winofy-backend/apps/locations/views.py
Ali Asadi 23eb0fc2f0 Add required_alternate_scopes to authenticated views
Declares the HTTP methods each authenticated view/viewset exposes,
scoped to empty scope requirements, ready for OAuth2 scope enforcement.
2026-08-15 11:48:35 +03:30

44 lines
1.5 KiB
Python

from rest_framework import mixins, viewsets
from rest_framework.permissions import AllowAny, IsAuthenticated
from .models import Address, City, Neighborhood
from .serializers import AddressSerializer, CitySerializer, NeighborhoodSerializer
class CityViewSet(mixins.ListModelMixin, mixins.RetrieveModelMixin, viewsets.GenericViewSet):
schema_tags = ['Locations']
permission_classes = [AllowAny]
serializer_class = CitySerializer
queryset = City.objects.filter(is_active=True)
class NeighborhoodViewSet(mixins.ListModelMixin, mixins.RetrieveModelMixin, viewsets.GenericViewSet):
schema_tags = ['Locations']
permission_classes = [AllowAny]
serializer_class = NeighborhoodSerializer
queryset = Neighborhood.objects.filter(is_active=True).select_related('city')
def get_queryset(self):
queryset = super().get_queryset()
city_uuid = self.request.query_params.get('city')
if city_uuid:
queryset = queryset.filter(city__uuid=city_uuid)
return queryset
class AddressViewSet(viewsets.ModelViewSet):
schema_tags = ['Addresses']
permission_classes = [IsAuthenticated]
required_alternate_scopes = {
"GET": [[]],
"POST": [[]],
"PUT": [[]],
"PATCH": [[]],
"DELETE": [[]],
}
serializer_class = AddressSerializer
def get_queryset(self):
if getattr(self, 'swagger_fake_view', False):
return Address.objects.none()
return Address.objects.filter(user=self.request.user).select_related('city', 'neighborhood')