为专家确定正确的范围连接

Identifying the right scope joins for pundit

我目前正在执行 pundit,我正在尝试确定用户是否具有管理员角色。

问题

我试图通过利用

之间的关系来避免在折扣和用户之间创建 join_table

--> 但是,我收到错误消息:undefined local variable or method `attraction' for #<DiscountPolicy::Scope:0x00007fa012ec6b70>

问题

我在想:

  1. 如果我想做的事情有可能,如果有的话
  2. 我怎样才能访问用户?

代码

折扣控制器

def index
    @user = current_user
    if params[:attraction_id]
      @attraction = Attraction.find(params[:attraction_id])
      @discounts = @attraction.discounts
      @discounts = policy_scope(@discounts)
    else
      @discounts = []
    end
end

折扣政策

class DiscountPolicy < ApplicationPolicy
  class Scope < Scope
    def resolve
      if user.admin?
        # scope.where(user: user)
        scope.joins(attraction: :discounts).where(discounts: { attraction_id: attraction.id }).joins(park: :attractions).where(attractions: { park_id: park.id }).joins(park: :user_parks).where(user_parks: { user_id: user.id })
      else
        raise Pundit::NotAuthorizedError
      end
    end
  end

  def index?
    user.admin?
  end
end

型号

class Discount < ApplicationRecord
  belongs_to :attraction
  has_many :reservations
end

class Attraction < ApplicationRecord
  belongs_to :park
  has_many :discounts, dependent: :destroy
  accepts_nested_attributes_for :discounts, allow_destroy: true
end

class Park < ApplicationRecord
  has_many :attractions, dependent: :destroy
  has_many :discounts, through: :attractions
  has_many :user_parks, dependent: :destroy
  has_many :users, through: :user_parks
  accepts_nested_attributes_for :users, allow_destroy: true, reject_if: ->(attrs) { attrs['email'].blank? || attrs['role'].blank?}
end

class UserPark < ApplicationRecord
  belongs_to :park
  belongs_to :user
end

class User < ApplicationRecord
  has_many :user_parks, dependent: :destroy
  has_many :parks, through: :user_parks
  enum role: [:owner, :admin, :employee, :accountant]
  after_initialize :set_default_role, :if => :new_record?

  def set_default_role
    self.role ||= :admin
  end

  devise :invitable, :database_authenticatable, :registerable,
         :recoverable, :rememberable, :validatable, :invitable
end

您需要嵌套关联连接。您的示波器应如下所示:

scope.joins(attraction: [park: :user_parks]).where(user_parks: { user_id: user.id })

你可以通过documentation来更好地理解。