|
1 | 1 | from django_filters import rest_framework as filters |
2 | 2 | from rest_framework import serializers, viewsets |
3 | | -from rest_framework.permissions import AllowAny |
| 3 | +from rest_framework.decorators import action |
| 4 | +from rest_framework.permissions import AllowAny, BasePermission, IsAuthenticated |
| 5 | +from rest_framework.request import Request |
| 6 | +from rest_framework.response import Response |
| 7 | +from rest_framework.views import APIView |
4 | 8 |
|
5 | | -from shared.models import NixpkgsIssue |
| 9 | +from shared.auth import user_can_edit_suggestion |
| 10 | +from shared.models import CVEDerivationClusterProposal, NixpkgsIssue |
6 | 11 |
|
7 | 12 |
|
8 | 13 | class StringInFilter(filters.BaseInFilter, filters.CharFilter): |
@@ -39,3 +44,26 @@ class Meta: |
39 | 44 | "suggestion__cve", |
40 | 45 | ).all() |
41 | 46 | serializer_class = Serializer |
| 47 | + |
| 48 | + |
| 49 | +class CanEditSuggestion(BasePermission): |
| 50 | + def has_permission(self, request: Request, view: APIView) -> bool: # pyright: ignore[reportIncompatibleMethodOverride] |
| 51 | + return user_can_edit_suggestion(request.user) |
| 52 | + |
| 53 | + |
| 54 | +class SuggestionViewSet(viewsets.GenericViewSet): |
| 55 | + class StatusSerializer(serializers.ModelSerializer): |
| 56 | + class Meta: |
| 57 | + model = CVEDerivationClusterProposal |
| 58 | + extra_kwargs = {"status": {"required": True}} |
| 59 | + fields = ["status", "rejection_reason", "comment"] |
| 60 | + |
| 61 | + queryset = CVEDerivationClusterProposal.objects.all() |
| 62 | + permission_classes = [IsAuthenticated, CanEditSuggestion] |
| 63 | + |
| 64 | + @action(detail=True, methods=["post"], serializer_class=StatusSerializer) |
| 65 | + def change_status(self, request: Request, pk: int) -> Response: |
| 66 | + serializer = self.get_serializer(instance=self.get_object(), data=request.data) |
| 67 | + serializer.is_valid(raise_exception=True) |
| 68 | + serializer.save() |
| 69 | + return Response(serializer.data) |
0 commit comments