| author | verrierj |
| Thu, 10 Nov 2011 14:47:16 +0100 | |
| changeset 237 | 2c37496369db |
| parent 235 | e5e5c4aeede9 |
| permissions | -rw-r--r-- |
| 237 | 1 |
from django.conf import settings |
2 |
from django.db.models import Manager |
|
|
235
e5e5c4aeede9
User can leave groups and code is cleaner when updating project permissions
verrierj
parents:
232
diff
changeset
|
3 |
from django.contrib.auth.models import Group |
| 237 | 4 |
from django.contrib.contenttypes.models import ContentType |
5 |
from guardian.shortcuts import assign, remove_perm, get_objects_for_user |
|
6 |
from guardian.core import ObjectPermissionChecker |
|
7 |
||
8 |
def protect_models(user): |
|
9 |
for cls in get_models_to_protect(): |
|
10 |
protect_model(cls, user) |
|
11 |
||
12 |
def unprotect_models(): |
|
13 |
for cls in get_models_to_protect(): |
|
14 |
unprotect_model(cls) |
|
15 |
||
16 |
def get_models_to_protect(): |
|
17 |
to_protect = [] |
|
18 |
||
19 |
for cls_name in settings.USE_GROUP_PERMISSIONS: |
|
20 |
cls_type = ContentType.objects.get(app_label="ldt_utils", model=cls_name.lower()) |
|
21 |
to_protect.append(cls_type.model_class()) |
|
22 |
return to_protect |
|
23 |
||
24 |
def protect_model(cls, user): |
|
25 |
cls.base_objects = cls.objects |
|
26 |
cls.objects = SafeManager(cls, user) |
|
27 |
||
28 |
cls.base_save = cls.save |
|
29 |
cls.save = save_security(user, cls.__name__.lower())(cls.save) |
|
30 |
||
31 |
def unprotect_model(cls): |
|
32 |
if hasattr(cls, 'base_objects'): |
|
33 |
cls.objects = cls.base_objects |
|
34 |
cls.save = cls.base_save |
|
35 |
del cls.base_objects |
|
36 |
del cls.base_save |
|
37 |
||
38 |
class SafeManager(Manager): |
|
39 |
||
40 |
def __init__(self, cls, user=None): |
|
41 |
super(SafeManager, self).__init__() |
|
42 |
self.model_name = cls.__name__.lower() |
|
43 |
self.model = cls |
|
44 |
if user: |
|
45 |
self.check_perm_for(user) |
|
46 |
else: |
|
47 |
self.user = None |
|
48 |
self.checker = None |
|
49 |
||
50 |
def check_perm_for(self, user): |
|
51 |
self.user = user |
|
52 |
self.checker = ObjectPermissionChecker(self.user) |
|
53 |
||
54 |
def stop_checking(self): |
|
55 |
self.user = None |
|
56 |
self.checker = None |
|
57 |
||
58 |
def has_user(self): |
|
59 |
return self.user != None |
|
60 |
||
61 |
def get_query_set(self): |
|
62 |
if not self.has_user(): |
|
63 |
raise AttributeError("A user has to be chosen to check permissions.") |
|
64 |
||
65 |
user_objects = get_objects_for_user(self.user, 'ldt_utils.view_%s' % self.model_name) |
|
66 |
||
67 |
return user_objects |
|
68 |
||
69 |
def save_security(user, cls_name): |
|
70 |
def wrapper(func): |
|
71 |
def wrapped(self, *args, **kwargs): |
|
72 |
||
73 |
if self.pk and not user.has_perm('change_%s' % cls_name, self): |
|
74 |
raise AttributeError('User %s is not allowed to change object %s' % (user, self)) |
|
75 |
||
76 |
return func(self, *args, **kwargs) |
|
77 |
return wrapped |
|
78 |
||
79 |
return wrapper |
|
|
235
e5e5c4aeede9
User can leave groups and code is cleaner when updating project permissions
verrierj
parents:
232
diff
changeset
|
80 |
|
|
e5e5c4aeede9
User can leave groups and code is cleaner when updating project permissions
verrierj
parents:
232
diff
changeset
|
81 |
def assign_project_to_groups(project, permissions): |
|
e5e5c4aeede9
User can leave groups and code is cleaner when updating project permissions
verrierj
parents:
232
diff
changeset
|
82 |
for elem in permissions: |
|
e5e5c4aeede9
User can leave groups and code is cleaner when updating project permissions
verrierj
parents:
232
diff
changeset
|
83 |
group = Group.objects.get(id=elem['group']) |
|
e5e5c4aeede9
User can leave groups and code is cleaner when updating project permissions
verrierj
parents:
232
diff
changeset
|
84 |
if elem['share']: |
|
e5e5c4aeede9
User can leave groups and code is cleaner when updating project permissions
verrierj
parents:
232
diff
changeset
|
85 |
assign('view_project', group, project) |
|
e5e5c4aeede9
User can leave groups and code is cleaner when updating project permissions
verrierj
parents:
232
diff
changeset
|
86 |
if elem['perms'] == 'write': |
|
e5e5c4aeede9
User can leave groups and code is cleaner when updating project permissions
verrierj
parents:
232
diff
changeset
|
87 |
assign('change_project', group, project) |
|
e5e5c4aeede9
User can leave groups and code is cleaner when updating project permissions
verrierj
parents:
232
diff
changeset
|
88 |
else: |
|
e5e5c4aeede9
User can leave groups and code is cleaner when updating project permissions
verrierj
parents:
232
diff
changeset
|
89 |
remove_perm('view_project', group, project) |
| 237 | 90 |
remove_perm('change_project', group, project) |