winofy-backend/apps/reviews/views.py
Ali Asadi eb5eb38665 Migrate manual query-param filtering to django-filter
django-filter was already installed and set as DEFAULT_FILTER_BACKENDS
but unused everywhere. Replace hand-rolled get_queryset filtering with
FilterSet classes (stores/catalog/locations/reviews) and
filterset_fields (orders status). drf-spectacular auto-documents these
for swagger, so the manual OpenApiParameter declarations for the
migrated fields are removed (stores keeps lat/lng manual since
geo-distance isn't a plain filter).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-22 17:31:01 +03:30

56 lines
2.2 KiB
Python

from rest_framework import mixins, viewsets
from rest_framework.decorators import action
from rest_framework.permissions import AllowAny, IsAuthenticated
from rest_framework.response import Response
from apps.gooyal_oauth2.rest_framework import IsAuthenticatedOrTokenMatchesOASRequirements
from apps.core.permissions import IsStoreOwner
from .filters import ReviewFilter
from .models import Review
from .serializers import ReviewSerializer, SellerReplySerializer
class ReviewViewSet(mixins.ListModelMixin, mixins.CreateModelMixin, viewsets.GenericViewSet):
"""Customer reviews — create after a delivered order, list is public per store."""
schema_tags = ['Reviews']
serializer_class = ReviewSerializer
permission_classes = [IsAuthenticatedOrTokenMatchesOASRequirements]
required_alternate_scopes = {
"POST": [[]],
}
filterset_class = ReviewFilter
queryset = Review.objects.select_related('customer', 'store')
def get_permissions(self):
if self.action == 'create':
return [IsAuthenticatedOrTokenMatchesOASRequirements]
return [AllowAny()]
class SellerReviewViewSet(mixins.ListModelMixin, viewsets.GenericViewSet):
"""Reviews left for the authenticated seller's store, with reply support."""
schema_tags = ['Seller · Reviews']
serializer_class = ReviewSerializer
# permission_classes = [IsAuthenticated, IsStoreOwner]
# TODO:
permission_classes = [IsAuthenticatedOrTokenMatchesOASRequirements]
required_alternate_scopes = {
"POST": [[]],
}
def get_queryset(self):
if getattr(self, 'swagger_fake_view', False):
return Review.objects.none()
return Review.objects.filter(store=self.request.user.store).select_related('customer')
@action(detail=True, methods=['post'])
def reply(self, request, pk=None):
review = self.get_object()
serializer = SellerReplySerializer(data=request.data)
serializer.is_valid(raise_exception=True)
review.seller_reply = serializer.validated_data['seller_reply']
review.save(update_fields=['seller_reply', 'updated_at'])
return Response(ReviewSerializer(review).data)