多用户场景下Organization销毁后的跳转处理方案咨询
问题:组织销毁后非操作用户的访问处理方案
模型关联结构
本应用采用用户通过memberships关联多个organizations的结构,模型代码如下:
class User < ApplicationRecord has_many :memberships, dependent: :destroy has_many :organizations, through: :memberships # ...其他代码 end class Membership < ApplicationRecord belongs_to :organization, touch: true belongs_to :user, counter_cache: true # ...其他代码 end class Organization < ApplicationRecord has_many :memberships, dependent: :destroy has_many :members, through: :memberships, source: :user # ...其他代码 end
当前权限与销毁逻辑
拥有owners属性(memberships中的属性)的用户可销毁Organization,销毁时会通过回调处理关联关系的销毁。
系统通过before_action检查用户与组织的关联是否存在,当用户访问已删除组织的URL时会被跳转,但当前处理方式存在疑问。
控制器的检查逻辑如下:
class Organizations::BaseController < ApplicationController before_action :restrict_user_by_role protected def restrict_user_by_role if organization_set? if !member? flash[:warning] = t("restricted_roles") redirect_to redirect_path elsif !current_membership.can_view_organization? flash[:warning] = t("restricted_roles") redirect_to redirect_path end else id = params[:parm_passed] unless Membership.current_member_check(id).exists? flash[:warning] = t("restricted_roles") refresh_or_redirect_to redirect_path return else organization = Organization.find_by(id: id) set_organization(organization) @organization = current_organization end end end end
注:organization_set?、current_membership、member?为每个请求设置的关注点;can_view_organization?、Membership.current_member_check(id).exists?为模型层面的权限检查逻辑。
核心疑问
- 当前用户销毁组织后会跟随控制器动作跳转,但其他用户访问已删除组织的URL时该如何处理?
- 是否应该让其他用户触发
before_action,由其统一处理跳转? - 能否用
after_destroy回调处理?但这似乎违反MVC模式,还需要判断用户是否处于该组织页面。 - 这个问题是否已有相关讨论或特定命名?
内容的提问来源于stack exchange,提问作者Chrismisballs
相关产品推荐
相关产品推荐

