Django 6 + DRF resource server against the Gooyal accounts OAuth2 service, matching the Winsoo ecosystem's conventions. Covers locations, stores, catalog, cart, checkout/orders (with the multi-store-cart split and the status stepper), reviews, and notifications, plus a demo-data seed command. Payment integration (wallet debits, online gateway, seller payouts) is intentionally left out here — see feature/payment. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
19 lines
763 B
Python
19 lines
763 B
Python
import logging
|
|
|
|
from oauth2_provider.contrib.rest_framework import TokenMatchesOASRequirements, OAuth2Authentication
|
|
from rest_framework.permissions import (
|
|
IsAuthenticated
|
|
)
|
|
|
|
loger = logging.getLogger("oauth2_provider")
|
|
|
|
|
|
class IsAuthenticatedOrTokenMatchesOASRequirements(TokenMatchesOASRequirements):
|
|
def has_permission(self, request, view):
|
|
is_authenticated = IsAuthenticated().has_permission(request, view)
|
|
oauth2authenticated = False
|
|
if is_authenticated:
|
|
oauth2authenticated = isinstance(request.successful_authenticator, OAuth2Authentication)
|
|
|
|
token_has_scope = TokenMatchesOASRequirements()
|
|
return (is_authenticated and not oauth2authenticated) or token_has_scope.has_permission(request, view)
|