Class: Bullet::Rack

Inherits:
Object
  • Object
show all
Includes:
Dependency
Defined in:
lib/bullet/rack.rb

Constant Summary collapse

NONCE_MATCHER =
/(script|style)-src .*'nonce-(?<nonce>[A-Za-z0-9+\/]+={0,2})'/

Instance Method Summary collapse

Methods included from Dependency

#active_record6_or_older?, #active_record70?, #active_record71?, #active_record72?, #active_record7?, #active_record80?, #active_record81?, #active_record8?, #active_record?, #active_record_version, #mongoid4x?, #mongoid5x?, #mongoid6x?, #mongoid7x?, #mongoid8x?, #mongoid9x?, #mongoid?, #mongoid_version

Constructor Details

#initialize(app) ⇒ Rack

Returns a new instance of Rack.



13
14
15
# File 'lib/bullet/rack.rb', line 13

def initialize(app)
  @app = app
end

Instance Method Details

#append_to_html_body(response_body, content) ⇒ Object



62
63
64
65
66
67
68
69
70
71
# File 'lib/bullet/rack.rb', line 62

def append_to_html_body(response_body, content)
  body = response_body.dup
  content = content.html_safe if content.respond_to?(:html_safe)
  if body.include?('</body>')
    position = body.rindex('</body>')
    body.insert(position, content)
  else
    body << content
  end
end

#call(env) ⇒ Object



17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
# File 'lib/bullet/rack.rb', line 17

def call(env)
  return @app.call(env) unless Bullet.enable?

  Bullet.start_request
  status, headers, response = @app.call(env)

  response_body = nil

  if Bullet.notification? || Bullet.always_append_html_body
    request = ::Rack::Request.new(env)
    if Bullet.inject_into_page? && !skip_html_injection?(request) && !file?(headers) && !sse?(headers) && !empty?(response) && status == 200
      if html_request?(headers, response)
        response_body = response_body(response)

        with_security_policy_nonce(headers) do |nonce|
          response_body = append_to_html_body(response_body, footer_note(nonce)) if Bullet.add_footer
          response_body = append_to_html_body(response_body, Bullet.gather_inline_notifications)
          if Bullet.add_footer && !Bullet.skip_http_headers
            response_body = append_to_html_body(response_body, xhr_script(nonce))
          end
        end

        headers['Content-Length'] = response_body.bytesize.to_s
      elsif !Bullet.skip_http_headers
        set_header(headers, 'X-bullet-footer-text', Bullet.footer_info.uniq) if Bullet.add_footer
        set_header(headers, 'X-bullet-console-text', Bullet.text_notifications) if Bullet.console_enabled?
      end
    end
    Bullet.perform_out_of_channel_notifications(env)
  end
  [status, headers, response_body ? [response_body] : response]
ensure
  Bullet.end_request
end

#empty?(response) ⇒ Boolean

fix issue if response's body is a Proc

Returns:

  • (Boolean)


53
54
55
56
57
58
59
60
# File 'lib/bullet/rack.rb', line 53

def empty?(response)
  # response may be ["Not Found"], ["Move Permanently"], etc, but
  # those should not happen if the status is 200
  return true if !response.respond_to?(:body) && !response.respond_to?(:first)

  body = response_body(response)
  body.nil? || body.empty?
end


73
74
75
# File 'lib/bullet/rack.rb', line 73

def footer_note(nonce = nil)
  %(<details id="bullet-footer" data-is-bullet-footer><summary>Bullet Warnings</summary><div>#{Bullet.footer_info.uniq.join('<br>')}#{footer_console_message(nonce)}</div>#{footer_style(nonce)}</details>)
end

Make footer styles work with ContentSecurityPolicy style-src as self



78
79
80
81
82
83
84
85
86
87
88
89
90
# File 'lib/bullet/rack.rb', line 78

def footer_style(nonce = nil)
  position_css = footer_position_css
  css = <<~CSS
    details#bullet-footer {cursor: pointer; position: fixed; #{position_css}; z-index: 9999; background: #fdf2f2; color: #9b1c1c; font-size: 12px; #{footer_border_radius}; border: 1px solid #9b1c1c;}
    details#bullet-footer summary {font-weight: 600; padding: 2px 8px;}
    details#bullet-footer div {padding: 8px; border-top: 1px solid #9b1c1c;}
  CSS
  if nonce
    %(<style type="text/css" nonce="#{nonce}">#{css}</style>)
  else
    %(<style type="text/css">#{css}</style>)
  end
end