You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
102 lines
3.0 KiB
102 lines
3.0 KiB
from rest_framework.permissions import BasePermission, SAFE_METHODS
|
|
|
|
|
|
class IsActiveUser(BasePermission):
|
|
def has_permission(self, request, view):
|
|
return bool(request.user and request.user.is_authenticated and request.user.is_active)
|
|
|
|
|
|
class IsSuperAdmin(BasePermission):
|
|
"""
|
|
Allows access strictly to super administrators.
|
|
"""
|
|
def has_permission(self, request, view):
|
|
return bool(
|
|
request.user and
|
|
request.user.is_authenticated and
|
|
request.user.is_active and
|
|
request.user.is_super_admin
|
|
)
|
|
|
|
|
|
class IsRegionalAdmin(BasePermission):
|
|
"""
|
|
Allows access to regional administrators and super administrators.
|
|
"""
|
|
def has_permission(self, request, view):
|
|
return bool(
|
|
request.user and
|
|
request.user.is_authenticated and
|
|
request.user.is_active and
|
|
request.user.is_regional_admin
|
|
)
|
|
|
|
|
|
class IsInstitutionAdmin(BasePermission):
|
|
"""
|
|
Allows access to institution administrators, regional admins, and super admins.
|
|
"""
|
|
def has_permission(self, request, view):
|
|
return bool(
|
|
request.user and
|
|
request.user.is_authenticated and
|
|
request.user.is_active and
|
|
request.user.is_institution_admin
|
|
)
|
|
|
|
|
|
class IsEditorOrAbove(BasePermission):
|
|
"""
|
|
Allows access to content editors, institution admins, regional admins, and super admins.
|
|
"""
|
|
def has_permission(self, request, view):
|
|
return bool(
|
|
request.user and
|
|
request.user.is_authenticated and
|
|
request.user.is_active and
|
|
request.user.is_editor
|
|
)
|
|
|
|
|
|
class IsDocumentOwnerOrAdmin(BasePermission):
|
|
"""
|
|
Object-level permission allowing the document owner or platform admin to read/modify.
|
|
"""
|
|
def has_permission(self, request, view):
|
|
return bool(request.user and request.user.is_authenticated and request.user.is_active)
|
|
|
|
def has_object_permission(self, request, view, obj):
|
|
if request.user.is_regional_admin:
|
|
return True
|
|
return obj.user == request.user
|
|
|
|
|
|
class IsPanelUser(BasePermission):
|
|
"""
|
|
Allows access to administrative panel users.
|
|
"""
|
|
def has_permission(self, request, view):
|
|
return bool(
|
|
request.user and
|
|
request.user.is_authenticated and
|
|
request.user.is_active and
|
|
request.user.can_access_admin_panel()
|
|
)
|
|
|
|
|
|
class IsSuperAdminOrReadOnlyForProfessor(BasePermission):
|
|
"""
|
|
Allows full read-write access to super admins and admins,
|
|
but only read-only (GET, HEAD, OPTIONS) access to professors.
|
|
"""
|
|
def has_permission(self, request, view):
|
|
if not request.user or not request.user.is_authenticated or not request.user.is_active:
|
|
return False
|
|
|
|
if request.user.is_admin_panel_user():
|
|
return True
|
|
|
|
if request.user.is_professor_panel_user():
|
|
return request.method in SAFE_METHODS
|
|
|
|
return False
|