You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
61 lines
2.1 KiB
61 lines
2.1 KiB
from rest_framework.permissions import BasePermission, SAFE_METHODS
|
|
|
|
|
|
class IsAuthorOrEditorOrReadOnly(BasePermission):
|
|
"""
|
|
Read access is public.
|
|
Editing / deleting is restricted to the original author, an institution editor/admin,
|
|
or a platform administrator.
|
|
"""
|
|
def has_permission(self, request, view):
|
|
if request.method in SAFE_METHODS:
|
|
return True
|
|
return bool(request.user and request.user.is_authenticated and request.user.is_active)
|
|
|
|
def has_object_permission(self, request, view, obj):
|
|
if request.method in SAFE_METHODS:
|
|
return True
|
|
|
|
if not request.user or not request.user.is_authenticated:
|
|
return False
|
|
|
|
# Platform Super Admin & Regional Admin
|
|
if getattr(request.user, 'is_super_admin', False) or getattr(request.user, 'is_regional_admin', False):
|
|
return True
|
|
|
|
# Post author
|
|
if hasattr(obj, 'author') and obj.author == request.user:
|
|
return True
|
|
|
|
# Institution Editor / Admin
|
|
if hasattr(obj, 'institution') and obj.institution:
|
|
if obj.institution.is_editor(request.user):
|
|
return True
|
|
|
|
return False
|
|
|
|
|
|
class CanPublishPost(BasePermission):
|
|
"""
|
|
Allows creating / publishing content for authenticated users who are staff,
|
|
platform administrators, or institutional editors.
|
|
"""
|
|
def has_permission(self, request, view):
|
|
if request.method in SAFE_METHODS:
|
|
return True
|
|
|
|
if not request.user or not request.user.is_authenticated or not request.user.is_active:
|
|
return False
|
|
|
|
if (
|
|
request.user.is_staff or
|
|
getattr(request.user, 'is_super_admin', False) or
|
|
getattr(request.user, 'is_regional_admin', False) or
|
|
getattr(request.user, 'is_institution_admin', False) or
|
|
getattr(request.user, 'is_editor', False) or
|
|
request.user.institution_memberships.filter(role__in=['admin', 'editor']).exists()
|
|
):
|
|
return True
|
|
|
|
# By default, any authenticated registered user can draft/submit posts
|
|
return True
|