about summary refs log tree commit diff
path: root/app/controllers/api/web/push_subscriptions_controller.rb
blob: d8153e082feafdf2e2608492cf227fa93bcbb9e4 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
# frozen_string_literal: true

class Api::Web::PushSubscriptionsController < Api::Web::BaseController
  respond_to :json

  before_action :require_user!

  def create
    active_session = current_session

    unless active_session.web_push_subscription.nil?
      active_session.web_push_subscription.destroy!
      active_session.update!(web_push_subscription: nil)
    end

    # Mobile devices do not support regular notifications, so we enable push notifications by default
    alerts_enabled = active_session.detection.device.mobile? || active_session.detection.device.tablet?

    data = {
      alerts: {
        follow: alerts_enabled,
        favourite: alerts_enabled,
        reblog: alerts_enabled,
        mention: alerts_enabled,
        poll: alerts_enabled,
      },
    }

    data.deep_merge!(data_params) if params[:data]

    web_subscription = ::Web::PushSubscription.create!(
      endpoint: subscription_params[:endpoint],
      key_p256dh: subscription_params[:keys][:p256dh],
      key_auth: subscription_params[:keys][:auth],
      data: data,
      user_id: active_session.user_id,
      access_token_id: active_session.access_token_id
    )

    active_session.update!(web_push_subscription: web_subscription)

    render json: web_subscription, serializer: REST::WebPushSubscriptionSerializer
  end

  def update
    params.require([:id])

    web_subscription = ::Web::PushSubscription.find(params[:id])
    web_subscription.update!(data: data_params)

    render json: web_subscription, serializer: REST::WebPushSubscriptionSerializer
  end

  private

  def subscription_params
    @subscription_params ||= params.require(:subscription).permit(:endpoint, keys: [:auth, :p256dh])
  end

  def data_params
    @data_params ||= params.require(:data).permit(alerts: [:follow, :favourite, :reblog, :mention, :poll])
  end
end