from django.contrib.auth import get_user_model from django.contrib.auth.decorators import login_required from django.contrib.auth.views import LoginView from django.shortcuts import render from django.utils import timezone from oauth2_provider.contrib.rest_framework import IsAuthenticatedOrTokenHasScope from rest_framework import generics, status, permissions from rest_framework.response import Response from rest_framework.views import APIView from apps.gooyal_oauth2.rest_framework import IsAuthenticatedOrTokenMatchesOASRequirements from apps.users.forms import OTPAuthenticationForm from apps.users.models import User from apps.users.provinces_and_cities import State from apps.users.serializers import PublicUserSerializer, AccountSerializer, RequestOTPSerializer, \ ChangePasswordSerializer UserModel = get_user_model() class UserListView(generics.ListAPIView): permission_classes = [IsAuthenticatedOrTokenMatchesOASRequirements] queryset = User.objects.all() serializer_class = PublicUserSerializer required_alternate_scopes = { "GET": [["accounts.profile:list"]], } class UserDetailView(generics.RetrieveAPIView): permission_classes = [IsAuthenticatedOrTokenMatchesOASRequirements] queryset = User.objects.all() serializer_class = PublicUserSerializer lookup_field = 'uuid' required_alternate_scopes = { "GET": [["accounts.profile:retrieve"]], } class AccountView(generics.RetrieveUpdateAPIView): serializer_class = AccountSerializer permission_classes = [IsAuthenticatedOrTokenMatchesOASRequirements] required_alternate_scopes = { "GET": [["accounts.account:retrieve"]], "POST": [["accounts.account:update"]], "PUT": [["accounts.account:update"]], "PATCH": [["accounts.account:update"]], } def get_object(self): return self.request.user def perform_update(self, serializer): serializer.save(last_update=timezone.now()) class RequestOTPView(generics.CreateAPIView): permission_classes = [] serializer_class = RequestOTPSerializer required_scopes = [] class ChangePasswordView(generics.UpdateAPIView): permission_classes = [IsAuthenticatedOrTokenHasScope] serializer_class = ChangePasswordSerializer required_scopes = ["accounts.account:change_password"] model = User def get_object(self, queryset=None): obj = self.request.user return obj def update(self, request, *args, **kwargs): self.object = self.get_object() serializer = self.get_serializer(data=request.data) if serializer.is_valid(): pass_field = serializer.data.get("old_password_field") old_password = serializer.data.get("old_password") new_password = serializer.data.get("new_password") if not self.object.check_auth(pass_field, old_password): return Response({"old_password": ["Wrong password/otp."]}, status=status.HTTP_400_BAD_REQUEST) self.object.set_password(new_password) self.object.last_update = timezone.now() self.object.save() return Response({"state": 'success'}, status=status.HTTP_200_OK) return Response(serializer.errors, status=status.HTTP_400_BAD_REQUEST) @login_required def home(request): return render(request, 'registration/profile.html') class OTPLoginView(LoginView): """ Display the login form and handle the login action. """ form_class = OTPAuthenticationForm class ProvinceApiView(APIView): permission_classes = [permissions.AllowAny] def get(self, request): return Response(State().province_list())