from rest_framework.permissions import BasePermission, SAFE_METHODS class IsCourseInstructorOrAdmin(BasePermission): """ Grants permission to course creators, institution admins, regional admins, and super admins. Allows read-only access to anyone for safe methods. """ def has_permission(self, request, view): if request.method in SAFE_METHODS: return True return bool(request.user and request.user.is_authenticated and request.user.is_active) def has_object_permission(self, request, view, obj): if request.method in SAFE_METHODS: return True if not request.user or not request.user.is_authenticated: return False if getattr(request.user, 'is_super_admin', False) or getattr(request.user, 'is_regional_admin', False): return True # If obj is a Course if hasattr(obj, 'created_by') and obj.created_by == request.user: return True if hasattr(obj, 'institution') and obj.institution: if obj.institution.is_editor(request.user): return True # If obj is CourseModule or Lesson if hasattr(obj, 'course'): course = obj.course if course.created_by == request.user: return True if course.institution and course.institution.is_editor(request.user): return True if hasattr(obj, 'module'): course = obj.module.course if course.created_by == request.user: return True if course.institution and course.institution.is_editor(request.user): return True return False class IsEnrolledOrPreview(BasePermission): """ Allows access if the lesson is marked as preview, or if the user is enrolled, or course admin. """ def has_permission(self, request, view): return bool(request.user and request.user.is_authenticated and request.user.is_active)