You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
142 lines
4.9 KiB
142 lines
4.9 KiB
from django.contrib import admin
|
|
from django.utils.translation import gettext_lazy as _
|
|
from unfold.admin import ModelAdmin
|
|
from unfold.decorators import display
|
|
|
|
from apps.account.models.role import Role, PERMISSION_CATEGORIES
|
|
from utils.admin import project_admin_site
|
|
|
|
|
|
class RoleAdmin(ModelAdmin):
|
|
list_display = ('name', 'slug', 'is_default', 'is_system', 'users_count', 'updated_at')
|
|
list_filter = ('is_default', 'is_system')
|
|
search_fields = ('name', 'slug', 'description')
|
|
ordering = ('name',)
|
|
readonly_fields = ('created_at', 'updated_at')
|
|
|
|
fieldsets = (
|
|
(None, {
|
|
"fields": (
|
|
("name", "slug"),
|
|
("is_default", "is_system"),
|
|
"description",
|
|
),
|
|
}),
|
|
(_("Identity & Profiles"), {
|
|
"classes": ["tab"],
|
|
"fields": (
|
|
("is_searchable", "can_submit_verification"),
|
|
("can_view_full_profiles", "can_manage_institutions"),
|
|
),
|
|
}),
|
|
(_("Chat & Communications"), {
|
|
"classes": ["tab"],
|
|
"fields": (
|
|
("can_send_direct_messages", "can_create_group_chats"),
|
|
("can_start_video_calls", "can_moderate_chat"),
|
|
("is_chat_muted",),
|
|
),
|
|
}),
|
|
(_("CMS & Articles"), {
|
|
"classes": ["tab"],
|
|
"fields": (
|
|
("can_create_posts", "can_publish_posts_directly"),
|
|
("can_edit_own_posts", "can_delete_own_posts"),
|
|
("can_comment",),
|
|
),
|
|
}),
|
|
(_("LMS & Academics"), {
|
|
"classes": ["tab"],
|
|
"fields": (
|
|
("can_enroll_courses", "can_create_courses"),
|
|
("can_publish_courses", "can_issue_certificates"),
|
|
("can_grade_submissions", "has_premium_lms_access"),
|
|
),
|
|
}),
|
|
(_("Meetings"), {
|
|
"classes": ["tab"],
|
|
"fields": (
|
|
("can_request_meetings", "can_accept_meetings"),
|
|
),
|
|
}),
|
|
(_("Events"), {
|
|
"classes": ["tab"],
|
|
"fields": (
|
|
("can_register_events", "can_create_events"),
|
|
("can_publish_events", "can_checkin_attendees"),
|
|
("can_export_attendee_list",),
|
|
),
|
|
}),
|
|
(_("Community Projects"), {
|
|
"classes": ["tab"],
|
|
"fields": (
|
|
("can_volunteer", "can_create_projects"),
|
|
("can_manage_project_tasks", "can_approve_projects"),
|
|
),
|
|
}),
|
|
(_("Donations & Charity"), {
|
|
"classes": ["tab"],
|
|
"fields": (
|
|
("can_make_donations", "can_create_donation_campaigns"),
|
|
("can_view_donation_reports",),
|
|
),
|
|
}),
|
|
(_("Support & Tickets"), {
|
|
"classes": ["tab"],
|
|
"fields": (
|
|
("can_create_tickets", "can_reply_tickets"),
|
|
("can_manage_tickets",),
|
|
),
|
|
}),
|
|
(_("Dynamic Forms"), {
|
|
"classes": ["tab"],
|
|
"fields": (
|
|
("can_submit_forms", "can_create_forms"),
|
|
("can_export_form_data",),
|
|
),
|
|
}),
|
|
(_("Diplomacy & Institutional"), {
|
|
"classes": ["tab"],
|
|
"fields": (
|
|
("can_view_diplomatic_reports", "can_create_diplomatic_reports"),
|
|
),
|
|
}),
|
|
(_("Administration & Security"), {
|
|
"classes": ["tab"],
|
|
"fields": (
|
|
("can_access_admin_panel", "can_manage_users"),
|
|
("can_ban_users", "can_view_analytics"),
|
|
),
|
|
}),
|
|
(_("Metadata"), {
|
|
"classes": ["tab"],
|
|
"fields": (
|
|
("created_at", "updated_at"),
|
|
),
|
|
}),
|
|
)
|
|
|
|
@display(description=_("Assigned Users"))
|
|
def users_count(self, obj):
|
|
count = obj.users.count()
|
|
return f"{count} users"
|
|
|
|
def has_add_permission(self, request):
|
|
return bool(request.user and request.user.is_authenticated and (request.user.is_staff or request.user.is_superuser or request.user.can_access_admin_panel()))
|
|
|
|
def has_change_permission(self, request, obj=None):
|
|
return bool(request.user and request.user.is_authenticated and (request.user.is_staff or request.user.is_superuser or request.user.can_access_admin_panel()))
|
|
|
|
def has_delete_permission(self, request, obj=None):
|
|
if obj and getattr(obj, 'is_system', False):
|
|
return False # Protect core default roles from accidental deletion
|
|
return bool(request.user and request.user.is_authenticated and (request.user.is_staff or request.user.is_superuser or request.user.can_access_admin_panel()))
|
|
|
|
|
|
# Register in both default and custom admin sites
|
|
try:
|
|
admin.site.register(Role, RoleAdmin)
|
|
except admin.sites.AlreadyRegistered:
|
|
pass
|
|
|
|
project_admin_site.register(Role, RoleAdmin)
|