|
91 | 91 | ) |
92 | 92 | from .patrons.search import PatronsSearch |
93 | 93 | from .permissions import ( |
94 | | - PatronOwnerPermission, |
| 94 | + PatronOwnerReadPermission, |
95 | 95 | authenticated_user_permission, |
96 | 96 | backoffice_permission, |
| 97 | + backoffice_read_permission, |
97 | 98 | views_permissions_factory, |
98 | 99 | ) |
99 | 100 | from .records.permissions import record_read_permission_factory |
@@ -395,8 +396,8 @@ def _(x): |
395 | 396 | default_media_type="application/json", |
396 | 397 | max_result_window=RECORDS_REST_MAX_RESULT_WINDOW, |
397 | 398 | error_handlers=dict(), |
398 | | - read_permission_factory_imp=backoffice_permission, |
399 | | - list_permission_factory_imp=backoffice_permission, |
| 399 | + read_permission_factory_imp=backoffice_read_permission, |
| 400 | + list_permission_factory_imp=backoffice_read_permission, |
400 | 401 | create_permission_factory_imp=backoffice_permission, |
401 | 402 | update_permission_factory_imp=backoffice_permission, |
402 | 403 | delete_permission_factory_imp=backoffice_permission, |
@@ -427,8 +428,8 @@ def _(x): |
427 | 428 | default_media_type="application/json", |
428 | 429 | max_result_window=RECORDS_REST_MAX_RESULT_WINDOW, |
429 | 430 | error_handlers=dict(), |
430 | | - read_permission_factory_imp=backoffice_permission, |
431 | | - list_permission_factory_imp=backoffice_permission, |
| 431 | + read_permission_factory_imp=backoffice_read_permission, |
| 432 | + list_permission_factory_imp=backoffice_read_permission, |
432 | 433 | create_permission_factory_imp=backoffice_permission, |
433 | 434 | update_permission_factory_imp=backoffice_permission, |
434 | 435 | delete_permission_factory_imp=backoffice_permission, |
@@ -522,8 +523,8 @@ def _(x): |
522 | 523 | default_media_type="application/json", |
523 | 524 | max_result_window=RECORDS_REST_MAX_RESULT_WINDOW, |
524 | 525 | error_handlers=dict(), |
525 | | - read_permission_factory_imp=backoffice_permission, |
526 | | - list_permission_factory_imp=backoffice_permission, |
| 526 | + read_permission_factory_imp=backoffice_read_permission, |
| 527 | + list_permission_factory_imp=backoffice_read_permission, |
527 | 528 | create_permission_factory_imp=backoffice_permission, |
528 | 529 | update_permission_factory_imp=backoffice_permission, |
529 | 530 | delete_permission_factory_imp=backoffice_permission, |
@@ -552,7 +553,7 @@ def _(x): |
552 | 553 | max_result_window=RECORDS_REST_MAX_RESULT_WINDOW, |
553 | 554 | error_handlers=dict(), |
554 | 555 | read_permission_factory_imp=deny_all, |
555 | | - list_permission_factory_imp=backoffice_permission, |
| 556 | + list_permission_factory_imp=backoffice_read_permission, |
556 | 557 | create_permission_factory_imp=deny_all, |
557 | 558 | update_permission_factory_imp=deny_all, |
558 | 559 | delete_permission_factory_imp=deny_all, |
@@ -584,7 +585,7 @@ def _(x): |
584 | 585 | default_media_type="application/json", |
585 | 586 | max_result_window=RECORDS_REST_MAX_RESULT_WINDOW, |
586 | 587 | error_handlers=dict(), |
587 | | - read_permission_factory_imp=PatronOwnerPermission, |
| 588 | + read_permission_factory_imp=PatronOwnerReadPermission, |
588 | 589 | # auth via search_factory |
589 | 590 | list_permission_factory_imp=authenticated_user_permission, |
590 | 591 | create_permission_factory_imp=authenticated_user_permission, |
|
0 commit comments