Skip to content
Open
Show file tree
Hide file tree
Changes from 1 commit
Commits
Show all changes
19 commits
Select commit Hold shift + click to select a range
d0dcd25
Rename TermsAndConditions entity URL accessor to document_url to pres…
Ioannis Sep 28, 2026
0729aef
Improve UI/UX for Terms and Conditions Review (CFM-501)
arlen Jun 15, 2026
ce38fbc
Move common code and language strings from TermsAgreer plugin to core…
arlen Jun 18, 2026
f32d86b
Further cleanup to Terms and Conditions (CFM-501)
arlen Jun 26, 2026
5eb95ff
Fix preview link to TandC Mostly Static Page (CFM-501)
arlen Jun 26, 2026
00e4f4d
Add JavaScript nonce to TandC script tag (CFM-501)
arlen Jun 28, 2026
082342e
Implement ajax UI for CO-level Terms and Conditions agreements (CFM-501)
arlen Jul 15, 2026
e41e2e0
Simplify TermsAndConditionsController::review() now that ajax is used…
arlen Aug 10, 2026
20d8802
Move ajax request check from maybeEnforceTAndCs() to beforeFilter() (…
arlen Aug 20, 2026
7e6ad79
Add inline-alert feature (CFM-501)
arlen Aug 27, 2026
4805e90
Improve T&C (and all) mobile rendering (CFM-501)
arlen Aug 30, 2026
3b62d0e
Ensure elements under #main can overflow when necessary (CFM-501)
arlen Sep 3, 2026
e0f62b8
Ensure hover state underlines ignore icons (CFM-501)
arlen Sep 4, 2026
f201720
Move TAndCEnrollmentModeEnum to core TAndCAgreementModeEnum (CFM-510)
arlen Sep 16, 2026
49258d9
Ensure TermsAndConditionsController includes vv_base_url (CFM-501)
arlen Sep 28, 2026
9edae67
Create separate API for recording T&C (CFM-553)
arlen Sep 29, 2026
1c24f70
Fix Mostly Static Page link from T&C index view (CFM-501)
arlen Sep 29, 2026
f0f5894
Use enumerations rather than direct values in TandC templates (CFM-501)
arlen Oct 1, 2026
2c4fdd4
Split recordTAndC into two separate actions, one for the Model Specif…
arlen Oct 2, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 4 additions & 9 deletions app/config/routes.php
Original file line number Diff line number Diff line change
Expand Up @@ -145,19 +145,14 @@ function (RouteBuilder $builder) {
['controller' => 'ApiV2', 'action' => 'generateApiKey', 'model' => 'api_users'])
->setPass(['id'])
->setPatterns(['id' => '[0-9]+']);
$builder->post(
'/terms_and_conditions/record/{id}',
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This route was in here twice (which is why the change may look a little more confusing than it is). The only actual change here is changing the terms_and_conditions/record action from 'recordTAndC' to 'xRecordTAndC'.

['controller' => 'ApiV2', 'action' => 'recordTAndC', 'model' => 'terms_and_conditions'])
->setPass(['id'])
->setPatterns(['id' => '[0-9]+']);
$builder->get(
'/people/pick',
['controller' => 'ApiV2', 'action' => 'pick', 'model' => 'people']);
$builder->post(
'/terms_and_conditions/record/{id}',
['controller' => 'ApiV2', 'action' => 'recordTAndC', 'model' => 'terms_and_conditions'])
['controller' => 'ApiV2', 'action' => 'xRecordTAndC', 'model' => 'terms_and_conditions'])
->setPass(['id'])
->setPatterns(['id' => '[0-9]+']);
$builder->get(
'/people/pick',
['controller' => 'ApiV2', 'action' => 'pick', 'model' => 'people']);
// These establish the usual CRUD options on all models:
$builder->delete(
'/{model}/{id}', ['controller' => 'ApiV2', 'action' => 'delete'])
Expand Down
17 changes: 17 additions & 0 deletions app/src/Controller/ApiV2Controller.php
Original file line number Diff line number Diff line change
Expand Up @@ -639,4 +639,21 @@ public function willHandleAuth(\Cake\Event\EventInterface $event): string
// Apply standard behavior
return $mode;
}

/* AJAX-SPECIFIC ACTIONS */
/* The following actions share a common purpose with the regular REST API actions above but require CoMember access
and must therefore only be exposed over ajax routes (within the user interface, using csrf tokens).
By convention, we prefix these actions with "x". */

/**
* Record a Terms and Conditions Agreement (via AJAX for CoMember).
*
* @since COmange Registry v5.3.0
* @param string $id Terms And Conditions ID
* @param bool $trusted If true, allow the request to assert Actor and Subject
*/

public function xRecordTAndC(string $id, bool $trusted=false) {
$this->recordTAndC($id, $trusted);
}
}
10 changes: 6 additions & 4 deletions app/src/Model/Table/TermsAndConditionsTable.php
Original file line number Diff line number Diff line change
Expand Up @@ -85,7 +85,7 @@ public function initialize(array $config): void {

$this->setPrimaryLink('co_id');
$this->setRequiresCO(true);
$this->setAllowLookupPrimaryLink(['agree', 'proxy', 'recordTAndC', 'revoke']);
$this->setAllowLookupPrimaryLink(['agree', 'proxy', 'recordTAndC', 'revoke', 'xRecordTAndC']);
$this->setAllowLookupRelatedPrimaryLink(['status' => ['person_id']]);
$this->setAllowUnkeyedPrimaryLink(['review']);

Expand Down Expand Up @@ -123,9 +123,11 @@ public function initialize(array $config): void {
// able to record the actor foreign key for audit purposes.
'proxy' => ['coAdmin'],
// 'recordTAndC' is used by ApiV2Controller
'recordTAndC' => ['platformAdmin', 'coAdmin', 'coMember'],
'recordTAndC' => ['platformAdmin', 'coAdmin'],
'revoke' => ['platformAdmin', 'coAdmin'],
'view' => ['platformAdmin', 'coAdmin']
'view' => ['platformAdmin', 'coAdmin'],
// 'xRecordTAndC' is used by ApiV2Controller for AJAX routes
'xRecordTAndC' => ['coMember']
],
// Actions that operate over a table (ie: do not require an $id)
'table' => [
Expand Down Expand Up @@ -292,7 +294,7 @@ public function status(int $personId): array {
break;
// Because of the Cake inflection bug in the find(), the related model
// is available via the incorrect property name
} elseif($a->terms_and_condition->terms_and_conditions_id == $t->id) {
} elseif($a->terms_and_condition?->terms_and_conditions_id == $t->id) {
// Agreement is to a previous version of the current T&C. Whether this is
// sufficient or not depends on the configuration on the _current_ T&C.

Expand Down