do
      render layout: 'without_sidebar'
    end
    format.json do
      render json: filters_json
    end
  end
end

#filters_jsonObject



90
91
92
93
94
95
96
97
98
99
100
101
# File 'app/controllers/users_controller.rb', line 90

def filters_json
  system_filters = Rails.cache.fetch 'default_system_filters', expires_in: 1.day do
    User.find(-1).filters.to_h { |filter| [filter.name, filter_json(filter)] }
  end

  if user_signed_in?
    current_user.filters.to_h { |filter| [filter.name, filter_json(filter)] }
                .merge(system_filters)
  else
    system_filters
  end
end

#full_logObject



247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
# File 'app/controllers/users_controller.rb', line 247

def full_log
  @posts = Post.where(user: @user).count
  @comments = Comment.where(user: @user).count
  @flags = Flag.where(user: @user).count
  @suggested_edits = SuggestedEdit.where(user: @user).count
  @edits = PostHistory.where(user: @user).count
  @mod_warnings_received = ModWarning.where(community_user: @user.community_user).count

  @all_edits = @suggested_edits + @edits

  @interesting_comments = Comment.where(user: @user, deleted: true).count
  @interesting_flags = Flag.where(user: @user, status: 'declined').count
  @interesting_edits = SuggestedEdit.where(user: @user, active: false, accepted: false).count
  @interesting_posts = Post.where(user: @user).where('score < 0.25 OR deleted=1').count

  @interesting = @interesting_comments + @interesting_flags + @mod_warnings_received + \
                 @interesting_edits + @interesting_posts

  @items = (case params[:filter]
            when 'posts'
              Post.where(user: @user).all
            when 'comments'
              Comment.where(user: @user).all
            when 'flags'
              Flag.where(user: @user).all
            when 'edits'
              SuggestedEdit.where(user: @user).all + PostHistory.where(user: @user).all
            when 'warnings'
              ModWarning.where(community_user: @user.community_user).all
            when 'interesting'
              Comment.where(user: @user, deleted: true).all + Flag.where(user: @user, status: 'declined').all + \
                SuggestedEdit.where(user: @user, active: false, accepted: false).all + \
                Post.where(user: @user).where('score < 0.25 OR deleted=1').all
            else
              Post.where(user: @user).all + Comment.where(user: @user).all + Flag.where(user: @user).all + \
                SuggestedEdit.where(user: @user).all + PostHistory.where(user: @user).all + \
                ModWarning.where(community_user: @user.community_user).all
            end).sort_by(&:created_at).reverse.paginate(page: params[:page], per_page: 50)

  render layout: 'without_sidebar'
end

#indexObject



17
18
19
20
21
22
23
24
25
26
# File 'app/controllers/users_controller.rb', line 17

def index
  sort_param = { reputation: :reputation, age: :created_at }[params[:sort]&.to_sym] || :reputation
  @users = if params[:search].present?
             user_scope.search(params[:search])
           else
             user_scope.order(sort_param => :desc)
           end.where.not(deleted: true).where.not(community_users: { deleted: true })
              .paginate(page: params[:page], per_page: 48) # rubocop:disable Layout/MultilineMethodCallIndentation
  @post_counts = Post.where(user_id: @users.pluck(:id).uniq).group(:user_id).count
end

#meObject



47
48
49
50
51
52
53
54
55
56
57
58
59
# File 'app/controllers/users_controller.rb', line 47

def me
  @user = current_user
  respond_to do |format|
    format.html do
      redirect_to user_path(@user)
    end
    format.json do
      data = [:id, :username, :is_moderator, :is_admin, :is_global_moderator, :is_global_admin, :trust_level,
              :se_acct_id].to_h { |a| [a, @user.send(a)] }
      render json: data
    end
  end
end

#modObject



245
# File 'app/controllers/users_controller.rb', line 245

def mod; end

#mod_privilege_actionObject



447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
# File 'app/controllers/users_controller.rb', line 447

def mod_privilege_action
  ability = Ability.find_by internal_id: params[:ability]
  return not_found if ability.internal_id == 'mod'

  ua = @user.community_user.privilege(ability.internal_id)

  case params[:do]
  when 'grant'
    if ua.nil?
      @user.community_user.grant_privilege!(ability.internal_id)
      AuditLog.admin_audit(event_type: 'ability_grant', related: @user, user: current_user,
                           comment: ability.internal_id.to_s)
    elsif ua.is_suspended
      ua.update is_suspended: false
      AuditLog.admin_audit(event_type: 'ability_unsuspend', related: @user, user: current_user,
                           comment: "#{ability.internal_id} ability unsuspended")
    end

  when 'suspend'
    return not_found if ua.nil?

    duration = params[:duration]&.to_i
    duration = duration <= 0 ? nil : duration.days.from_now
    message = params[:message]

    ua.update is_suspended: true, suspension_end: duration, suspension_message: message
    @user.create_notification("Your #{ability.name} ability has been suspended. Click for more information.",
                              ability_url(ability.internal_id))
    AuditLog.admin_audit(event_type: 'ability_suspend', related: @user, user: current_user,
                         comment: "#{ability.internal_id} ability suspended\n\n#{message}")

  when 'delete'
    return not_found if ua.nil?

    ua.destroy
    AuditLog.admin_audit(event_type: 'ability_remove', related: @user, user: current_user,
                         comment: "#{ability.internal_id} ability removed")

    AuditLog.user_history(event_type: 'deleted_ability', related: nil, user: @user,
                          comment: ability.internal_id)
  else
    return not_found
  end
  render json: { status: 'success' }
end

#mod_privilegesObject



289
290
291
# File 'app/controllers/users_controller.rb', line 289

def mod_privileges
  @abilities = Ability.all
end

#my_networkObject



204
205
206
# File 'app/controllers/users_controller.rb', line 204

def my_network
  redirect_to network_path(current_user)
end

#my_vote_summaryObject



577
578
579
# File 'app/controllers/users_controller.rb', line 577

def my_vote_summary
  redirect_to vote_summary_path(current_user)
end

#networkObject



208
209
210
211
# File 'app/controllers/users_controller.rb', line 208

def network
  @communities = Community.all
  render layout: 'without_sidebar'
end

#postsObject



184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
# File 'app/controllers/users_controller.rb', line 184

def posts
  @posts = if current_user&.privilege?('flag_curate') || @user == current_user
             Post.all
           else
             Post.undeleted
           end.where(user: @user).list_includes.joins(:category)
           .where('IFNULL(categories.min_view_trust_level, 0) <= ?', current_user&.trust_level || 0)
           .user_sort({ term: params[:sort], default: :score },
                      age: :created_at, score: :score)
           .paginate(page: params[:page], per_page: 25)
  respond_to do |format|
    format.html do
      render :posts
    end
    format.json do
      render json: @posts
    end
  end
end

#preferencesObject



61
62
63
64
65
66
67
68
69
70
71
72
73
74
# File 'app/controllers/users_controller.rb', line 61

def preferences
  current_user.validate_prefs!
  respond_to do |format|
    format.html do
      prefs = current_user.preferences
      @preferences = prefs[:global]
      @community_prefs = prefs[:community]
      render layout: 'without_sidebar'
    end
    format.json do
      render json: current_user.preferences
    end
  end
end

#qr_login_codeObject



538
539
540
541
542
# File 'app/controllers/users_controller.rb', line 538

def 
  @token = SecureRandom.urlsafe_base64(64)
  @qr_code = RQRCode::QRCode.new((@token))
  current_user.update(login_token: @token, login_token_expires_at: 5.minutes.from_now)
end

#role_toggleObject



407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
# File 'app/controllers/users_controller.rb', line 407

def role_toggle
  role_map = { mod: :is_moderator, admin: :is_admin, mod_global: :is_global_moderator, admin_global: :is_global_admin,
               staff: :staff }
  permission_map = { mod: :is_admin, admin: :is_global_admin, mod_global: :is_global_admin,
  admin_global: :is_global_admin, staff: :staff }
  unless role_map.keys.include?(params[:role].underscore.to_sym)
    render json: { status: 'error', message: "Role not found: #{params[:role]}" }, status: :bad_request
  end

  key = params[:role].underscore.to_sym
  attrib = role_map[key]
  permission = permission_map[key]
  return not_found unless current_user.send(permission)

  case key
  when :mod
    new_value = !@user.community_user.send(attrib)

    # Set/update ability
    if new_value
      @user.community_user.grant_privilege! 'mod'
    else
      @user.community_user.privilege('mod').destroy
    end

    @user.community_user.update(attrib => new_value)
  when :admin
    new_value = !@user.community_user.send(attrib)
    @user.community_user.update(attrib => new_value)
  else
    new_value = !@user.send(attrib)
    @user.update(attrib => new_value)
  end
  AuditLog.admin_audit(event_type: 'role_toggle', related: @user, user: current_user,
                       comment: "#{attrib} to #{new_value}")
  AbilityQueue.add(@user, 'Role Change')

  render json: { status: 'success' }
end

#set_filterObject



114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
# File 'app/controllers/users_controller.rb', line 114

def set_filter
  if user_signed_in? && params[:name]
    filter = Filter.find_or_create_by(user: current_user, name: params[:name])

    filter.update(filter_params)

    unless params[:category].nil? || params[:is_default].nil?
      helpers.set_filter_default(current_user.id, filter.id, params[:category].to_i, params[:is_default])
    end

    render json: { status: 'success', success: true, filters: filters_json },
           status: 200
  else
    render json: { status: 'failed', success: false, errors: ['Filter name is required'] },
           status: 400
  end
end

#set_preferenceObject



169
170
171
172
173
174
175
176
177
178
179
180
181
182
# File 'app/controllers/users_controller.rb', line 169

def set_preference
  if !params[:name].nil? && !params[:value].nil?
    global_key = "prefs.#{current_user.id}"
    community_key = "prefs.#{current_user.id}.community.#{RequestContext.community_id}"
    key = params[:community].present? && params[:community] ? community_key : global_key
    current_user.validate_prefs!
    render json: { status: 'success', success: true,
                   count: RequestContext.redis.hset(key, params[:name], params[:value].to_s),
                   preferences: current_user.preferences }
  else
    render json: { status: 'failed', success: false, errors: ['Both name and value parameters are required'] },
           status: 400
  end
end

#showObject



28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
# File 'app/controllers/users_controller.rb', line 28

def show
  @abilities = Ability.on_user(@user)

  all_posts = if current_user&.privilege?('flag_curate') || @user == current_user
                @user.posts
              else
                @user.posts.undeleted
              end
              .list_includes
              .joins(:category)
              .where('IFNULL(categories.min_view_trust_level, 0) <= ?', current_user&.trust_level || 0)
              .user_sort({ term: params[:sort], default: :score },
                         age: :created_at, score: :score)

  @posts = all_posts.first(15)
  @total_post_count = all_posts.count
  render layout: 'without_sidebar'
end

#soft_deleteObject



326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
# File 'app/controllers/users_controller.rb', line 326

def soft_delete
  if @user.is_admin || @user.is_moderator
    render json: { status: 'failed', message: 'Admins and moderators cannot be deleted.' },
           status: :unprocessable_entity
    return
  end

  case params[:type]
  when 'profile'
    AuditLog.moderator_audit(event_type: 'profile_delete', related: @user.community_user, user: current_user,
                             comment: @user.community_user.attributes_print(join: "\n"))
    @user.community_user.update(deleted: true, deleted_by: current_user, deleted_at: DateTime.now)
  when 'user'
    unless current_user.is_global_moderator || current_user.is_global_admin
      render json: { status: 'failed', message: 'Non-global moderator cannot perform global deletion.' },
             status: 403
      return
    end

    @user.do_soft_delete(current_user)
  else
    render json: { status: 'failed', message: 'Unrecognised deletion type.' }, status: 400
    return
  end

  render json: { status: 'success', user: @user.id }
end

#specific_avatarObject



608
609
610
611
612
613
614
615
616
# File 'app/controllers/users_controller.rb', line 608

def specific_avatar
  respond_to do |format|
    format.png do
      size = params[:size]&.to_i&.positive? ? params[:size]&.to_i : 64
      send_data helpers.user_auto_avatar(size, letter: params[:letter], color: params[:color]).to_blob,
                type: 'image/png', disposition: 'inline'
    end
  end
end

#stack_redirectObject



493
494
495
496
497
498
499
500
501
502
503
504
505
506
# File 'app/controllers/users_controller.rb', line 493

def stack_redirect
  response = Net::HTTP.post_form(URI('https://stackoverflow.com/oauth/access_token/json'),
                                 'client_id' => SiteSetting['SEApiClientId'],
                                 'client_secret' => SiteSetting['SEApiClientSecret'],
                                 'code' => params[:code], 'redirect_uri' => stack_redirect_url)
  access_token = JSON.parse(response.body)['access_token']

  uri = "https://api.stackexchange.com/2.2/me/associated?key=#{SiteSetting['SEApiKey']}" \
        "&access_token=#{access_token}&filter=!-rH86dva"
  accounts = JSON.parse(Net::HTTP.get(URI(uri)))
  network_id = accounts['items'][0]['account_id']
  current_user.update(se_acct_id: network_id)
  redirect_to 
end

#transfer_se_contentObject



508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
# File 'app/controllers/users_controller.rb', line 508

def transfer_se_content
  unless params[:agree_to_relicense].present? && params[:agree_to_relicense] == 'true'
    flash[:danger] = 'To claim your content, we need you to agree to relicense your posts to us.'
    redirect_to() && return
  end

  auto_user = User.where(se_acct_id: current_user.se_acct_id).where.not(id: current_user.id).first
  if auto_user.nil?
    flash[:warning] = "There doesn't appear to be any of your content here."
    redirect_to() && return
  end

  community = RequestContext.community

  Thread.new do
    RequestContext.community = community

    ApplicationRecord.transaction do
      auto_user.posts.each do |post|
        post.reassign_user(current_user)
        post.remove_attribution_notice!
      end
      auto_user.reload.destroy
      current_user.update(transferred_content: true)
    end
  end
  flash[:success] = 'Your content is being transferred to you.'
  redirect_to 
end

#update_profileObject



366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
# File 'app/controllers/users_controller.rb', line 366

def update_profile
  profile_params = params.require(:user).permit(:username,
                                                :profile_markdown,
                                                :website,
                                                :discord,
                                                :twitter,
                                                user_websites_attributes: [:id, :label, :url])

  if profile_params[:user_websites_attributes].present?
    profile_params[:user_websites_attributes] = cleaned_profile_websites(profile_params)
  end

  @user = current_user

  if params[:user][:avatar].present?
    if helpers.valid_image?(params[:user][:avatar])
      @user.avatar.attach(params[:user][:avatar])
    else
      @user.errors.add(:avatar, 'must be a valid image')
      flash[:danger] = "Couldn't update your profile."
      render :edit_profile
      return
    end
  end

  if params[:user][:profile_markdown].present?
    profile_rendered = helpers.post_markdown(:user, :profile_markdown)
    profile_params = profile_params.merge(profile: profile_rendered)
  end

  status = @user.update(profile_params)

  if status
    flash[:success] = 'Your profile details were updated.'
    redirect_to user_path(current_user)
  else
    flash[:danger] = "Couldn't update your profile."
    render :edit_profile
  end
end

#vote_summaryObject



581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
# File 'app/controllers/users_controller.rb', line 581

def vote_summary
  @votes = Vote.where(recv_user: @user)
               .includes(:post)
               .group(:date_of, :post_id, :vote_type)

  @votes = @votes.select(:post_id, :vote_type)
                 .select('count(*) as vote_count')
                 .select('date(votes.created_at) as date_of')

  @votes = @votes.order(date_of: :desc, post_id: :desc).all \
                 .group_by(&:date_of).map do |k, vl|
                   [k, vl.group_by(&:post), vl.sum { |v| v.vote_type * v.vote_count }]
                 end \
                 .paginate(page: params[:page], per_page: 15)

  render layout: 'without_sidebar'
end