Restrict render profiling to non-prod

This commit is contained in:
Daniel Schädler 2026-04-15 10:02:26 +02:00
parent 8d72b863d0
commit 43aa0e11ba
3 changed files with 26 additions and 1 deletions

View File

@ -143,7 +143,7 @@ class TournamentsController < ApplicationController
end
def set_tournament_for_show
profiling = RequestProfiling.new(enabled: show_params.fetch(:profile, 'false') == 'true')
profiling = RequestProfiling.new(enabled: profiling_requested?)
@tournament = profiling.measure('load_tournament') do
Tournament.includes(
:user,
@ -168,6 +168,10 @@ class TournamentsController < ApplicationController
params.permit(:simple, :profile)
end
def profiling_requested?
!Rails.env.production? && show_params.fetch(:profile, 'false') == 'true'
end
def tournament_params
params.slice(:name, :description, :public, :teams, :group_stage, :playoff_teams_amount).permit!
end

View File

@ -118,6 +118,26 @@ RSpec.describe TournamentsController, type: :controller do
expect(body[:teams]).to be_nil
end
end
context 'with profile=true parameter' do
it 'adds profiling headers outside production' do
get :show, params: { id: @tournament.to_param, profile: 'true' }
expect(response.headers['Server-Timing']).to include('load_tournament')
expect(response.headers['Server-Timing']).to include('serialize_tournament')
expect(response.headers['X-Turniere-Profile']).to include('tournament.show')
end
it 'ignores profiling in production' do
allow(Rails).to receive(:env).and_return(ActiveSupport::StringInquirer.new('production'))
get :show, params: { id: @tournament.to_param, profile: 'true' }
expect(response.headers['Server-Timing']).to be_nil
expect(response.headers['X-Turniere-Profile']).to be_nil
end
end
context 'on a group stage tournament' do
before do
@group_stage_tournament = create(:group_stage_tournament)

View File

@ -39,5 +39,6 @@ Observed and covered by `spec/e2e/http/tournament_rendering_spec.rb` and `script
- large group-stage tournaments are created through the same authenticated HTTP `POST /tournaments` flow as normal clients
- tournament show profiling is requested via `GET /tournaments/:id?profile=true`
- profiling is intentionally non-production-only; local/test flows may use it, production should ignore it
- the backend returns `Server-Timing` and `X-Turniere-Profile` headers with `load_tournament` and `serialize_tournament`
- current locked shapes are `8x4`, `64x6`, and `4x32`