* chore: removed viewer role * chore: indentation * chore: remove viewer role * chore: handled user permissions in store * chore: updated the migration file * chore: updated user permissions store * chore: removed the owner key * chore: code refactor * chore: code refactor * chore: code refactor * chore: code refactor * chore: code refactor * fix: build error * chore: updated user permissions store and handled the permissions fetch in workspace and project wrappers * chore: package user enum updated * chore: user permission updated * chore: user permission updated * chore: resolved build errors * chore: resolved build error * chore: resolved build errors * chore: computedFn deep map issue resolved * chore: added back migration * chore: added new field in project table * chore: removed member store in users * chore: private project for admins * chore: workspace notification access validation updated * fix: workspace member edit option * fix: project intake permission validation updated * chore: workspace export settings permission updated * chore: guest_view_all_issues added * chore: guest_view_all_issues added * chore: key changed for guest access * chore: added validation for individual issues * chore: changed the dashboard issues count * chore: added new yarn file * chore: modified yarn file * chore: project page permission updated * chore: project page permission updated * chore: member setting ux updated * chore: build error * fix: yarn lock * fix: build error --------- Co-authored-by: gurusainath <gurusainath007@gmail.com> Co-authored-by: Anmol Singh Bhatia <anmolsinghbhatia@plane.so>
60 lines
2 KiB
Python
60 lines
2 KiB
Python
from plane.db.models import WorkspaceMember, ProjectMember
|
|
from functools import wraps
|
|
from rest_framework.response import Response
|
|
from rest_framework import status
|
|
|
|
from enum import Enum
|
|
|
|
class ROLE(Enum):
|
|
ADMIN = 20
|
|
MEMBER = 15
|
|
GUEST = 5
|
|
|
|
|
|
def allow_permission(allowed_roles, level="PROJECT", creator=False, model=None):
|
|
def decorator(view_func):
|
|
@wraps(view_func)
|
|
def _wrapped_view(instance, request, *args, **kwargs):
|
|
|
|
# Check for creator if required
|
|
if creator and model:
|
|
obj = model.objects.filter(
|
|
id=kwargs["pk"], created_by=request.user
|
|
).exists()
|
|
if obj:
|
|
return view_func(instance, request, *args, **kwargs)
|
|
|
|
# Convert allowed_roles to their values if they are enum members
|
|
allowed_role_values = [
|
|
role.value if isinstance(role, ROLE) else role
|
|
for role in allowed_roles
|
|
]
|
|
|
|
# Check role permissions
|
|
if level == "WORKSPACE":
|
|
if WorkspaceMember.objects.filter(
|
|
member=request.user,
|
|
workspace__slug=kwargs["slug"],
|
|
role__in=allowed_role_values,
|
|
is_active=True,
|
|
).exists():
|
|
return view_func(instance, request, *args, **kwargs)
|
|
else:
|
|
if ProjectMember.objects.filter(
|
|
member=request.user,
|
|
workspace__slug=kwargs["slug"],
|
|
project_id=kwargs["project_id"],
|
|
role__in=allowed_role_values,
|
|
is_active=True,
|
|
).exists():
|
|
return view_func(instance, request, *args, **kwargs)
|
|
|
|
# Return permission denied if no conditions are met
|
|
return Response(
|
|
{"error": "You don't have the required permissions."},
|
|
status=status.HTTP_403_FORBIDDEN,
|
|
)
|
|
|
|
return _wrapped_view
|
|
|
|
return decorator
|