diff --git a/apps/users/views.py b/apps/users/views.py index 2b2a063..3becc00 100644 --- a/apps/users/views.py +++ b/apps/users/views.py @@ -3,7 +3,8 @@ from django.contrib.auth.decorators import login_required from django.contrib.auth.views import LoginView from django.shortcuts import render from django.utils import timezone -from oauth2_provider.contrib.rest_framework import IsAuthenticatedOrTokenHasScope +from oauth2_provider.contrib.rest_framework import IsAuthenticatedOrTokenHasScope, OAuth2Authentication, \ + TokenMatchesOASRequirements from rest_framework import generics, permissions, status from rest_framework.response import Response @@ -32,9 +33,13 @@ class UserDetailView(generics.RetrieveAPIView): class AccountView(generics.RetrieveUpdateAPIView): - permission_classes = [permissions.IsAuthenticated, IsAuthenticatedOrTokenHasScope] serializer_class = AccountSerializer - required_scopes = [] + authentication_classes = [OAuth2Authentication] + permission_classes = [TokenMatchesOASRequirements] + required_alternate_scopes = { + "GET": [["accounts.account:retrieve"]], + "POST": [["accounts.account:update"]], + } def get_object(self): return self.request.user diff --git a/utils/notification_client.py b/utils/notification_client.py index fdb99b4..8472a6b 100644 --- a/utils/notification_client.py +++ b/utils/notification_client.py @@ -14,7 +14,7 @@ class NotificationClient(): "charset": "utf-8" } header.setdefault("Authorization", f"Bearer {settings.ACCESS_TOKEN}", ) - + return {} response = requests.request('post', f'{settings.NOTIFICATIONS_SERVICE_URL}/notifications/', headers=header,