3 ms·
Hmm. I usually find that when I'm surprised by something in Ruby/Rails, as I come to an understanding of what's going on, it's an "of course that's how it works
by RangerScience 4y ago
Hmm. I usually find that when I'm surprised by something in Ruby/Rails, as I come to an understanding of what's going on, it's an "of course that's how it works" situation.
I suspect, but don't know, that ActiveStorage works on top of serving assets from the `public/` folder, so it makes sense that it's skipping controller `before_actions`. And, I guess it does makes sense that it's skipping those, since there's also otherwise not a controller action to write to handle serving the asset.
Hmm - so the usual flow would be that the controller renders something that includes the asset URL (HTML or JSON), and then the page loads the asset. The URL will be "security through obscurity".
I guess, if I wanted to change this behavior, I'd want a gem (or a quick pattern) that provides a controller that'll actually serve the asset (and not just the asset URL), which in turn would allow me to plug in actions, etc; then you disable the default routes, and you're done.