Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 11 additions & 2 deletions backend/gsr_booking/serializers.py
Original file line number Diff line number Diff line change
Expand Up @@ -127,13 +127,22 @@ def create(self, validated_data):

class SharedGSRBookingSerializer(serializers.ModelSerializer):

building = serializers.CharField(source="gsr.name")
is_valid = serializers.SerializerMethodField()
owner_name = serializers.SerializerMethodField()
gsr = GSRSerializer(read_only=True)

class Meta:
model = GSRBooking
fields = ["room_name", "building", "start", "end", "is_valid", "owner_name"]
fields = [
"booking_id",
"gsr",
"room_id",
"room_name",
"start",
"end",
"is_valid",
"owner_name",
]
Comment thread
minghansun1 marked this conversation as resolved.
read_only_fields = fields

def get_owner_name(self, obj):
Expand Down
24 changes: 20 additions & 4 deletions backend/tests/gsr_booking/test_share_codes.py
Original file line number Diff line number Diff line change
Expand Up @@ -117,13 +117,22 @@ def test_view_shared_booking_public_access(self):
payload = json.loads(response.content)

# Should only contain booking info and not owner info
print("Payload: ", payload)
Comment thread
minghansun1 marked this conversation as resolved.
self.assertIn("booking_id", payload)
self.assertIn("gsr", payload)
self.assertIn("lid", payload["gsr"])
self.assertIn("gid", payload["gsr"])
self.assertIn("name", payload["gsr"])
self.assertIn("kind", payload["gsr"])
self.assertIn("image_url", payload["gsr"])
self.assertIn("room_name", payload)
self.assertIn("building", payload)
self.assertIn("room_id", payload)
self.assertIn("start", payload)
self.assertIn("end", payload)
self.assertIn("is_valid", payload)
self.assertIn("owner_name", payload)
Comment thread
minghansun1 marked this conversation as resolved.
self.assertEqual(payload["room_name"], self.booking.room_name)
self.assertEqual(payload["building"], self.booking.gsr.name)
self.assertEqual(payload["gsr"]["name"], self.booking.gsr.name)
self.assertEqual(payload["is_valid"], True)

def test_view_shared_booking_invalid_code(self):
Expand Down Expand Up @@ -304,17 +313,24 @@ def test_shared_booking_serializer(self):
data = serializer.data

# Should have booking details
self.assertIn("booking_id", data)
self.assertIn("gsr", data)
self.assertIn("lid", data["gsr"])
self.assertIn("gid", data["gsr"])
self.assertIn("name", data["gsr"])
self.assertIn("kind", data["gsr"])
self.assertIn("image_url", data["gsr"])
self.assertIn("room_name", data)
self.assertIn("building", data)
self.assertIn("room_id", data)
self.assertIn("start", data)
self.assertIn("end", data)
self.assertIn("is_valid", data)
self.assertIn("owner_name", data)

# Should not have owner info
Copy link

Copilot AI Feb 10, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The test asserts owner_name is included, but immediately after it says "Should not have owner info". Clarify the intent by adjusting the comment to reflect what is actually forbidden (e.g., exclude user/owner objects but allow owner_name), or remove owner_name from the expected output if it shouldn't be public.

Suggested change
# Should not have owner info
# Should not expose owner-related model fields (only owner_name is allowed)

Copilot uses AI. Check for mistakes.
self.assertNotIn("user", data)
self.assertNotIn("owner", data)
self.assertNotIn("reservation", data)
self.assertNotIn("booking_id", data)

def test_is_valid_method(self):
share_code = GSRShareCode.objects.create(
Expand Down
Loading