You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
24 lines
946 B
24 lines
946 B
from rest_framework.permissions import BasePermission
|
|
from apps.chat.models.chat import ChatRoom, ChatMessage
|
|
|
|
|
|
class IsRoomParticipant(BasePermission):
|
|
"""
|
|
Ensures that only authorized participants (individual user or member of a participating institution)
|
|
can view room messages, send messages, or receive read receipts.
|
|
"""
|
|
def has_permission(self, request, view):
|
|
return bool(request.user and request.user.is_authenticated and request.user.is_active)
|
|
|
|
def has_object_permission(self, request, view, obj):
|
|
if not request.user or not request.user.is_authenticated:
|
|
return False
|
|
|
|
if getattr(request.user, 'is_super_admin', False) or getattr(request.user, 'is_regional_admin', False):
|
|
return True
|
|
|
|
room = obj if isinstance(obj, ChatRoom) else getattr(obj, 'room', None)
|
|
if not room:
|
|
return False
|
|
|
|
return room.is_participant(request.user)
|