Compare commits
No commits in common. "63a116c2b2f563dec9ff7682a950d46d2585d01c" and "a223772ffb541925022726fb905a0241383fa1dd" have entirely different histories.
63a116c2b2
...
a223772ffb
6 changed files with 15 additions and 71 deletions
|
|
@ -1,11 +1,12 @@
|
|||
SECRET_KEY=change-me
|
||||
DEBUG=True
|
||||
ALLOWED_HOSTS=winofy-staging.winsoo.ir,localhost,127.0.0.1
|
||||
ALLOWED_HOSTS=localhost,127.0.0.1
|
||||
|
||||
DB_NAME=winofy_dev
|
||||
DB_USER=
|
||||
DB_PASSWORD=
|
||||
DB_HOST=localhost
|
||||
DB_PORT=5432
|
||||
|
||||
REDIS_URL=redis://localhost:6379/1
|
||||
|
||||
|
|
|
|||
|
|
@ -4,8 +4,6 @@ from rest_framework.decorators import action
|
|||
from rest_framework.permissions import AllowAny, IsAuthenticated
|
||||
from rest_framework.response import Response
|
||||
|
||||
from apps.gooyal_oauth2.rest_framework import IsAuthenticatedOrTokenMatchesOASRequirements
|
||||
|
||||
from apps.core.permissions import IsStoreOwner
|
||||
from apps.stores.models import Store
|
||||
|
||||
|
|
@ -62,13 +60,8 @@ class SellerProductViewSet(viewsets.ModelViewSet):
|
|||
"""Seller's own product management (S06 list, S07 add, S08 inventory)."""
|
||||
|
||||
schema_tags = ['Seller · Products']
|
||||
permission_classes = [IsAuthenticated, IsStoreOwner]
|
||||
serializer_class = SellerProductSerializer
|
||||
# permission_classes = [IsAuthenticated, IsStoreOwner]
|
||||
# TODO: IsStoreOwner?
|
||||
permission_classes = [IsAuthenticatedOrTokenMatchesOASRequirements]
|
||||
required_alternate_scopes = {
|
||||
"POST": [[]],
|
||||
}
|
||||
|
||||
def get_queryset(self):
|
||||
if getattr(self, 'swagger_fake_view', False):
|
||||
|
|
|
|||
|
|
@ -1,8 +1,6 @@
|
|||
from rest_framework import mixins, viewsets
|
||||
from rest_framework.permissions import AllowAny, IsAuthenticated
|
||||
|
||||
from apps.gooyal_oauth2.rest_framework import IsAuthenticatedOrTokenMatchesOASRequirements
|
||||
|
||||
from .models import Address, City, Neighborhood
|
||||
from .serializers import AddressSerializer, CitySerializer, NeighborhoodSerializer
|
||||
|
||||
|
|
@ -30,11 +28,8 @@ class NeighborhoodViewSet(mixins.ListModelMixin, mixins.RetrieveModelMixin, view
|
|||
|
||||
class AddressViewSet(viewsets.ModelViewSet):
|
||||
schema_tags = ['Addresses']
|
||||
permission_classes = [IsAuthenticated]
|
||||
serializer_class = AddressSerializer
|
||||
permission_classes = [IsAuthenticatedOrTokenMatchesOASRequirements]
|
||||
required_alternate_scopes = {
|
||||
"POST": [[]],
|
||||
}
|
||||
|
||||
def get_queryset(self):
|
||||
if getattr(self, 'swagger_fake_view', False):
|
||||
|
|
|
|||
|
|
@ -6,8 +6,6 @@ from rest_framework.permissions import IsAuthenticated
|
|||
from rest_framework.response import Response
|
||||
from rest_framework.views import APIView
|
||||
|
||||
from apps.gooyal_oauth2.rest_framework import IsAuthenticatedOrTokenMatchesOASRequirements
|
||||
|
||||
from apps.core.permissions import IsStoreOwner
|
||||
|
||||
from . import services
|
||||
|
|
@ -29,11 +27,8 @@ class CartView(APIView):
|
|||
"""The authenticated user's cart, grouped by store (C07)."""
|
||||
|
||||
schema_tags = ['Cart']
|
||||
permission_classes = [IsAuthenticated]
|
||||
serializer_class = CartSerializer
|
||||
permission_classes = [IsAuthenticatedOrTokenMatchesOASRequirements]
|
||||
required_alternate_scopes = {
|
||||
"POST": [[]],
|
||||
}
|
||||
|
||||
def get(self, request):
|
||||
cart, _ = Cart.objects.get_or_create(user=request.user)
|
||||
|
|
@ -50,11 +45,8 @@ class CartItemView(APIView):
|
|||
"""Add/update/remove a single product line in the authenticated user's cart."""
|
||||
|
||||
schema_tags = ['Cart']
|
||||
permission_classes = [IsAuthenticated]
|
||||
serializer_class = CartItemWriteSerializer
|
||||
permission_classes = [IsAuthenticatedOrTokenMatchesOASRequirements]
|
||||
required_alternate_scopes = {
|
||||
"POST": [[]],
|
||||
}
|
||||
|
||||
@extend_schema(request=CartItemWriteSerializer, responses=CartItemSerializer)
|
||||
def post(self, request):
|
||||
|
|
@ -94,11 +86,8 @@ class CheckoutView(APIView):
|
|||
"""Splits the authenticated customer's multi-store cart into per-store orders (C08)."""
|
||||
|
||||
schema_tags = ['Checkout']
|
||||
permission_classes = [IsAuthenticated]
|
||||
serializer_class = CheckoutSerializer
|
||||
permission_classes = [IsAuthenticatedOrTokenMatchesOASRequirements]
|
||||
required_alternate_scopes = {
|
||||
"POST": [[]],
|
||||
}
|
||||
|
||||
@extend_schema(request=CheckoutSerializer, responses=OrderGroupSerializer)
|
||||
def post(self, request):
|
||||
|
|
@ -113,11 +102,8 @@ class OrderGroupViewSet(mixins.ListModelMixin, mixins.RetrieveModelMixin, viewse
|
|||
"""Customer order history — each group may contain orders from several stores."""
|
||||
|
||||
schema_tags = ['Orders']
|
||||
permission_classes = [IsAuthenticated]
|
||||
serializer_class = OrderGroupSerializer
|
||||
permission_classes = [IsAuthenticatedOrTokenMatchesOASRequirements]
|
||||
required_alternate_scopes = {
|
||||
"POST": [[]],
|
||||
}
|
||||
|
||||
def get_queryset(self):
|
||||
if getattr(self, 'swagger_fake_view', False):
|
||||
|
|
@ -129,11 +115,8 @@ class OrderViewSet(mixins.RetrieveModelMixin, viewsets.GenericViewSet):
|
|||
"""Customer-facing single-order tracking (C09) + cancel."""
|
||||
|
||||
schema_tags = ['Orders']
|
||||
permission_classes = [IsAuthenticated]
|
||||
serializer_class = OrderSerializer
|
||||
permission_classes = [IsAuthenticatedOrTokenMatchesOASRequirements]
|
||||
required_alternate_scopes = {
|
||||
"POST": [[]],
|
||||
}
|
||||
|
||||
def get_queryset(self):
|
||||
if getattr(self, 'swagger_fake_view', False):
|
||||
|
|
@ -153,13 +136,8 @@ class SellerOrderViewSet(mixins.ListModelMixin, mixins.RetrieveModelMixin, views
|
|||
"""Seller order management (S09 list w/ status tabs, S10 detail + stepper actions)."""
|
||||
|
||||
schema_tags = ['Seller · Orders']
|
||||
permission_classes = [IsAuthenticated, IsStoreOwner]
|
||||
serializer_class = OrderSerializer
|
||||
# permission_classes = [IsAuthenticated, IsStoreOwner]
|
||||
# TODO: IsStoreOwner
|
||||
permission_classes = [IsAuthenticatedOrTokenMatchesOASRequirements]
|
||||
required_alternate_scopes = {
|
||||
"POST": [[]],
|
||||
}
|
||||
|
||||
def get_queryset(self):
|
||||
if getattr(self, 'swagger_fake_view', False):
|
||||
|
|
@ -206,11 +184,8 @@ class NotificationViewSet(mixins.ListModelMixin, mixins.RetrieveModelMixin, view
|
|||
"""Shared notification feed (S16 for sellers; same model serves the customer app)."""
|
||||
|
||||
schema_tags = ['Notifications']
|
||||
permission_classes = [IsAuthenticated]
|
||||
serializer_class = NotificationSerializer
|
||||
permission_classes = [IsAuthenticatedOrTokenMatchesOASRequirements]
|
||||
required_alternate_scopes = {
|
||||
"POST": [[]],
|
||||
}
|
||||
|
||||
def get_queryset(self):
|
||||
if getattr(self, 'swagger_fake_view', False):
|
||||
|
|
|
|||
|
|
@ -3,7 +3,6 @@ from rest_framework.decorators import action
|
|||
from rest_framework.permissions import AllowAny, IsAuthenticated
|
||||
from rest_framework.response import Response
|
||||
|
||||
from apps.gooyal_oauth2.rest_framework import IsAuthenticatedOrTokenMatchesOASRequirements
|
||||
from apps.core.permissions import IsStoreOwner
|
||||
|
||||
from .models import Review
|
||||
|
|
@ -15,14 +14,10 @@ class ReviewViewSet(mixins.ListModelMixin, mixins.CreateModelMixin, viewsets.Gen
|
|||
|
||||
schema_tags = ['Reviews']
|
||||
serializer_class = ReviewSerializer
|
||||
permission_classes = [IsAuthenticatedOrTokenMatchesOASRequirements]
|
||||
required_alternate_scopes = {
|
||||
"POST": [[]],
|
||||
}
|
||||
|
||||
def get_permissions(self):
|
||||
if self.action == 'create':
|
||||
return [IsAuthenticatedOrTokenMatchesOASRequirements]
|
||||
return [IsAuthenticated()]
|
||||
return [AllowAny()]
|
||||
|
||||
def get_queryset(self):
|
||||
|
|
@ -37,13 +32,8 @@ class SellerReviewViewSet(mixins.ListModelMixin, viewsets.GenericViewSet):
|
|||
"""Reviews left for the authenticated seller's store, with reply support."""
|
||||
|
||||
schema_tags = ['Seller · Reviews']
|
||||
permission_classes = [IsAuthenticated, IsStoreOwner]
|
||||
serializer_class = ReviewSerializer
|
||||
# permission_classes = [IsAuthenticated, IsStoreOwner]
|
||||
# TODO:
|
||||
permission_classes = [IsAuthenticatedOrTokenMatchesOASRequirements]
|
||||
required_alternate_scopes = {
|
||||
"POST": [[]],
|
||||
}
|
||||
|
||||
def get_queryset(self):
|
||||
if getattr(self, 'swagger_fake_view', False):
|
||||
|
|
|
|||
|
|
@ -9,8 +9,6 @@ from rest_framework.permissions import AllowAny, IsAuthenticated
|
|||
from rest_framework.response import Response
|
||||
from rest_framework.views import APIView
|
||||
|
||||
from apps.gooyal_oauth2.rest_framework import IsAuthenticatedOrTokenMatchesOASRequirements
|
||||
|
||||
from apps.core.permissions import IsStoreOwner
|
||||
|
||||
from .models import Store, StoreCategory, StoreWorkingHours
|
||||
|
|
@ -72,11 +70,8 @@ class SellerStoreView(APIView):
|
|||
"""The authenticated seller's own store — GET/PATCH to manage it, POST to create it."""
|
||||
|
||||
schema_tags = ['Seller · Store']
|
||||
permission_classes = [IsAuthenticated]
|
||||
serializer_class = SellerStoreSerializer
|
||||
permission_classes = [IsAuthenticatedOrTokenMatchesOASRequirements]
|
||||
required_alternate_scopes = {
|
||||
"POST": [[]],
|
||||
}
|
||||
|
||||
def get(self, request):
|
||||
store = get_object_or_404(Store, owner=request.user)
|
||||
|
|
@ -107,13 +102,8 @@ class SellerStoreWorkingHoursView(APIView):
|
|||
"""Bulk get/set the authenticated seller's weekly working hours (S14)."""
|
||||
|
||||
schema_tags = ['Seller · Store']
|
||||
permission_classes = [IsAuthenticated, IsStoreOwner]
|
||||
serializer_class = StoreWorkingHoursSerializer
|
||||
# permission_classes = [IsAuthenticated, IsStoreOwner]
|
||||
# TODO:
|
||||
permission_classes = [IsAuthenticatedOrTokenMatchesOASRequirements]
|
||||
required_alternate_scopes = {
|
||||
"POST": [[]],
|
||||
}
|
||||
|
||||
def get(self, request):
|
||||
hours = StoreWorkingHours.objects.filter(store=request.user.store)
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue