You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
 
 

55 lines
2.0 KiB

from rest_framework.permissions import BasePermission, SAFE_METHODS
class IsCourseInstructorOrAdmin(BasePermission):
"""
Grants permission to course creators, institution admins, regional admins, and super admins.
Allows read-only access to anyone for safe methods.
"""
def has_permission(self, request, view):
if request.method in SAFE_METHODS:
return True
return bool(request.user and request.user.is_authenticated and request.user.is_active)
def has_object_permission(self, request, view, obj):
if request.method in SAFE_METHODS:
return True
if not request.user or not request.user.is_authenticated:
return False
if getattr(request.user, 'is_super_admin', False) or getattr(request.user, 'is_regional_admin', False):
return True
# If obj is a Course
if hasattr(obj, 'created_by') and obj.created_by == request.user:
return True
if hasattr(obj, 'institution') and obj.institution:
if obj.institution.is_editor(request.user):
return True
# If obj is CourseModule or Lesson
if hasattr(obj, 'course'):
course = obj.course
if course.created_by == request.user:
return True
if course.institution and course.institution.is_editor(request.user):
return True
if hasattr(obj, 'module'):
course = obj.module.course
if course.created_by == request.user:
return True
if course.institution and course.institution.is_editor(request.user):
return True
return False
class IsEnrolledOrPreview(BasePermission):
"""
Allows access if the lesson is marked as preview, or if the user is enrolled, or course admin.
"""
def has_permission(self, request, view):
return bool(request.user and request.user.is_authenticated and request.user.is_active)