From 308faff85860d9f3a5ab3b4b09e27f99d3fc269d Mon Sep 17 00:00:00 2001 From: Sayyid Hamid Mahdavi Date: Wed, 3 Dec 2025 12:08:16 +0330 Subject: [PATCH] some bugfix --- apps/promotions/views.py | 17 ++++++++++++++++- 1 file changed, 16 insertions(+), 1 deletion(-) diff --git a/apps/promotions/views.py b/apps/promotions/views.py index 8775077..626845a 100644 --- a/apps/promotions/views.py +++ b/apps/promotions/views.py @@ -156,6 +156,11 @@ class ApplicationPromoteUserApiView(CreateAPIView): model = Promotion serializer_class = PromoteSerializer + permission_classes = [IsAuthenticatedOrTokenMatchesOASRequirements] + required_alternate_scopes = { + "POST": [[]], + } + def get_plan(self): plan_uuid = self.kwargs.get('plan') plan = get_object_or_404(Plan, uuid=plan_uuid) @@ -184,6 +189,11 @@ class ApplicationPromotionListApiView(ListAPIView): model = Promotion serializer_class = PromotionSerializer + permission_classes = [IsAuthenticatedOrTokenMatchesOASRequirements] + required_alternate_scopes = { + "GET": [[]], + } + def get_plan(self): plan_uuid = self.kwargs.get('plan') plan = get_object_or_404(Plan, uuid=plan_uuid) @@ -219,6 +229,10 @@ class ApplicationPromotionListApiView(ListAPIView): class ApplicationEventSubmitAPIView(CreateAPIView): model = Promotion serializer_class = PromoteSerializer + permission_classes = [IsAuthenticatedOrTokenMatchesOASRequirements] + required_alternate_scopes = { + "POST": [[]], + } def create(self, request, *args, **kwargs): serializer = self.get_serializer(data=request.data) @@ -226,8 +240,9 @@ class ApplicationEventSubmitAPIView(CreateAPIView): data = serializer.validated_data application = get_application(self.request) event_saver: EventSaver = EventSaver.objects.filter(event_label=serializer.validated_data['label']).first() + user = self.request.user.pk or serializer.validated_data['user'] try: - event = event_saver.save_event(user=None, application=application, **serializer.validated_data) + event = event_saver.save_event(user=user, application=application, **serializer.validated_data) except Exception as e: raise UnprocessableEntity(str(e))