/
authorization.py
executable file
·99 lines (73 loc) · 3.15 KB
/
authorization.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
from tastypie.authorization import Authorization
from tastypie.exceptions import Unauthorized
class UserObjectsOnlyAuthorization(Authorization):
def read_list(self, object_list, bundle):
# This assumes a ``QuerySet`` from ``ModelResource``.
return object_list.filter(user=bundle.request.user)
def read_detail(self, object_list, bundle):
# Is the requested object owned by the user?
return bundle.obj.user == bundle.request.user
def create_list(self, object_list, bundle):
# Assuming their auto-assigned to ``user``.
return object_list
def create_detail(self, object_list, bundle):
return bundle.obj.user == bundle.request.user
def update_list(self, object_list, bundle):
'''
allowed = []
# Since they may not all be saved, iterate over them.
for obj in object_list:
if obj.user == bundle.request.user:
allowed.append(obj)
return allowed
'''
return object_list.filter(user=bundle.request.user)
def update_detail(self, object_list, bundle):
return bundle.obj.user == bundle.request.user
def delete_list(self, object_list, bundle):
'''
allowed = []
# Since they may not all be saved, iterate over them.
for obj in object_list:
if obj.user == bundle.request.user:
allowed.append(obj)
return allowed
'''
return object_list.filter(user=bundle.request.user)
def delete_detail(self, object_list, bundle):
return bundle.obj.user == bundle.request.user
class MonthlyCategoryRestrictionAuthorization(Authorization):
def read_list(self, object_list, bundle):
return object_list.filter(baserestriction__user=bundle.request.user)
def read_detail(self, object_list, bundle):
# Is the requested object owned by the user?
return bundle.obj.baserestriction.user == bundle.request.user
def create_list(self, object_list, bundle):
# Assuming their auto-assigned to ``user``.
return object_list
def create_detail(self, object_list, bundle):
return bundle.obj.baserestriction.user == bundle.request.user
def update_list(self, object_list, bundle):
'''
allowed = []
# Since they may not all be saved, iterate over them.
for obj in object_list:
if obj.user == bundle.request.user:
allowed.append(obj)
return allowed
'''
return object_list.filter(baserestriction__user=bundle.request.user)
def update_detail(self, object_list, bundle):
return bundle.obj.baserestriction.user == bundle.request.user
def delete_list(self, object_list, bundle):
'''
allowed = []
# Since they may not all be saved, iterate over them.
for obj in object_list:
if obj.user == bundle.request.user:
allowed.append(obj)
return allowed
'''
return object_list.filter(baserestrictio__user=bundle.request.user)
def delete_detail(self, object_list, bundle):
return bundle.obj.baserestriction.user == bundle.request.user