account update scope
This commit is contained in:
parent
496dbc481d
commit
506b30096e
2 changed files with 22 additions and 23 deletions
|
|
@ -37,11 +37,11 @@ class UserDetailView(generics.RetrieveAPIView):
|
||||||
|
|
||||||
class AccountView(generics.RetrieveUpdateAPIView):
|
class AccountView(generics.RetrieveUpdateAPIView):
|
||||||
serializer_class = AccountSerializer
|
serializer_class = AccountSerializer
|
||||||
authentication_classes = [OAuth2Authentication]
|
|
||||||
permission_classes = [TokenMatchesOASRequirements]
|
permission_classes = [TokenMatchesOASRequirements]
|
||||||
required_alternate_scopes = {
|
required_alternate_scopes = {
|
||||||
"GET": [["accounts.account:retrieve"]],
|
"GET": [["accounts.account:retrieve"]],
|
||||||
"POST": [["accounts.account:update"]],
|
"POST": [["accounts.account:update"]],
|
||||||
|
"PUT": [["accounts.account:update"]],
|
||||||
}
|
}
|
||||||
|
|
||||||
def get_object(self):
|
def get_object(self):
|
||||||
|
|
@ -58,32 +58,32 @@ class RequestOTPView(generics.CreateAPIView):
|
||||||
|
|
||||||
|
|
||||||
class ChangePasswordView(generics.UpdateAPIView):
|
class ChangePasswordView(generics.UpdateAPIView):
|
||||||
permission_classes = [permissions.IsAuthenticated, IsAuthenticatedOrTokenHasScope]
|
permission_classes = [permissions.IsAuthenticated, IsAuthenticatedOrTokenHasScope]
|
||||||
serializer_class = ChangePasswordSerializer
|
serializer_class = ChangePasswordSerializer
|
||||||
required_scopes = ["accounts.account:change_password"]
|
required_scopes = ["accounts.account:change_password"]
|
||||||
model = User
|
model = User
|
||||||
|
|
||||||
def get_object(self, queryset=None):
|
def get_object(self, queryset=None):
|
||||||
obj = self.request.user
|
obj = self.request.user
|
||||||
return obj
|
return obj
|
||||||
|
|
||||||
def update(self, request, *args, **kwargs):
|
def update(self, request, *args, **kwargs):
|
||||||
self.object = self.get_object()
|
self.object = self.get_object()
|
||||||
serializer = self.get_serializer(data=request.data)
|
serializer = self.get_serializer(data=request.data)
|
||||||
|
|
||||||
if serializer.is_valid():
|
if serializer.is_valid():
|
||||||
pass_field = serializer.data.get("old_password_field")
|
pass_field = serializer.data.get("old_password_field")
|
||||||
old_password = serializer.data.get("old_password")
|
old_password = serializer.data.get("old_password")
|
||||||
new_password = serializer.data.get("new_password")
|
new_password = serializer.data.get("new_password")
|
||||||
if not self.object.check_auth(pass_field, old_password):
|
if not self.object.check_auth(pass_field, old_password):
|
||||||
return Response({"old_password": ["Wrong password/otp."]}, status=status.HTTP_400_BAD_REQUEST)
|
return Response({"old_password": ["Wrong password/otp."]}, status=status.HTTP_400_BAD_REQUEST)
|
||||||
|
|
||||||
self.object.set_password(new_password)
|
self.object.set_password(new_password)
|
||||||
self.object.last_update = timezone.now()
|
self.object.last_update = timezone.now()
|
||||||
self.object.save()
|
self.object.save()
|
||||||
return Response({"state": 'success'}, status=status.HTTP_200_OK)
|
return Response({"state": 'success'}, status=status.HTTP_200_OK)
|
||||||
|
|
||||||
return Response(serializer.errors, status=status.HTTP_400_BAD_REQUEST)
|
return Response(serializer.errors, status=status.HTTP_400_BAD_REQUEST)
|
||||||
|
|
||||||
|
|
||||||
@login_required
|
@login_required
|
||||||
|
|
|
||||||
|
|
@ -107,7 +107,6 @@ TEMPLATES = [
|
||||||
]
|
]
|
||||||
|
|
||||||
AUTHENTICATION_BACKENDS = (
|
AUTHENTICATION_BACKENDS = (
|
||||||
# TODO: where use this?
|
|
||||||
'apps.users.backends.OTPBackend',
|
'apps.users.backends.OTPBackend',
|
||||||
'django.contrib.auth.backends.ModelBackend',
|
'django.contrib.auth.backends.ModelBackend',
|
||||||
)
|
)
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue