mirror of
https://github.com/dartdavros/chatballs.git
synced 2026-10-08 10:24:59 +03:00
- DRF defaults: SessionAuthentication, IsAuthenticated, JSON-only render/parse
- shared api package: IsOwner permission (audits denials) and an exception
handler that flattens every error body to the {detail} SPA contract
- products views rewritten as APIView with permission_classes; manual JSON
parsing and auth checks removed (DRF parser returns 400 on bad JSON)
- response shapes and status codes preserved; product tests use DRF APIClient
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
30 lines
1.0 KiB
Python
30 lines
1.0 KiB
Python
from rest_framework.permissions import BasePermission
|
|
from rest_framework.request import Request
|
|
from rest_framework.views import APIView
|
|
|
|
from hub_platform.identity.audit import record_audit_event
|
|
from hub_platform.identity.models import AuditResult
|
|
from hub_platform.identity.permissions import is_owner
|
|
|
|
|
|
class IsOwner(BasePermission):
|
|
"""Allow only authenticated OWNER users; audit denials, as the legacy decorator did."""
|
|
|
|
message = "Owner role required"
|
|
|
|
def has_permission(self, request: Request, view: APIView) -> bool:
|
|
user = request.user
|
|
if not (user and user.is_authenticated):
|
|
return False
|
|
if is_owner(user):
|
|
return True
|
|
organization = getattr(getattr(user, "employee_profile", None), "organization", None)
|
|
record_audit_event(
|
|
action="identity.owner_permission_denied",
|
|
actor=user,
|
|
organization=organization,
|
|
result=AuditResult.DENIED,
|
|
request=request,
|
|
)
|
|
return False
|