feat: restrict thematic inspection access to admins and apply migration to reset non-admin permissions
This commit is contained in:
parent
bd1f084862
commit
b0a8af9a0f
2 changed files with 32 additions and 6 deletions
|
|
@ -0,0 +1,32 @@
|
||||||
|
# Generated by Django 6.0.7 on 2026-08-08
|
||||||
|
|
||||||
|
from django.db import migrations
|
||||||
|
|
||||||
|
|
||||||
|
def reset_can_inspect_permissions(apps, schema_editor):
|
||||||
|
UserThematics = apps.get_model('common', 'UserThematics')
|
||||||
|
|
||||||
|
for ut in UserThematics.objects.select_related('user_config__user').prefetch_related('user_config__roles').all():
|
||||||
|
uc = ut.user_config
|
||||||
|
if not uc or not uc.user:
|
||||||
|
continue
|
||||||
|
is_admin = bool(uc.user.is_superuser) or uc.roles.filter(name='admin').exists()
|
||||||
|
if not is_admin:
|
||||||
|
if ut.can_inspect:
|
||||||
|
ut.can_inspect = False
|
||||||
|
ut.save(update_fields=['can_inspect'])
|
||||||
|
else:
|
||||||
|
if not ut.can_inspect:
|
||||||
|
ut.can_inspect = True
|
||||||
|
ut.save(update_fields=['can_inspect'])
|
||||||
|
|
||||||
|
|
||||||
|
class Migration(migrations.Migration):
|
||||||
|
|
||||||
|
dependencies = [
|
||||||
|
('common', '0007_alter_userthematics_can_inspect'),
|
||||||
|
]
|
||||||
|
|
||||||
|
operations = [
|
||||||
|
migrations.RunPython(reset_can_inspect_permissions, reverse_code=migrations.RunPython.noop),
|
||||||
|
]
|
||||||
|
|
@ -467,9 +467,6 @@ class UserConfig(models.Model):
|
||||||
if self.user.is_superuser or self.has_role('admin'):
|
if self.user.is_superuser or self.has_role('admin'):
|
||||||
return Thematic.objects.all()
|
return Thematic.objects.all()
|
||||||
|
|
||||||
if not self.userthematics.exists():
|
|
||||||
return Thematic.objects.all()
|
|
||||||
|
|
||||||
return Thematic.objects.filter(
|
return Thematic.objects.filter(
|
||||||
userthematics__user_config=self,
|
userthematics__user_config=self,
|
||||||
userthematics__can_inspect=True
|
userthematics__can_inspect=True
|
||||||
|
|
@ -480,9 +477,6 @@ class UserConfig(models.Model):
|
||||||
if self.user.is_superuser or self.has_role('admin'):
|
if self.user.is_superuser or self.has_role('admin'):
|
||||||
return True
|
return True
|
||||||
|
|
||||||
if not self.userthematics.exists():
|
|
||||||
return True
|
|
||||||
|
|
||||||
return self.userthematics.filter(thematic=thematic, can_inspect=True).exists()
|
return self.userthematics.filter(thematic=thematic, can_inspect=True).exists()
|
||||||
|
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue