feat: restrict thematic inspection access to admins and apply migration to reset non-admin permissions
This commit is contained in:
parent
bd1f084862
commit
b0a8af9a0f
2 changed files with 32 additions and 6 deletions
|
|
@ -0,0 +1,32 @@
|
|||
# Generated by Django 6.0.7 on 2026-08-08
|
||||
|
||||
from django.db import migrations
|
||||
|
||||
|
||||
def reset_can_inspect_permissions(apps, schema_editor):
|
||||
UserThematics = apps.get_model('common', 'UserThematics')
|
||||
|
||||
for ut in UserThematics.objects.select_related('user_config__user').prefetch_related('user_config__roles').all():
|
||||
uc = ut.user_config
|
||||
if not uc or not uc.user:
|
||||
continue
|
||||
is_admin = bool(uc.user.is_superuser) or uc.roles.filter(name='admin').exists()
|
||||
if not is_admin:
|
||||
if ut.can_inspect:
|
||||
ut.can_inspect = False
|
||||
ut.save(update_fields=['can_inspect'])
|
||||
else:
|
||||
if not ut.can_inspect:
|
||||
ut.can_inspect = True
|
||||
ut.save(update_fields=['can_inspect'])
|
||||
|
||||
|
||||
class Migration(migrations.Migration):
|
||||
|
||||
dependencies = [
|
||||
('common', '0007_alter_userthematics_can_inspect'),
|
||||
]
|
||||
|
||||
operations = [
|
||||
migrations.RunPython(reset_can_inspect_permissions, reverse_code=migrations.RunPython.noop),
|
||||
]
|
||||
|
|
@ -467,9 +467,6 @@ class UserConfig(models.Model):
|
|||
if self.user.is_superuser or self.has_role('admin'):
|
||||
return Thematic.objects.all()
|
||||
|
||||
if not self.userthematics.exists():
|
||||
return Thematic.objects.all()
|
||||
|
||||
return Thematic.objects.filter(
|
||||
userthematics__user_config=self,
|
||||
userthematics__can_inspect=True
|
||||
|
|
@ -480,9 +477,6 @@ class UserConfig(models.Model):
|
|||
if self.user.is_superuser or self.has_role('admin'):
|
||||
return True
|
||||
|
||||
if not self.userthematics.exists():
|
||||
return True
|
||||
|
||||
return self.userthematics.filter(thematic=thematic, can_inspect=True).exists()
|
||||
|
||||
|
||||
|
|
|
|||
Loading…
Reference in a new issue