winofy-backend/apps/catalog/views.py
Ali Asadi 674ca34041 Add missing required_alternate_scopes across OAS-gated views
Several views using IsAuthenticatedOrTokenMatchesOASRequirements were
missing scope entries for methods they actually expose (GET on
list/retrieve-only viewsets, PUT/PATCH/DELETE on ModelViewSets), and
two had a stale POST entry for a method that doesn't exist
(SellerStoreWorkingHoursView, OrderGroupViewSet). Fixes:
- SellerStoreView, SellerStoreWorkingHoursView (apps/stores/views.py)
- AddressViewSet (apps/locations/views.py)
- SellerReviewViewSet (apps/reviews/views.py)
- SellerProductViewSet (apps/catalog/views.py)
- OrderGroupViewSet, OrderViewSet, SellerOrderViewSet,
  NotificationViewSet (apps/orders/views.py)

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-31 14:46:02 +03:30

73 lines
2.6 KiB
Python

from rest_framework import mixins, viewsets
from rest_framework.decorators import action
from rest_framework.permissions import AllowAny, IsAuthenticated
from rest_framework.response import Response
from apps.gooyal_oauth2.rest_framework import IsAuthenticatedOrTokenMatchesOASRequirements
from apps.core.permissions import IsStoreOwner
from apps.stores.models import Store
from .filters import ProductFilter
from .models import Product, ProductCategory
from .serializers import (
ProductCategorySerializer,
ProductDetailSerializer,
ProductListSerializer,
SellerProductSerializer,
StockAdjustSerializer,
)
class ProductCategoryViewSet(mixins.ListModelMixin, viewsets.GenericViewSet):
schema_tags = ['Catalog']
permission_classes = [AllowAny]
serializer_class = ProductCategorySerializer
queryset = ProductCategory.objects.all()
class ProductViewSet(mixins.ListModelMixin, mixins.RetrieveModelMixin, viewsets.GenericViewSet):
"""Customer-facing product browsing (store page, product detail, search)."""
schema_tags = ['Catalog']
permission_classes = [AllowAny]
queryset = Product.objects.filter(
is_active=True, store__status=Store.Status.APPROVED,
).select_related('store', 'category')
filterset_class = ProductFilter
def get_serializer_class(self):
if self.action == 'retrieve':
return ProductDetailSerializer
return ProductListSerializer
class SellerProductViewSet(viewsets.ModelViewSet):
"""Seller's own product management (S06 list, S07 add, S08 inventory)."""
schema_tags = ['Seller · Products']
serializer_class = SellerProductSerializer
# permission_classes = [IsAuthenticated, IsStoreOwner]
# TODO: IsStoreOwner?
permission_classes = [IsAuthenticatedOrTokenMatchesOASRequirements]
required_alternate_scopes = {
"GET": [[]],
"POST": [[]],
"PUT": [[]],
"PATCH": [[]],
"DELETE": [[]],
}
def get_queryset(self):
if getattr(self, 'swagger_fake_view', False):
return Product.objects.none()
return Product.objects.filter(store=self.request.user.store).select_related('category')
@action(detail=True, methods=['patch'], url_path='stock')
def adjust_stock(self, request, pk=None):
product = self.get_object()
serializer = StockAdjustSerializer(data=request.data)
serializer.is_valid(raise_exception=True)
product.stock_quantity = serializer.validated_data['stock_quantity']
product.save(update_fields=['stock_quantity', 'updated_at'])
return Response(SellerProductSerializer(product).data)