2024-02-07 02:26:49 +01:00
|
|
|
# Copyright (C) 2018-2024 by BDE ENS Paris-Saclay
|
2020-03-18 14:42:35 +01:00
|
|
|
# SPDX-License-Identifier: GPL-3.0-or-later
|
|
|
|
|
|
|
|
from rest_framework.permissions import DjangoObjectPermissions
|
2020-03-25 00:39:40 +01:00
|
|
|
|
2020-03-24 22:13:15 +01:00
|
|
|
from .backends import PermissionBackend
|
2020-03-18 14:42:35 +01:00
|
|
|
|
|
|
|
SAFE_METHODS = ('HEAD', 'OPTIONS', )
|
|
|
|
|
|
|
|
|
|
|
|
class StrongDjangoObjectPermissions(DjangoObjectPermissions):
|
2020-03-20 15:58:14 +01:00
|
|
|
"""
|
|
|
|
Default DjangoObjectPermissions grant view permission to all.
|
|
|
|
This is a simple patch of this class that controls view access.
|
|
|
|
"""
|
|
|
|
|
2020-09-09 22:27:07 +02:00
|
|
|
# The queryset is filtered, and permissions are more powerful than a simple check than just "can view this model"
|
2020-03-18 14:42:35 +01:00
|
|
|
perms_map = {
|
2020-09-10 09:31:27 +02:00
|
|
|
'GET': ['%(app_label)s.view_%(model_name)s'],
|
2020-03-18 14:42:35 +01:00
|
|
|
'OPTIONS': [],
|
|
|
|
'HEAD': [],
|
|
|
|
'POST': ['%(app_label)s.add_%(model_name)s'],
|
2020-07-29 12:25:53 +02:00
|
|
|
'PUT': [], # ['%(app_label)s.change_%(model_name)s'],
|
|
|
|
'PATCH': [], # ['%(app_label)s.change_%(model_name)s'],
|
2020-03-18 14:42:35 +01:00
|
|
|
'DELETE': ['%(app_label)s.delete_%(model_name)s'],
|
|
|
|
}
|
|
|
|
|
|
|
|
def get_required_object_permissions(self, method, model_cls):
|
|
|
|
kwargs = {
|
|
|
|
'app_label': model_cls._meta.app_label,
|
|
|
|
'model_name': model_cls._meta.model_name
|
|
|
|
}
|
|
|
|
|
|
|
|
if method not in self.perms_map:
|
|
|
|
from rest_framework import exceptions
|
|
|
|
raise exceptions.MethodNotAllowed(method)
|
|
|
|
|
|
|
|
return [perm % kwargs for perm in self.perms_map[method]]
|
|
|
|
|
|
|
|
def has_object_permission(self, request, view, obj):
|
|
|
|
# authentication checks have already executed via has_permission
|
|
|
|
queryset = self._queryset(view)
|
|
|
|
model_cls = queryset.model
|
|
|
|
user = request.user
|
|
|
|
|
|
|
|
perms = self.get_required_object_permissions(request.method, model_cls)
|
2020-03-24 20:16:56 +01:00
|
|
|
# if not user.has_perms(perms, obj):
|
2021-06-15 14:40:32 +02:00
|
|
|
if not all(PermissionBackend.check_perm(request, perm, obj) for perm in perms):
|
2020-03-18 14:42:35 +01:00
|
|
|
# If the user does not have permissions we need to determine if
|
|
|
|
# they have read permissions to see 403, or not, and simply see
|
|
|
|
# a 404 response.
|
|
|
|
from django.http import Http404
|
|
|
|
|
|
|
|
if request.method in SAFE_METHODS:
|
|
|
|
# Read permissions already checked and failed, no need
|
|
|
|
# to make another lookup.
|
|
|
|
raise Http404
|
|
|
|
|
|
|
|
read_perms = self.get_required_object_permissions('GET', model_cls)
|
|
|
|
if not user.has_perms(read_perms, obj):
|
|
|
|
raise Http404
|
|
|
|
|
|
|
|
# Has read permissions.
|
|
|
|
return False
|
|
|
|
|
|
|
|
return True
|