issues_controller.rb 9.6 KB
Newer Older
1 2
# frozen_string_literal: true

3
class Projects::IssuesController < Projects::ApplicationController
D
Douwe Maan 已提交
4
  include RendersNotes
5
  include ToggleSubscriptionAction
6
  include IssuableActions
7
  include ToggleAwardEmoji
8
  include IssuableCollections
9
  include IssuesCalendar
10
  include SpammableActions
11
  include RecordUserLastActivity
12

13
  def issue_except_actions
14
    %i[index calendar new create bulk_update import_csv export_csv]
15 16
  end

17
  def set_issuables_index_only_actions
18 19 20
    %i[index calendar]
  end

21 22
  prepend_before_action(only: [:index]) { authenticate_sessionless_user!(:rss) }
  prepend_before_action(only: [:calendar]) { authenticate_sessionless_user!(:ics) }
23
  prepend_before_action :authenticate_user!, only: [:new, :export_csv]
24 25
  # designs is only applicable to EE, but defining a prepend_before_action in EE code would overwrite this
  prepend_before_action :store_uri, only: [:new, :show, :designs]
26

27
  before_action :whitelist_query_limiting, only: [:create, :create_merge_request, :move, :bulk_update]
28
  before_action :check_issues_available!
29
  before_action :issue, unless: ->(c) { c.issue_except_actions.include?(c.action_name.to_sym) }
30

31
  before_action :set_issuables_index, if: ->(c) { c.set_issuables_index_only_actions.include?(c.action_name.to_sym) }
D
Dmitriy Zaporozhets 已提交
32 33

  # Allow write(create) issue
D
Dmitriy Zaporozhets 已提交
34
  before_action :authorize_create_issue!, only: [:new, :create]
D
Dmitriy Zaporozhets 已提交
35 36

  # Allow modify issue
37
  before_action :authorize_update_issuable!, only: [:edit, :update, :move, :reorder]
D
Dmitriy Zaporozhets 已提交
38

39
  # Allow create a new branch and empty WIP merge request from current issue
40
  before_action :authorize_create_merge_request_from!, only: [:create_merge_request]
41

42
  before_action :authorize_import_issues!, only: [:import_csv]
43
  before_action :authorize_download_code!, only: [:related_branches]
44

45 46 47
  # Limit the amount of issues created per minute
  before_action :create_rate_limit, only: [:create]

48 49
  before_action do
    push_frontend_feature_flag(:vue_issuable_sidebar, project.group)
50
    push_frontend_feature_flag(:save_issuable_health_status, project.group, default_enabled: true)
51 52
  end

53 54
  around_action :allow_gitaly_ref_name_caching, only: [:discussions]

D
Dmitriy Zaporozhets 已提交
55
  respond_to :html
G
gitlabhq 已提交
56

57 58
  alias_method :designs, :show

G
gitlabhq 已提交
59
  def index
J
Jarka Kadlecova 已提交
60
    @issues = @issuables
61

G
gitlabhq 已提交
62
    respond_to do |format|
D
Dmitriy Zaporozhets 已提交
63
      format.html
64
      format.atom { render layout: 'xml.atom' }
D
Dmitriy Zaporozhets 已提交
65 66
      format.json do
        render json: {
67
          html: view_to_html_string("projects/issues/_issues"),
P
Phil Hughes 已提交
68
          labels: @labels.as_json(methods: :text_color)
D
Dmitriy Zaporozhets 已提交
69 70
        }
      end
G
gitlabhq 已提交
71 72 73
    end
  end

74
  def calendar
75
    render_issues_calendar(@issuables)
76 77
  end

G
gitlabhq 已提交
78
  def new
79
    params[:issue] ||= ActionController::Parameters.new(
80
      assignee_ids: ""
81
    )
82
    build_params = issue_params.merge(
B
Bob Van Landuyt 已提交
83
      merge_request_to_resolve_discussions_of: params[:merge_request_to_resolve_discussions_of],
84
      discussion_to_resolve: params[:discussion_to_resolve]
85
    )
86
    service = Issues::BuildService.new(project, current_user, build_params)
87

88
    @issue = @noteable = service.execute
B
Bob Van Landuyt 已提交
89
    @merge_request_to_resolve_discussions_of = service.merge_request_to_resolve_discussions_of
90
    @discussion_to_resolve = service.discussions_to_resolve.first if params[:discussion_to_resolve]
91

G
gitlabhq 已提交
92 93 94
    respond_with(@issue)
  end

95 96 97 98
  def edit
    respond_with(@issue)
  end

G
gitlabhq 已提交
99
  def create
100
    create_params = issue_params.merge(spammable_params).merge(
B
Bob Van Landuyt 已提交
101
      merge_request_to_resolve_discussions_of: params[:merge_request_to_resolve_discussions_of],
102 103 104
      discussion_to_resolve: params[:discussion_to_resolve]
    )

105 106 107
    service = Issues::CreateService.new(project, current_user, create_params)
    @issue = service.execute

108
    if service.discussions_to_resolve.count(&:resolved?) > 0
109
      flash[:notice] = if service.discussion_to_resolve_id
110
                         _("Resolved 1 discussion.")
111
                       else
112
                         _("Resolved all discussions.")
113
                       end
114
    end
G
gitlabhq 已提交
115

116
    respond_to do |format|
117
      format.html do
118
        recaptcha_check_with_fallback { render :new }
119
      end
120
      format.js do
121 122
        @link = @issue.attachment.url.to_js
      end
123
    end
G
gitlabhq 已提交
124 125
  end

126 127 128
  def move
    params.require(:move_to_project_id)

129 130
    if params[:move_to_project_id].to_i > 0
      new_project = Project.find(params[:move_to_project_id])
131 132
      return render_404 unless issue.can_move?(current_user, new_project)

133
      @issue = Issues::UpdateService.new(project, current_user, target_project: new_project).execute(issue)
134
    end
G
gitlabhq 已提交
135 136

    respond_to do |format|
137
      format.json do
138
        render_issue_json
139
      end
G
gitlabhq 已提交
140
    end
141 142

  rescue ActiveRecord::StaleObjectError
143
    render_conflict_response
G
gitlabhq 已提交
144 145
  end

146 147 148 149 150 151 152 153 154 155
  def reorder
    service = Issues::ReorderService.new(project, current_user, reorder_params)

    if service.execute(issue)
      head :ok
    else
      head :unprocessable_entity
    end
  end

156
  def related_branches
157
    @related_branches = Issues::RelatedBranchesService.new(project, current_user).execute(issue)
158 159 160 161 162 163 164 165 166 167

    respond_to do |format|
      format.json do
        render json: {
          html: view_to_html_string('projects/issues/_related_branches')
        }
      end
    end
  end

168 169 170
  def can_create_branch
    can_create = current_user &&
      can?(current_user, :push_code, @project) &&
H
Heinrich Lee Yu 已提交
171
      @issue.can_be_worked_on?
172 173 174

    respond_to do |format|
      format.json do
H
Heinrich Lee Yu 已提交
175
        render json: { can_create_branch: can_create, suggested_branch_name: @issue.suggested_branch_name }
176 177 178 179
      end
    end
  end

180
  def create_merge_request
181
    create_params = params.slice(:branch_name, :ref).merge(issue_iid: issue.iid)
182
    create_params[:target_project_id] = params[:target_project_id] if helpers.create_confidential_merge_request_enabled?
183
    result = ::MergeRequests::CreateFromIssueService.new(project, current_user, create_params).execute
184 185 186 187

    if result[:status] == :success
      render json: MergeRequestCreateSerializer.new.represent(result[:merge_request])
    else
188
      render json: result[:message], status: :unprocessable_entity
189 190 191
    end
  end

192 193 194 195
  def export_csv
    ExportCsvWorker.perform_async(current_user.id, project.id, finder_options.to_h) # rubocop:disable CodeReuse/Worker

    index_path = project_issues_path(project)
196 197
    message = _('Your CSV export has started. It will be emailed to %{email} when complete.') % { email: current_user.notification_email }
    redirect_to(index_path, notice: message)
198 199
  end

H
Heinrich Lee Yu 已提交
200
  def import_csv
201
    if uploader = UploadService.new(project, params[:file]).execute
202
      ImportIssuesCsvWorker.perform_async(current_user.id, project.id, uploader.upload.id) # rubocop:disable CodeReuse/Worker
H
Heinrich Lee Yu 已提交
203 204 205 206 207 208 209

      flash[:notice] = _("Your issues are being imported. Once finished, you'll get a confirmation email.")
    else
      flash[:alert] = _("File upload error.")
    end

    redirect_to project_issues_path(project)
H
Heinrich Lee Yu 已提交
210 211
  end

N
Nihad Abbasov 已提交
212
  protected
G
gitlabhq 已提交
213

G
George Koltsov 已提交
214
  def sorting_field
215 216 217
    Issue::SORTING_PREFERENCE_FIELD
  end

218
  # rubocop: disable CodeReuse/ActiveRecord
G
gitlabhq 已提交
219
  def issue
220
    return @issue if defined?(@issue)
221

222
    # The Sortable default scope causes performance issues when used with find_by
223
    @issuable = @noteable = @issue ||= @project.issues.includes(author: :status).where(iid: params[:id]).reorder(nil).take!
224
    @note = @project.notes.new(noteable: @issuable)
225 226 227 228

    return render_404 unless can?(current_user, :read_issue, @issue)

    @issue
G
gitlabhq 已提交
229
  end
230
  # rubocop: enable CodeReuse/ActiveRecord
231
  alias_method :subscribable_resource, :issue
232
  alias_method :issuable, :issue
233
  alias_method :awardable, :issue
234
  alias_method :spammable, :issue
D
Dmitriy Zaporozhets 已提交
235

236 237 238 239
  def spammable_path
    project_issue_path(@project, @issue)
  end

240
  def authorize_create_merge_request!
241
    render_404 unless can?(current_user, :push_code, @project) && @issue.can_be_worked_on?
242 243
  end

244 245 246 247 248 249 250 251
  def render_issue_json
    if @issue.valid?
      render json: serializer.represent(@issue)
    else
      render json: { errors: @issue.errors.full_messages }, status: :unprocessable_entity
    end
  end

252
  def issue_params
253 254 255 256
    params.require(:issue).permit(
      *issue_params_attributes,
      sentry_issue_attributes: [:sentry_issue_identifier]
    )
257 258 259 260 261 262 263 264 265 266 267 268 269 270
  end

  def issue_params_attributes
    %i[
      title
      assignee_id
      position
      description
      confidential
      milestone_id
      due_date
      state_event
      task_num
      lock_version
271
      discussion_locked
272
    ] + [{ label_ids: [], assignee_ids: [], update_task: [:index, :checked, :line_number, :line_source] }]
273
  end
274

275 276 277 278
  def reorder_params
    params.permit(:move_before_id, :move_after_id, :group_full_path)
  end

279
  def store_uri
280 281 282
    if request.get? && !request.xhr?
      store_location_for :user, request.fullpath
    end
283
  end
D
Douwe Maan 已提交
284 285 286 287

  def serializer
    IssueSerializer.new(current_user: current_user, project: issue.project)
  end
288 289 290 291 292

  def update_service
    update_params = issue_params.merge(spammable_params)
    Issues::UpdateService.new(project, current_user, update_params)
  end
J
Jarka Kadlecova 已提交
293

294 295
  def finder_type
    IssuesFinder
J
Jarka Kadlecova 已提交
296
  end
297 298 299 300

  def whitelist_query_limiting
    # Also see the following issues:
    #
301 302 303 304
    # 1. https://gitlab.com/gitlab-org/gitlab-foss/issues/42423
    # 2. https://gitlab.com/gitlab-org/gitlab-foss/issues/42424
    # 3. https://gitlab.com/gitlab-org/gitlab-foss/issues/42426
    Gitlab::QueryLimiting.whitelist('https://gitlab.com/gitlab-org/gitlab-foss/issues/42422')
305
  end
306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321

  private

  def create_rate_limit
    key = :issues_create

    if rate_limiter.throttled?(key, scope: [@project, @current_user])
      rate_limiter.log_request(request, "#{key}_request_limit".to_sym, current_user)

      render plain: _('This endpoint has been requested too many times. Try again later.'), status: :too_many_requests
    end
  end

  def rate_limiter
    ::Gitlab::ApplicationRateLimiter
  end
G
gitlabhq 已提交
322
end
323 324

Projects::IssuesController.prepend_if_ee('EE::Projects::IssuesController')