|
1 | 1 | from django.contrib.auth import get_user_model |
| 2 | +from django.shortcuts import get_object_or_404 |
2 | 3 | from rest_framework import permissions |
3 | | -from rest_framework.exceptions import NotFound |
4 | 4 | from rest_framework.permissions import SAFE_METHODS |
5 | 5 |
|
6 | 6 | from partner_programs.models import PartnerProgram |
|
10 | 10 |
|
11 | 11 |
|
12 | 12 | class IsNewsCreatorOrReadOnly(permissions.BasePermission): |
13 | | - def has_object_permission(self, request, view, obj): |
14 | | - """ |
15 | | - read/update/delete permission |
16 | | - currently can only be updated/deleted in admin panel |
17 | | - """ |
| 13 | + def has_permission(self, request, view): |
18 | 14 | if request.method in SAFE_METHODS: |
19 | 15 | return True |
20 | | - if ( |
21 | | - isinstance(obj.content_object, Project) |
22 | | - and obj.content_object.leader == request.user |
23 | | - ): |
24 | | - return True |
25 | | - if isinstance(obj.content_object, User) and obj.content_object == request.user: |
26 | | - return True |
27 | | - if isinstance(obj.content_object, PartnerProgram): |
28 | | - # TODO: implement |
29 | | - pass |
| 16 | + |
| 17 | + if view.kwargs.get("project_pk"): |
| 18 | + project = get_object_or_404(Project, pk=view.kwargs["project_pk"]) |
| 19 | + return request.user == project.leader |
| 20 | + |
| 21 | + if view.kwargs.get("user_pk"): |
| 22 | + user = get_object_or_404(User, pk=view.kwargs["user_pk"]) |
| 23 | + return request.user == user |
| 24 | + |
| 25 | + if view.kwargs.get("partnerprogram_pk"): |
| 26 | + program = get_object_or_404( |
| 27 | + PartnerProgram, pk=view.kwargs["partnerprogram_pk"] |
| 28 | + ) |
| 29 | + return program.is_manager(request.user) |
| 30 | + |
30 | 31 | return False |
31 | 32 |
|
32 | | - def has_permission(self, request, view): |
33 | | - """ |
34 | | - Creation permission |
35 | | - Currently can only be created via admin panel |
36 | | - """ |
| 33 | + def has_object_permission(self, request, view, obj): |
37 | 34 | if request.method in SAFE_METHODS: |
38 | 35 | return True |
39 | 36 |
|
40 | | - if view.kwargs.get("project_pk"): |
41 | | - try: |
42 | | - project = Project.objects.get(pk=view.kwargs["project_pk"]) |
43 | | - if request.method in SAFE_METHODS or (request.user == project.leader): |
44 | | - return True |
45 | | - except Project.DoesNotExist: |
46 | | - raise NotFound |
| 37 | + if isinstance(obj.content_object, Project): |
| 38 | + return obj.content_object.leader == request.user |
47 | 39 |
|
48 | | - if view.kwargs.get("user_pk"): |
49 | | - try: |
50 | | - user = User.objects.get(pk=view.kwargs["user_pk"]) |
51 | | - if request.method in SAFE_METHODS or (request.user == user): |
52 | | - return True |
53 | | - except User.DoesNotExist: |
54 | | - raise NotFound |
| 40 | + if isinstance(obj.content_object, User): |
| 41 | + return obj.content_object == request.user |
| 42 | + |
| 43 | + if isinstance(obj.content_object, PartnerProgram): |
| 44 | + return obj.content_object.is_manager(request.user) |
55 | 45 |
|
56 | 46 | return False |
0 commit comments