You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
62 lines
2.1 KiB
62 lines
2.1 KiB
from rest_framework.permissions import BasePermission, SAFE_METHODS
|
|
from apps.projects.models.project import Project, KanbanColumn, KanbanTask, ProjectDocument
|
|
|
|
|
|
class IsProjectParticipantOrReadOnly(BasePermission):
|
|
"""
|
|
Read access is open to all.
|
|
Write/modify access is restricted to:
|
|
- Platform Super / Regional Admins
|
|
- Owner Institution Admins & Editors
|
|
- Collaborating Institution Admins & Editors
|
|
"""
|
|
def has_permission(self, request, view):
|
|
if request.method in SAFE_METHODS:
|
|
return True
|
|
return bool(request.user and request.user.is_authenticated and request.user.is_active)
|
|
|
|
def has_object_permission(self, request, view, obj):
|
|
if request.method in SAFE_METHODS:
|
|
return True
|
|
|
|
if not request.user or not request.user.is_authenticated:
|
|
return False
|
|
|
|
if getattr(request.user, 'is_super_admin', False) or getattr(request.user, 'is_regional_admin', False):
|
|
return True
|
|
|
|
# Resolve the parent Project object
|
|
project = None
|
|
if isinstance(obj, Project):
|
|
project = obj
|
|
elif hasattr(obj, 'project'):
|
|
project = obj.project
|
|
|
|
if not project:
|
|
return False
|
|
|
|
return project.can_user_edit(request.user)
|
|
|
|
|
|
class CanCreateProject(BasePermission):
|
|
"""
|
|
Permits creating projects for authenticated users who belong to an institution
|
|
or hold platform administrative roles.
|
|
"""
|
|
def has_permission(self, request, view):
|
|
if request.method in SAFE_METHODS:
|
|
return True
|
|
|
|
if not request.user or not request.user.is_authenticated or not request.user.is_active:
|
|
return False
|
|
|
|
if (
|
|
getattr(request.user, 'is_super_admin', False) or
|
|
getattr(request.user, 'is_regional_admin', False) or
|
|
getattr(request.user, 'is_institution_admin', False) or
|
|
getattr(request.user, 'is_editor', False) or
|
|
request.user.institution_memberships.filter(role__in=['admin', 'editor']).exists()
|
|
):
|
|
return True
|
|
|
|
return True
|