Several views using IsAuthenticatedOrTokenMatchesOASRequirements were missing scope entries for methods they actually expose (GET on list/retrieve-only viewsets, PUT/PATCH/DELETE on ModelViewSets), and two had a stale POST entry for a method that doesn't exist (SellerStoreWorkingHoursView, OrderGroupViewSet). Fixes: - SellerStoreView, SellerStoreWorkingHoursView (apps/stores/views.py) - AddressViewSet (apps/locations/views.py) - SellerReviewViewSet (apps/reviews/views.py) - SellerProductViewSet (apps/catalog/views.py) - OrderGroupViewSet, OrderViewSet, SellerOrderViewSet, NotificationViewSet (apps/orders/views.py) Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
73 lines
2.6 KiB
Python
73 lines
2.6 KiB
Python
from rest_framework import mixins, viewsets
|
|
from rest_framework.decorators import action
|
|
from rest_framework.permissions import AllowAny, IsAuthenticated
|
|
from rest_framework.response import Response
|
|
|
|
from apps.gooyal_oauth2.rest_framework import IsAuthenticatedOrTokenMatchesOASRequirements
|
|
|
|
from apps.core.permissions import IsStoreOwner
|
|
from apps.stores.models import Store
|
|
|
|
from .filters import ProductFilter
|
|
from .models import Product, ProductCategory
|
|
from .serializers import (
|
|
ProductCategorySerializer,
|
|
ProductDetailSerializer,
|
|
ProductListSerializer,
|
|
SellerProductSerializer,
|
|
StockAdjustSerializer,
|
|
)
|
|
|
|
|
|
class ProductCategoryViewSet(mixins.ListModelMixin, viewsets.GenericViewSet):
|
|
schema_tags = ['Catalog']
|
|
permission_classes = [AllowAny]
|
|
serializer_class = ProductCategorySerializer
|
|
queryset = ProductCategory.objects.all()
|
|
|
|
|
|
class ProductViewSet(mixins.ListModelMixin, mixins.RetrieveModelMixin, viewsets.GenericViewSet):
|
|
"""Customer-facing product browsing (store page, product detail, search)."""
|
|
|
|
schema_tags = ['Catalog']
|
|
permission_classes = [AllowAny]
|
|
queryset = Product.objects.filter(
|
|
is_active=True, store__status=Store.Status.APPROVED,
|
|
).select_related('store', 'category')
|
|
filterset_class = ProductFilter
|
|
|
|
def get_serializer_class(self):
|
|
if self.action == 'retrieve':
|
|
return ProductDetailSerializer
|
|
return ProductListSerializer
|
|
|
|
|
|
class SellerProductViewSet(viewsets.ModelViewSet):
|
|
"""Seller's own product management (S06 list, S07 add, S08 inventory)."""
|
|
|
|
schema_tags = ['Seller · Products']
|
|
serializer_class = SellerProductSerializer
|
|
# permission_classes = [IsAuthenticated, IsStoreOwner]
|
|
# TODO: IsStoreOwner?
|
|
permission_classes = [IsAuthenticatedOrTokenMatchesOASRequirements]
|
|
required_alternate_scopes = {
|
|
"GET": [[]],
|
|
"POST": [[]],
|
|
"PUT": [[]],
|
|
"PATCH": [[]],
|
|
"DELETE": [[]],
|
|
}
|
|
|
|
def get_queryset(self):
|
|
if getattr(self, 'swagger_fake_view', False):
|
|
return Product.objects.none()
|
|
return Product.objects.filter(store=self.request.user.store).select_related('category')
|
|
|
|
@action(detail=True, methods=['patch'], url_path='stock')
|
|
def adjust_stock(self, request, pk=None):
|
|
product = self.get_object()
|
|
serializer = StockAdjustSerializer(data=request.data)
|
|
serializer.is_valid(raise_exception=True)
|
|
product.stock_quantity = serializer.validated_data['stock_quantity']
|
|
product.save(update_fields=['stock_quantity', 'updated_at'])
|
|
return Response(SellerProductSerializer(product).data)
|