Skip to content

Commit 34682f8

Browse files
authored
Merge pull request #6118 from gms-electronics/metadata-draft-pr
Admin and User Metadata for transactional ressources and users (#5897)
2 parents 7205ff0 + b954491 commit 34682f8

40 files changed

+716
-28
lines changed

Gemfile

-1
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,6 @@ gem 'pg', '~> 1.0', require: false if dbs.match?(/all|postgres/)
2121
gem 'fast_sqlite', require: false if dbs.match?(/all|sqlite/)
2222
gem 'sqlite3', '>= 2.1', require: false if dbs.match?(/all|sqlite/)
2323

24-
2524
gem 'database_cleaner', '~> 2.0', require: false
2625
gem 'rspec-activemodel-mocks', '~> 1.1', require: false
2726
gem 'rspec-rails', '~> 6.0.3', require: false

api/app/controllers/spree/api/base_controller.rb

+18-1
Original file line numberDiff line numberDiff line change
@@ -18,6 +18,9 @@ class BaseController < ActionController::Base
1818
class_attribute :admin_line_item_attributes
1919
self.admin_line_item_attributes = [:price, :variant_id, :sku]
2020

21+
class_attribute :admin_metadata_attributes
22+
self.admin_metadata_attributes = [{ admin_metadata: {} }]
23+
2124
attr_accessor :current_api_user
2225

2326
before_action :load_user
@@ -35,15 +38,29 @@ class BaseController < ActionController::Base
3538

3639
private
3740

41+
Spree::Api::Config.metadata_permit_parameters.each do |resource|
42+
define_method("permitted_#{resource.to_s.underscore}_attributes") do
43+
if can?(:admin, "Spree::#{resource}".constantize)
44+
super() + admin_metadata_attributes
45+
else
46+
super()
47+
end
48+
end
49+
end
50+
3851
# users should be able to set price when importing orders via api
3952
def permitted_line_item_attributes
4053
if can?(:admin, Spree::LineItem)
41-
super + admin_line_item_attributes
54+
super + admin_line_item_attributes + admin_metadata_attributes
4255
else
4356
super
4457
end
4558
end
4659

60+
def permitted_user_attributes
61+
can?(:admin, Spree.user_class) ? super + admin_metadata_attributes : super
62+
end
63+
4764
def load_user
4865
@current_api_user ||= Spree.user_class.find_by(spree_api_key: api_key.to_s)
4966
end

api/app/controllers/spree/api/line_items_controller.rb

+15-2
Original file line numberDiff line numberDiff line change
@@ -15,8 +15,10 @@ def create
1515
@line_item = @order.contents.add(
1616
variant,
1717
params[:line_item][:quantity] || 1,
18-
options: line_item_params[:options].to_h
18+
options: line_item_params[:options].to_h,
19+
**extract_metadata
1920
)
21+
2022
respond_with(@line_item, status: 201, default_template: :show)
2123
rescue ActiveRecord::RecordInvalid => error
2224
invalid_resource!(error.record)
@@ -56,10 +58,21 @@ def line_items_attributes
5658
{ line_items_attributes: {
5759
id: params[:id],
5860
quantity: params[:line_item][:quantity],
59-
options: line_item_params[:options] || {}
61+
options: line_item_params[:options] || {},
62+
**extract_metadata
6063
} }
6164
end
6265

66+
def extract_metadata
67+
metadata = { customer_metadata: line_item_params[:customer_metadata] }
68+
69+
if @current_user_roles&.include?("admin")
70+
metadata[:admin_metadata] = line_item_params[:admin_metadata]
71+
end
72+
73+
metadata
74+
end
75+
6376
def line_item_params
6477
params.require(:line_item).permit(permitted_line_item_attributes)
6578
end

api/app/controllers/spree/api/orders_controller.rb

+7
Original file line numberDiff line numberDiff line change
@@ -112,12 +112,19 @@ def mine
112112
def order_params
113113
if params[:order]
114114
normalize_params
115+
prevent_customer_metadata_update
115116
params.require(:order).permit(permitted_order_attributes)
116117
else
117118
{}
118119
end
119120
end
120121

122+
def prevent_customer_metadata_update
123+
return unless @order&.completed? && cannot?(:admin, Spree::Order)
124+
125+
params[:order].delete(:customer_metadata) if params[:order]
126+
end
127+
121128
def normalize_params
122129
if params[:order][:payments]
123130
payments_params = params[:order].delete(:payments)

api/app/helpers/spree/api/api_helpers.rb

+10
Original file line numberDiff line numberDiff line change
@@ -43,6 +43,16 @@ module ApiHelpers
4343
end
4444
end
4545

46+
Spree::Api::Config.metadata_api_parameters.each do |method_name, resource|
47+
define_method("#{method_name}_attributes") do
48+
authorized_attributes(resource, "#{method_name}_attributes")
49+
end
50+
end
51+
52+
def authorized_attributes(resource, config_attribute)
53+
can?(:admin, resource) ? Spree::Api::Config.public_send(config_attribute) + [:admin_metadata] : Spree::Api::Config.public_send(config_attribute)
54+
end
55+
4656
def required_fields_for(model)
4757
required_fields = model._validators.select do |_field, validations|
4858
validations.any? { |validation| validation.is_a?(ActiveModel::Validations::PresenceValidator) }

api/lib/spree/api_configuration.rb

+30-8
Original file line numberDiff line numberDiff line change
@@ -36,22 +36,44 @@ class ApiConfiguration < Preferences::Configuration
3636
:covered_by_store_credit, :display_total_applicable_store_credit,
3737
:order_total_after_store_credit, :display_order_total_after_store_credit,
3838
:total_applicable_store_credit, :display_total_available_store_credit,
39-
:display_store_credit_remaining_after_capture, :canceler_id
39+
:display_store_credit_remaining_after_capture, :canceler_id, :customer_metadata
4040
]
4141

42-
preference :line_item_attributes, :array, default: [:id, :quantity, :price, :variant_id]
42+
preference :line_item_attributes, :array, default: [:id, :quantity, :price, :variant_id, :customer_metadata]
43+
44+
# Spree::Api::Config.metadata_api_parameters contains the models
45+
# to which the admin_metadata attribute is added
46+
preference :metadata_api_parameters, :array, default: [
47+
[:order, 'Spree::Order'],
48+
[:customer_return, 'Spree::CustomerReturn'],
49+
[:payment, 'Spree::Payment'],
50+
[:return_authorization, 'Spree::ReturnAuthorization'],
51+
[:shipment, 'Spree::Shipment'],
52+
[:user, 'Spree.user_class'],
53+
[:line_item, 'Spree::LineItem']
54+
]
55+
56+
# Spree::Api::Config.metadata_permit_parameters contains the models
57+
# to which the admin_metadata attribute is permitted
58+
preference :metadata_permit_parameters, :array, default: [
59+
:Order,
60+
:CustomerReturn,
61+
:Payment,
62+
:ReturnAuthorization,
63+
:Shipment
64+
]
4365

4466
preference :option_type_attributes, :array, default: [:id, :name, :presentation, :position]
4567

4668
preference :payment_attributes, :array, default: [
4769
:id, :source_type, :source_id, :amount, :display_amount,
4870
:payment_method_id, :state, :avs_response, :created_at,
49-
:updated_at
71+
:updated_at, :customer_metadata
5072
]
5173

5274
preference :payment_method_attributes, :array, default: [:id, :name, :description]
5375

54-
preference :shipment_attributes, :array, default: [:id, :tracking, :tracking_url, :number, :cost, :shipped_at, :state]
76+
preference :shipment_attributes, :array, default: [:id, :tracking, :tracking_url, :number, :cost, :shipped_at, :state, :customer_metadata]
5577

5678
preference :taxonomy_attributes, :array, default: [:id, :name]
5779

@@ -81,11 +103,11 @@ class ApiConfiguration < Preferences::Configuration
81103
]
82104

83105
preference :customer_return_attributes, :array, default: [
84-
:id, :number, :stock_location_id, :created_at, :updated_at
106+
:id, :number, :stock_location_id, :created_at, :updated_at, :customer_metadata
85107
]
86108

87109
preference :return_authorization_attributes, :array, default: [
88-
:id, :number, :state, :order_id, :memo, :created_at, :updated_at
110+
:id, :number, :state, :order_id, :memo, :created_at, :updated_at, :customer_metadata
89111
]
90112

91113
preference :creditcard_attributes, :array, default: [
@@ -96,7 +118,7 @@ class ApiConfiguration < Preferences::Configuration
96118
:id, :month, :year, :cc_type, :last_digits, :name
97119
]
98120

99-
preference :user_attributes, :array, default: [:id, :email, :created_at, :updated_at]
121+
preference :user_attributes, :array, default: [:id, :email, :created_at, :updated_at, :customer_metadata]
100122

101123
preference :property_attributes, :array, default: [:id, :name, :presentation]
102124

@@ -132,7 +154,7 @@ def promotion_attributes=(value)
132154

133155
preference :store_credit_history_attributes, :array, default: [
134156
:display_amount, :display_user_total_amount, :display_action,
135-
:display_event_date, :display_remaining_amount
157+
:display_event_date, :display_remaining_amount, :customer_metadata
136158
]
137159

138160
preference :variant_property_attributes, :array, default: [

api/spec/requests/spree/api/customer_returns_spec.rb

+26-1
Original file line numberDiff line numberDiff line change
@@ -59,6 +59,14 @@ module Spree::Api
5959
expect(json_response).to have_attributes(attributes)
6060
end
6161

62+
it "can view admin_metadata" do
63+
customer_return = FactoryBot.create(:customer_return)
64+
65+
get spree.api_order_customer_return_path(customer_return.order, customer_return.id)
66+
67+
expect(json_response).to have_key('admin_metadata')
68+
end
69+
6270
it "can get a list of customer returns" do
6371
FactoryBot.create(:customer_return, shipped_order: order)
6472
FactoryBot.create(:customer_return, shipped_order: order)
@@ -97,7 +105,7 @@ module Spree::Api
97105
it "can learn how to create a new customer return" do
98106
get spree.new_api_order_customer_return_path(order)
99107

100-
expect(json_response["attributes"]).to eq(["id", "number", "stock_location_id", "created_at", "updated_at"])
108+
expect(json_response["attributes"]).to eq(["id", "number", "stock_location_id", "created_at", "updated_at", "customer_metadata", "admin_metadata"])
101109
end
102110

103111
it "can update a customer return" do
@@ -112,6 +120,23 @@ module Spree::Api
112120
expect(json_response["stock_location_id"]).to eq final_stock_location.id
113121
end
114122

123+
it "can update a customer return admin_metadata" do
124+
initial_stock_location = FactoryBot.create(:stock_location)
125+
final_stock_location = FactoryBot.create(:stock_location)
126+
customer_return = FactoryBot.create(:customer_return, stock_location: initial_stock_location)
127+
128+
put spree.api_order_customer_return_path(customer_return.order, customer_return.id),
129+
params: {
130+
order_id: customer_return.order.number,
131+
customer_return: { stock_location_id: final_stock_location.id, admin_metadata: { 'order_number' => 'PN345678' } }
132+
}
133+
134+
expect(response.status).to eq(200)
135+
expect(json_response).to have_attributes(attributes)
136+
expect(json_response["stock_location_id"]).to eq final_stock_location.id
137+
expect(json_response["admin_metadata"]).to eq({ 'order_number' => 'PN345678' })
138+
end
139+
115140
context "when creating new return items" do
116141
it "can create a new customer return" do
117142
stock_location = FactoryBot.create(:stock_location)

api/spec/requests/spree/api/line_items_spec.rb

+68-1
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ module Spree::Api
2424

2525
it "can learn how to create a new line item" do
2626
get spree.new_api_order_line_item_path(order)
27-
expect(json_response["attributes"]).to eq(["quantity", "price", "variant_id"])
27+
expect(json_response["attributes"]).to eq(["quantity", "price", "variant_id", "customer_metadata"])
2828
required_attributes = json_response["required_attributes"]
2929
expect(required_attributes).to include("quantity", "variant_id")
3030
end
@@ -95,6 +95,29 @@ module Spree::Api
9595
expect(response.status).to eq(201)
9696
end
9797

98+
it "cannot see admin_metadata" do
99+
post spree.api_order_line_items_path(order),
100+
params: {
101+
line_item: { variant_id: product.master.to_param, quantity: 1 },
102+
order_token: order.guest_token
103+
}
104+
105+
expect(response.status).to eq(201)
106+
expect(json_response).not_to have_key('admin_metadata')
107+
end
108+
109+
it "allows creating line item with customer metadata but not admin metadata" do
110+
post spree.api_order_line_items_path(order),
111+
params: {
112+
line_item: { variant_id: product.master.to_param,
113+
quantity: 1,
114+
customer_metadata: { "Company" => "Sample Company" } }
115+
}
116+
117+
expect(json_response['customer_metadata']).to eq({ "Company" => "Sample Company" })
118+
expect(json_response).not_to have_key('admin_metadata')
119+
end
120+
98121
it '#create calls #invalid_resource! if adding a line item fails validation' do
99122
allow_any_instance_of(Spree::LineItem).to receive(:valid?).and_return(false)
100123
expect_any_instance_of(Spree::Api::BaseController).to receive(:invalid_resource!).once
@@ -128,6 +151,22 @@ module Spree::Api
128151
expect(json_response["quantity"]).to eq(101)
129152
end
130153

154+
it "can update a line item customer metadata on the order" do
155+
line_item = order.line_items.first
156+
157+
put spree.api_order_line_item_path(order, line_item),
158+
params: { line_item: { quantity: 101, customer_metadata: { "adding_quantity" => "true" } } }
159+
160+
expect(response.status).to eq(200)
161+
162+
order.reload
163+
164+
expect(order.total).to eq(1010) # 10 original due to factory, + 1000 in this test
165+
expect(json_response).to have_attributes(attributes)
166+
expect(json_response["quantity"]).to eq(101)
167+
expect(json_response['customer_metadata']).to eq({ "adding_quantity" => "true" })
168+
end
169+
131170
it "can update a line item's options on the order" do
132171
without_partial_double_verification do
133172
expect_any_instance_of(Spree::LineItem).to receive(:some_option=).with("foobar")
@@ -189,6 +228,34 @@ module Spree::Api
189228
end
190229
end
191230

231+
context "as an admin" do
232+
sign_in_as_admin!
233+
234+
it "can see admin_metadata" do
235+
post spree.api_order_line_items_path(order),
236+
params: {
237+
line_item: { variant_id: product.master.to_param, quantity: 1 },
238+
order_token: order.guest_token
239+
}
240+
241+
expect(response.status).to eq(201)
242+
expect(json_response).to have_key('admin_metadata')
243+
end
244+
245+
it "allows creating line item with customer metadata and admin metadata" do
246+
post spree.api_order_line_items_path(order),
247+
params: {
248+
line_item: { variant_id: product.master.to_param,
249+
quantity: 1,
250+
customer_metadata: { "Company" => "Sample Company" },
251+
admin_metadata: { "discount" => "not_applicable" } }
252+
}
253+
254+
expect(json_response['customer_metadata']).to eq({ "Company" => "Sample Company" })
255+
expect(json_response['admin_metadata']).to eq({ "discount" => "not_applicable" })
256+
end
257+
end
258+
192259
context "as just another user" do
193260
before do
194261
user = create(:user)

0 commit comments

Comments
 (0)