mirror of
https://github.com/encode/django-rest-framework.git
synced 2024-11-11 12:17:24 +03:00
430 lines
45 KiB
HTML
430 lines
45 KiB
HTML
<!doctype html PUBLIC "-//W3C//DTD html 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
|
|
<html>
|
|
<head>
|
|
<meta http-equiv='Content-Type' content='text/html; charset=utf-8'>
|
|
|
|
|
|
<meta http-equiv='X-UA-Compatible' content='IE=emulateIE7' />
|
|
<title>Coverage for rest_framework/permissions: 81%</title>
|
|
<link rel='stylesheet' href='style.css' type='text/css'>
|
|
<script type='text/javascript' src='jquery-1.4.3.min.js'></script>
|
|
<script type='text/javascript' src='jquery.hotkeys.js'></script>
|
|
<script type='text/javascript' src='jquery.isonscreen.js'></script>
|
|
<script type='text/javascript' src='coverage_html.js'></script>
|
|
<script type='text/javascript' charset='utf-8'>
|
|
jQuery(document).ready(coverage.pyfile_ready);
|
|
</script>
|
|
</head>
|
|
<body id='pyfile'>
|
|
|
|
<div id='header'>
|
|
<div class='content'>
|
|
<h1>Coverage for <b>rest_framework/permissions</b> :
|
|
<span class='pc_cov'>81%</span>
|
|
</h1>
|
|
<img id='keyboard_icon' src='keybd_closed.png'>
|
|
<h2 class='stats'>
|
|
63 statements
|
|
<span class='run hide_run shortkey_r' onclick='coverage.toggle_lines(this, "run")'>51 run</span>
|
|
<span class='mis shortkey_m' onclick='coverage.toggle_lines(this, "mis")'>12 missing</span>
|
|
<span class='exc shortkey_x' onclick='coverage.toggle_lines(this, "exc")'>0 excluded</span>
|
|
|
|
</h2>
|
|
</div>
|
|
</div>
|
|
|
|
<div class='help_panel'>
|
|
<img id='panel_icon' src='keybd_open.png'>
|
|
<p class='legend'>Hot-keys on this page</p>
|
|
<div>
|
|
<p class='keyhelp'>
|
|
<span class='key'>r</span>
|
|
<span class='key'>m</span>
|
|
<span class='key'>x</span>
|
|
<span class='key'>p</span> toggle line displays
|
|
</p>
|
|
<p class='keyhelp'>
|
|
<span class='key'>j</span>
|
|
<span class='key'>k</span> next/prev highlighted chunk
|
|
</p>
|
|
<p class='keyhelp'>
|
|
<span class='key'>0</span> (zero) top of page
|
|
</p>
|
|
<p class='keyhelp'>
|
|
<span class='key'>1</span> (one) first highlighted chunk
|
|
</p>
|
|
</div>
|
|
</div>
|
|
|
|
<div id='source'>
|
|
<table cellspacing='0' cellpadding='0'>
|
|
<tr>
|
|
<td class='linenos' valign='top'>
|
|
<p id='n1' class='pln'><a href='#n1'>1</a></p>
|
|
<p id='n2' class='pln'><a href='#n2'>2</a></p>
|
|
<p id='n3' class='pln'><a href='#n3'>3</a></p>
|
|
<p id='n4' class='stm run hide_run'><a href='#n4'>4</a></p>
|
|
<p id='n5' class='stm run hide_run'><a href='#n5'>5</a></p>
|
|
<p id='n6' class='stm run hide_run'><a href='#n6'>6</a></p>
|
|
<p id='n7' class='pln'><a href='#n7'>7</a></p>
|
|
<p id='n8' class='stm run hide_run'><a href='#n8'>8</a></p>
|
|
<p id='n9' class='pln'><a href='#n9'>9</a></p>
|
|
<p id='n10' class='stm run hide_run'><a href='#n10'>10</a></p>
|
|
<p id='n11' class='pln'><a href='#n11'>11</a></p>
|
|
<p id='n12' class='pln'><a href='#n12'>12</a></p>
|
|
<p id='n13' class='stm run hide_run'><a href='#n13'>13</a></p>
|
|
<p id='n14' class='pln'><a href='#n14'>14</a></p>
|
|
<p id='n15' class='pln'><a href='#n15'>15</a></p>
|
|
<p id='n16' class='pln'><a href='#n16'>16</a></p>
|
|
<p id='n17' class='pln'><a href='#n17'>17</a></p>
|
|
<p id='n18' class='stm run hide_run'><a href='#n18'>18</a></p>
|
|
<p id='n19' class='pln'><a href='#n19'>19</a></p>
|
|
<p id='n20' class='pln'><a href='#n20'>20</a></p>
|
|
<p id='n21' class='pln'><a href='#n21'>21</a></p>
|
|
<p id='n22' class='stm run hide_run'><a href='#n22'>22</a></p>
|
|
<p id='n23' class='pln'><a href='#n23'>23</a></p>
|
|
<p id='n24' class='stm run hide_run'><a href='#n24'>24</a></p>
|
|
<p id='n25' class='pln'><a href='#n25'>25</a></p>
|
|
<p id='n26' class='pln'><a href='#n26'>26</a></p>
|
|
<p id='n27' class='pln'><a href='#n27'>27</a></p>
|
|
<p id='n28' class='stm run hide_run'><a href='#n28'>28</a></p>
|
|
<p id='n29' class='stm mis'><a href='#n29'>29</a></p>
|
|
<p id='n30' class='pln'><a href='#n30'>30</a></p>
|
|
<p id='n31' class='pln'><a href='#n31'>31</a></p>
|
|
<p id='n32' class='pln'><a href='#n32'>32</a></p>
|
|
<p id='n33' class='pln'><a href='#n33'>33</a></p>
|
|
<p id='n34' class='stm mis'><a href='#n34'>34</a></p>
|
|
<p id='n35' class='stm run hide_run'><a href='#n35'>35</a></p>
|
|
<p id='n36' class='pln'><a href='#n36'>36</a></p>
|
|
<p id='n37' class='pln'><a href='#n37'>37</a></p>
|
|
<p id='n38' class='stm run hide_run'><a href='#n38'>38</a></p>
|
|
<p id='n39' class='pln'><a href='#n39'>39</a></p>
|
|
<p id='n40' class='pln'><a href='#n40'>40</a></p>
|
|
<p id='n41' class='pln'><a href='#n41'>41</a></p>
|
|
<p id='n42' class='pln'><a href='#n42'>42</a></p>
|
|
<p id='n43' class='pln'><a href='#n43'>43</a></p>
|
|
<p id='n44' class='pln'><a href='#n44'>44</a></p>
|
|
<p id='n45' class='stm run hide_run'><a href='#n45'>45</a></p>
|
|
<p id='n46' class='stm run hide_run'><a href='#n46'>46</a></p>
|
|
<p id='n47' class='pln'><a href='#n47'>47</a></p>
|
|
<p id='n48' class='pln'><a href='#n48'>48</a></p>
|
|
<p id='n49' class='stm run hide_run'><a href='#n49'>49</a></p>
|
|
<p id='n50' class='pln'><a href='#n50'>50</a></p>
|
|
<p id='n51' class='pln'><a href='#n51'>51</a></p>
|
|
<p id='n52' class='pln'><a href='#n52'>52</a></p>
|
|
<p id='n53' class='pln'><a href='#n53'>53</a></p>
|
|
<p id='n54' class='stm run hide_run'><a href='#n54'>54</a></p>
|
|
<p id='n55' class='stm run hide_run'><a href='#n55'>55</a></p>
|
|
<p id='n56' class='stm run hide_run'><a href='#n56'>56</a></p>
|
|
<p id='n57' class='stm run hide_run'><a href='#n57'>57</a></p>
|
|
<p id='n58' class='pln'><a href='#n58'>58</a></p>
|
|
<p id='n59' class='pln'><a href='#n59'>59</a></p>
|
|
<p id='n60' class='stm run hide_run'><a href='#n60'>60</a></p>
|
|
<p id='n61' class='pln'><a href='#n61'>61</a></p>
|
|
<p id='n62' class='pln'><a href='#n62'>62</a></p>
|
|
<p id='n63' class='pln'><a href='#n63'>63</a></p>
|
|
<p id='n64' class='pln'><a href='#n64'>64</a></p>
|
|
<p id='n65' class='stm run hide_run'><a href='#n65'>65</a></p>
|
|
<p id='n66' class='stm mis'><a href='#n66'>66</a></p>
|
|
<p id='n67' class='stm mis'><a href='#n67'>67</a></p>
|
|
<p id='n68' class='stm mis'><a href='#n68'>68</a></p>
|
|
<p id='n69' class='pln'><a href='#n69'>69</a></p>
|
|
<p id='n70' class='pln'><a href='#n70'>70</a></p>
|
|
<p id='n71' class='stm run hide_run'><a href='#n71'>71</a></p>
|
|
<p id='n72' class='pln'><a href='#n72'>72</a></p>
|
|
<p id='n73' class='pln'><a href='#n73'>73</a></p>
|
|
<p id='n74' class='pln'><a href='#n74'>74</a></p>
|
|
<p id='n75' class='pln'><a href='#n75'>75</a></p>
|
|
<p id='n76' class='stm run hide_run'><a href='#n76'>76</a></p>
|
|
<p id='n77' class='stm mis'><a href='#n77'>77</a></p>
|
|
<p id='n78' class='pln'><a href='#n78'>78</a></p>
|
|
<p id='n79' class='pln'><a href='#n79'>79</a></p>
|
|
<p id='n80' class='stm mis'><a href='#n80'>80</a></p>
|
|
<p id='n81' class='stm mis'><a href='#n81'>81</a></p>
|
|
<p id='n82' class='pln'><a href='#n82'>82</a></p>
|
|
<p id='n83' class='pln'><a href='#n83'>83</a></p>
|
|
<p id='n84' class='stm run hide_run'><a href='#n84'>84</a></p>
|
|
<p id='n85' class='pln'><a href='#n85'>85</a></p>
|
|
<p id='n86' class='pln'><a href='#n86'>86</a></p>
|
|
<p id='n87' class='pln'><a href='#n87'>87</a></p>
|
|
<p id='n88' class='pln'><a href='#n88'>88</a></p>
|
|
<p id='n89' class='pln'><a href='#n89'>89</a></p>
|
|
<p id='n90' class='pln'><a href='#n90'>90</a></p>
|
|
<p id='n91' class='pln'><a href='#n91'>91</a></p>
|
|
<p id='n92' class='pln'><a href='#n92'>92</a></p>
|
|
<p id='n93' class='pln'><a href='#n93'>93</a></p>
|
|
<p id='n94' class='pln'><a href='#n94'>94</a></p>
|
|
<p id='n95' class='pln'><a href='#n95'>95</a></p>
|
|
<p id='n96' class='pln'><a href='#n96'>96</a></p>
|
|
<p id='n97' class='pln'><a href='#n97'>97</a></p>
|
|
<p id='n98' class='pln'><a href='#n98'>98</a></p>
|
|
<p id='n99' class='stm run hide_run'><a href='#n99'>99</a></p>
|
|
<p id='n100' class='pln'><a href='#n100'>100</a></p>
|
|
<p id='n101' class='pln'><a href='#n101'>101</a></p>
|
|
<p id='n102' class='pln'><a href='#n102'>102</a></p>
|
|
<p id='n103' class='pln'><a href='#n103'>103</a></p>
|
|
<p id='n104' class='pln'><a href='#n104'>104</a></p>
|
|
<p id='n105' class='pln'><a href='#n105'>105</a></p>
|
|
<p id='n106' class='pln'><a href='#n106'>106</a></p>
|
|
<p id='n107' class='pln'><a href='#n107'>107</a></p>
|
|
<p id='n108' class='pln'><a href='#n108'>108</a></p>
|
|
<p id='n109' class='stm run hide_run'><a href='#n109'>109</a></p>
|
|
<p id='n110' class='pln'><a href='#n110'>110</a></p>
|
|
<p id='n111' class='stm run hide_run'><a href='#n111'>111</a></p>
|
|
<p id='n112' class='pln'><a href='#n112'>112</a></p>
|
|
<p id='n113' class='pln'><a href='#n113'>113</a></p>
|
|
<p id='n114' class='pln'><a href='#n114'>114</a></p>
|
|
<p id='n115' class='pln'><a href='#n115'>115</a></p>
|
|
<p id='n116' class='stm run hide_run'><a href='#n116'>116</a></p>
|
|
<p id='n117' class='pln'><a href='#n117'>117</a></p>
|
|
<p id='n118' class='pln'><a href='#n118'>118</a></p>
|
|
<p id='n119' class='pln'><a href='#n119'>119</a></p>
|
|
<p id='n120' class='stm run hide_run'><a href='#n120'>120</a></p>
|
|
<p id='n121' class='pln'><a href='#n121'>121</a></p>
|
|
<p id='n122' class='stm run hide_run'><a href='#n122'>122</a></p>
|
|
<p id='n123' class='stm run hide_run'><a href='#n123'>123</a></p>
|
|
<p id='n124' class='stm run hide_run'><a href='#n124'>124</a></p>
|
|
<p id='n125' class='pln'><a href='#n125'>125</a></p>
|
|
<p id='n126' class='stm run hide_run'><a href='#n126'>126</a></p>
|
|
<p id='n127' class='stm mis'><a href='#n127'>127</a></p>
|
|
<p id='n128' class='pln'><a href='#n128'>128</a></p>
|
|
<p id='n129' class='pln'><a href='#n129'>129</a></p>
|
|
<p id='n130' class='pln'><a href='#n130'>130</a></p>
|
|
<p id='n131' class='stm run hide_run'><a href='#n131'>131</a></p>
|
|
<p id='n132' class='stm mis'><a href='#n132'>132</a></p>
|
|
<p id='n133' class='pln'><a href='#n133'>133</a></p>
|
|
<p id='n134' class='stm run hide_run'><a href='#n134'>134</a></p>
|
|
<p id='n135' class='pln'><a href='#n135'>135</a></p>
|
|
<p id='n136' class='pln'><a href='#n136'>136</a></p>
|
|
<p id='n137' class='stm run hide_run'><a href='#n137'>137</a></p>
|
|
<p id='n138' class='pln'><a href='#n138'>138</a></p>
|
|
<p id='n139' class='stm run hide_run'><a href='#n139'>139</a></p>
|
|
<p id='n140' class='pln'><a href='#n140'>140</a></p>
|
|
<p id='n141' class='pln'><a href='#n141'>141</a></p>
|
|
<p id='n142' class='stm run hide_run'><a href='#n142'>142</a></p>
|
|
<p id='n143' class='stm run hide_run'><a href='#n143'>143</a></p>
|
|
<p id='n144' class='pln'><a href='#n144'>144</a></p>
|
|
<p id='n145' class='pln'><a href='#n145'>145</a></p>
|
|
<p id='n146' class='stm run hide_run'><a href='#n146'>146</a></p>
|
|
<p id='n147' class='pln'><a href='#n147'>147</a></p>
|
|
<p id='n148' class='pln'><a href='#n148'>148</a></p>
|
|
<p id='n149' class='pln'><a href='#n149'>149</a></p>
|
|
<p id='n150' class='pln'><a href='#n150'>150</a></p>
|
|
<p id='n151' class='stm run hide_run'><a href='#n151'>151</a></p>
|
|
<p id='n152' class='pln'><a href='#n152'>152</a></p>
|
|
<p id='n153' class='pln'><a href='#n153'>153</a></p>
|
|
<p id='n154' class='stm run hide_run'><a href='#n154'>154</a></p>
|
|
<p id='n155' class='pln'><a href='#n155'>155</a></p>
|
|
<p id='n156' class='pln'><a href='#n156'>156</a></p>
|
|
<p id='n157' class='pln'><a href='#n157'>157</a></p>
|
|
<p id='n158' class='pln'><a href='#n158'>158</a></p>
|
|
<p id='n159' class='stm run hide_run'><a href='#n159'>159</a></p>
|
|
<p id='n160' class='stm run hide_run'><a href='#n160'>160</a></p>
|
|
<p id='n161' class='stm run hide_run'><a href='#n161'>161</a></p>
|
|
<p id='n162' class='pln'><a href='#n162'>162</a></p>
|
|
<p id='n163' class='stm run hide_run'><a href='#n163'>163</a></p>
|
|
<p id='n164' class='stm mis'><a href='#n164'>164</a></p>
|
|
<p id='n165' class='pln'><a href='#n165'>165</a></p>
|
|
<p id='n166' class='stm run hide_run'><a href='#n166'>166</a></p>
|
|
<p id='n167' class='stm run hide_run'><a href='#n167'>167</a></p>
|
|
<p id='n168' class='stm run hide_run'><a href='#n168'>168</a></p>
|
|
<p id='n169' class='stm run hide_run'><a href='#n169'>169</a></p>
|
|
<p id='n170' class='stm run hide_run'><a href='#n170'>170</a></p>
|
|
<p id='n171' class='pln'><a href='#n171'>171</a></p>
|
|
<p id='n172' class='stm mis'><a href='#n172'>172</a></p>
|
|
<p id='n173' class='pln'><a href='#n173'>173</a></p>
|
|
<p id='n174' class='pln'><a href='#n174'>174</a></p>
|
|
|
|
</td>
|
|
<td class='text' valign='top'>
|
|
<p id='t1' class='pln'><span class='str'>"""</span><span class='strut'> </span></p>
|
|
<p id='t2' class='pln'><span class='str'>Provides a set of pluggable permission policies.</span><span class='strut'> </span></p>
|
|
<p id='t3' class='pln'><span class='str'>"""</span><span class='strut'> </span></p>
|
|
<p id='t4' class='stm run hide_run'><span class='key'>from</span> <span class='nam'>__future__</span> <span class='key'>import</span> <span class='nam'>unicode_literals</span><span class='strut'> </span></p>
|
|
<p id='t5' class='stm run hide_run'><span class='key'>import</span> <span class='nam'>inspect</span><span class='strut'> </span></p>
|
|
<p id='t6' class='stm run hide_run'><span class='key'>import</span> <span class='nam'>warnings</span><span class='strut'> </span></p>
|
|
<p id='t7' class='pln'><span class='strut'> </span></p>
|
|
<p id='t8' class='stm run hide_run'><span class='nam'>SAFE_METHODS</span> <span class='op'>=</span> <span class='op'>[</span><span class='str'>'GET'</span><span class='op'>,</span> <span class='str'>'HEAD'</span><span class='op'>,</span> <span class='str'>'OPTIONS'</span><span class='op'>]</span><span class='strut'> </span></p>
|
|
<p id='t9' class='pln'><span class='strut'> </span></p>
|
|
<p id='t10' class='stm run hide_run'><span class='key'>from</span> <span class='nam'>rest_framework</span><span class='op'>.</span><span class='nam'>compat</span> <span class='key'>import</span> <span class='nam'>oauth2_provider_scope</span><span class='op'>,</span> <span class='nam'>oauth2_constants</span><span class='strut'> </span></p>
|
|
<p id='t11' class='pln'><span class='strut'> </span></p>
|
|
<p id='t12' class='pln'><span class='strut'> </span></p>
|
|
<p id='t13' class='stm run hide_run'><span class='key'>class</span> <span class='nam'>BasePermission</span><span class='op'>(</span><span class='nam'>object</span><span class='op'>)</span><span class='op'>:</span><span class='strut'> </span></p>
|
|
<p id='t14' class='pln'> <span class='str'>"""</span><span class='strut'> </span></p>
|
|
<p id='t15' class='pln'><span class='str'> A base class from which all permission classes should inherit.</span><span class='strut'> </span></p>
|
|
<p id='t16' class='pln'><span class='str'> """</span><span class='strut'> </span></p>
|
|
<p id='t17' class='pln'><span class='strut'> </span></p>
|
|
<p id='t18' class='stm run hide_run'> <span class='key'>def</span> <span class='nam'>has_permission</span><span class='op'>(</span><span class='nam'>self</span><span class='op'>,</span> <span class='nam'>request</span><span class='op'>,</span> <span class='nam'>view</span><span class='op'>)</span><span class='op'>:</span><span class='strut'> </span></p>
|
|
<p id='t19' class='pln'> <span class='str'>"""</span><span class='strut'> </span></p>
|
|
<p id='t20' class='pln'><span class='str'> Return `True` if permission is granted, `False` otherwise.</span><span class='strut'> </span></p>
|
|
<p id='t21' class='pln'><span class='str'> """</span><span class='strut'> </span></p>
|
|
<p id='t22' class='stm run hide_run'> <span class='key'>return</span> <span class='nam'>True</span><span class='strut'> </span></p>
|
|
<p id='t23' class='pln'><span class='strut'> </span></p>
|
|
<p id='t24' class='stm run hide_run'> <span class='key'>def</span> <span class='nam'>has_object_permission</span><span class='op'>(</span><span class='nam'>self</span><span class='op'>,</span> <span class='nam'>request</span><span class='op'>,</span> <span class='nam'>view</span><span class='op'>,</span> <span class='nam'>obj</span><span class='op'>)</span><span class='op'>:</span><span class='strut'> </span></p>
|
|
<p id='t25' class='pln'> <span class='str'>"""</span><span class='strut'> </span></p>
|
|
<p id='t26' class='pln'><span class='str'> Return `True` if permission is granted, `False` otherwise.</span><span class='strut'> </span></p>
|
|
<p id='t27' class='pln'><span class='str'> """</span><span class='strut'> </span></p>
|
|
<p id='t28' class='stm run hide_run'> <span class='key'>if</span> <span class='nam'>len</span><span class='op'>(</span><span class='nam'>inspect</span><span class='op'>.</span><span class='nam'>getargspec</span><span class='op'>(</span><span class='nam'>self</span><span class='op'>.</span><span class='nam'>has_permission</span><span class='op'>)</span><span class='op'>.</span><span class='nam'>args</span><span class='op'>)</span> <span class='op'>==</span> <span class='num'>4</span><span class='op'>:</span><span class='strut'> </span></p>
|
|
<p id='t29' class='stm mis'> <span class='nam'>warnings</span><span class='op'>.</span><span class='nam'>warn</span><span class='op'>(</span><span class='strut'> </span></p>
|
|
<p id='t30' class='pln'> <span class='str'>'The `obj` argument in `has_permission` is deprecated. '</span><span class='strut'> </span></p>
|
|
<p id='t31' class='pln'> <span class='str'>'Use `has_object_permission()` instead for object permissions.'</span><span class='op'>,</span><span class='strut'> </span></p>
|
|
<p id='t32' class='pln'> <span class='nam'>DeprecationWarning</span><span class='op'>,</span> <span class='nam'>stacklevel</span><span class='op'>=</span><span class='num'>2</span><span class='strut'> </span></p>
|
|
<p id='t33' class='pln'> <span class='op'>)</span><span class='strut'> </span></p>
|
|
<p id='t34' class='stm mis'> <span class='key'>return</span> <span class='nam'>self</span><span class='op'>.</span><span class='nam'>has_permission</span><span class='op'>(</span><span class='nam'>request</span><span class='op'>,</span> <span class='nam'>view</span><span class='op'>,</span> <span class='nam'>obj</span><span class='op'>)</span><span class='strut'> </span></p>
|
|
<p id='t35' class='stm run hide_run'> <span class='key'>return</span> <span class='nam'>True</span><span class='strut'> </span></p>
|
|
<p id='t36' class='pln'><span class='strut'> </span></p>
|
|
<p id='t37' class='pln'><span class='strut'> </span></p>
|
|
<p id='t38' class='stm run hide_run'><span class='key'>class</span> <span class='nam'>AllowAny</span><span class='op'>(</span><span class='nam'>BasePermission</span><span class='op'>)</span><span class='op'>:</span><span class='strut'> </span></p>
|
|
<p id='t39' class='pln'> <span class='str'>"""</span><span class='strut'> </span></p>
|
|
<p id='t40' class='pln'><span class='str'> Allow any access.</span><span class='strut'> </span></p>
|
|
<p id='t41' class='pln'><span class='str'> This isn't strictly required, since you could use an empty</span><span class='strut'> </span></p>
|
|
<p id='t42' class='pln'><span class='str'> permission_classes list, but it's useful because it makes the intention</span><span class='strut'> </span></p>
|
|
<p id='t43' class='pln'><span class='str'> more explicit.</span><span class='strut'> </span></p>
|
|
<p id='t44' class='pln'><span class='str'> """</span><span class='strut'> </span></p>
|
|
<p id='t45' class='stm run hide_run'> <span class='key'>def</span> <span class='nam'>has_permission</span><span class='op'>(</span><span class='nam'>self</span><span class='op'>,</span> <span class='nam'>request</span><span class='op'>,</span> <span class='nam'>view</span><span class='op'>)</span><span class='op'>:</span><span class='strut'> </span></p>
|
|
<p id='t46' class='stm run hide_run'> <span class='key'>return</span> <span class='nam'>True</span><span class='strut'> </span></p>
|
|
<p id='t47' class='pln'><span class='strut'> </span></p>
|
|
<p id='t48' class='pln'><span class='strut'> </span></p>
|
|
<p id='t49' class='stm run hide_run'><span class='key'>class</span> <span class='nam'>IsAuthenticated</span><span class='op'>(</span><span class='nam'>BasePermission</span><span class='op'>)</span><span class='op'>:</span><span class='strut'> </span></p>
|
|
<p id='t50' class='pln'> <span class='str'>"""</span><span class='strut'> </span></p>
|
|
<p id='t51' class='pln'><span class='str'> Allows access only to authenticated users.</span><span class='strut'> </span></p>
|
|
<p id='t52' class='pln'><span class='str'> """</span><span class='strut'> </span></p>
|
|
<p id='t53' class='pln'><span class='strut'> </span></p>
|
|
<p id='t54' class='stm run hide_run'> <span class='key'>def</span> <span class='nam'>has_permission</span><span class='op'>(</span><span class='nam'>self</span><span class='op'>,</span> <span class='nam'>request</span><span class='op'>,</span> <span class='nam'>view</span><span class='op'>)</span><span class='op'>:</span><span class='strut'> </span></p>
|
|
<p id='t55' class='stm run hide_run'> <span class='key'>if</span> <span class='nam'>request</span><span class='op'>.</span><span class='nam'>user</span> <span class='key'>and</span> <span class='nam'>request</span><span class='op'>.</span><span class='nam'>user</span><span class='op'>.</span><span class='nam'>is_authenticated</span><span class='op'>(</span><span class='op'>)</span><span class='op'>:</span><span class='strut'> </span></p>
|
|
<p id='t56' class='stm run hide_run'> <span class='key'>return</span> <span class='nam'>True</span><span class='strut'> </span></p>
|
|
<p id='t57' class='stm run hide_run'> <span class='key'>return</span> <span class='nam'>False</span><span class='strut'> </span></p>
|
|
<p id='t58' class='pln'><span class='strut'> </span></p>
|
|
<p id='t59' class='pln'><span class='strut'> </span></p>
|
|
<p id='t60' class='stm run hide_run'><span class='key'>class</span> <span class='nam'>IsAdminUser</span><span class='op'>(</span><span class='nam'>BasePermission</span><span class='op'>)</span><span class='op'>:</span><span class='strut'> </span></p>
|
|
<p id='t61' class='pln'> <span class='str'>"""</span><span class='strut'> </span></p>
|
|
<p id='t62' class='pln'><span class='str'> Allows access only to admin users.</span><span class='strut'> </span></p>
|
|
<p id='t63' class='pln'><span class='str'> """</span><span class='strut'> </span></p>
|
|
<p id='t64' class='pln'><span class='strut'> </span></p>
|
|
<p id='t65' class='stm run hide_run'> <span class='key'>def</span> <span class='nam'>has_permission</span><span class='op'>(</span><span class='nam'>self</span><span class='op'>,</span> <span class='nam'>request</span><span class='op'>,</span> <span class='nam'>view</span><span class='op'>)</span><span class='op'>:</span><span class='strut'> </span></p>
|
|
<p id='t66' class='stm mis'> <span class='key'>if</span> <span class='nam'>request</span><span class='op'>.</span><span class='nam'>user</span> <span class='key'>and</span> <span class='nam'>request</span><span class='op'>.</span><span class='nam'>user</span><span class='op'>.</span><span class='nam'>is_staff</span><span class='op'>:</span><span class='strut'> </span></p>
|
|
<p id='t67' class='stm mis'> <span class='key'>return</span> <span class='nam'>True</span><span class='strut'> </span></p>
|
|
<p id='t68' class='stm mis'> <span class='key'>return</span> <span class='nam'>False</span><span class='strut'> </span></p>
|
|
<p id='t69' class='pln'><span class='strut'> </span></p>
|
|
<p id='t70' class='pln'><span class='strut'> </span></p>
|
|
<p id='t71' class='stm run hide_run'><span class='key'>class</span> <span class='nam'>IsAuthenticatedOrReadOnly</span><span class='op'>(</span><span class='nam'>BasePermission</span><span class='op'>)</span><span class='op'>:</span><span class='strut'> </span></p>
|
|
<p id='t72' class='pln'> <span class='str'>"""</span><span class='strut'> </span></p>
|
|
<p id='t73' class='pln'><span class='str'> The request is authenticated as a user, or is a read-only request.</span><span class='strut'> </span></p>
|
|
<p id='t74' class='pln'><span class='str'> """</span><span class='strut'> </span></p>
|
|
<p id='t75' class='pln'><span class='strut'> </span></p>
|
|
<p id='t76' class='stm run hide_run'> <span class='key'>def</span> <span class='nam'>has_permission</span><span class='op'>(</span><span class='nam'>self</span><span class='op'>,</span> <span class='nam'>request</span><span class='op'>,</span> <span class='nam'>view</span><span class='op'>)</span><span class='op'>:</span><span class='strut'> </span></p>
|
|
<p id='t77' class='stm mis'> <span class='key'>if</span> <span class='op'>(</span><span class='nam'>request</span><span class='op'>.</span><span class='nam'>method</span> <span class='key'>in</span> <span class='nam'>SAFE_METHODS</span> <span class='key'>or</span><span class='strut'> </span></p>
|
|
<p id='t78' class='pln'> <span class='nam'>request</span><span class='op'>.</span><span class='nam'>user</span> <span class='key'>and</span><span class='strut'> </span></p>
|
|
<p id='t79' class='pln'> <span class='nam'>request</span><span class='op'>.</span><span class='nam'>user</span><span class='op'>.</span><span class='nam'>is_authenticated</span><span class='op'>(</span><span class='op'>)</span><span class='op'>)</span><span class='op'>:</span><span class='strut'> </span></p>
|
|
<p id='t80' class='stm mis'> <span class='key'>return</span> <span class='nam'>True</span><span class='strut'> </span></p>
|
|
<p id='t81' class='stm mis'> <span class='key'>return</span> <span class='nam'>False</span><span class='strut'> </span></p>
|
|
<p id='t82' class='pln'><span class='strut'> </span></p>
|
|
<p id='t83' class='pln'><span class='strut'> </span></p>
|
|
<p id='t84' class='stm run hide_run'><span class='key'>class</span> <span class='nam'>DjangoModelPermissions</span><span class='op'>(</span><span class='nam'>BasePermission</span><span class='op'>)</span><span class='op'>:</span><span class='strut'> </span></p>
|
|
<p id='t85' class='pln'> <span class='str'>"""</span><span class='strut'> </span></p>
|
|
<p id='t86' class='pln'><span class='str'> The request is authenticated using `django.contrib.auth` permissions.</span><span class='strut'> </span></p>
|
|
<p id='t87' class='pln'><span class='str'> See: https://docs.djangoproject.com/en/dev/topics/auth/#permissions</span><span class='strut'> </span></p>
|
|
<p id='t88' class='pln'><span class='strut'> </span></p>
|
|
<p id='t89' class='pln'><span class='str'> It ensures that the user is authenticated, and has the appropriate</span><span class='strut'> </span></p>
|
|
<p id='t90' class='pln'><span class='str'> `add`/`change`/`delete` permissions on the model.</span><span class='strut'> </span></p>
|
|
<p id='t91' class='pln'><span class='strut'> </span></p>
|
|
<p id='t92' class='pln'><span class='str'> This permission can only be applied against view classes that</span><span class='strut'> </span></p>
|
|
<p id='t93' class='pln'><span class='str'> provide a `.model` or `.queryset` attribute.</span><span class='strut'> </span></p>
|
|
<p id='t94' class='pln'><span class='str'> """</span><span class='strut'> </span></p>
|
|
<p id='t95' class='pln'><span class='strut'> </span></p>
|
|
<p id='t96' class='pln'> <span class='com'># Map methods into required permission codes.</span><span class='strut'> </span></p>
|
|
<p id='t97' class='pln'> <span class='com'># Override this if you need to also provide 'view' permissions,</span><span class='strut'> </span></p>
|
|
<p id='t98' class='pln'> <span class='com'># or if you want to provide custom permission codes.</span><span class='strut'> </span></p>
|
|
<p id='t99' class='stm run hide_run'> <span class='nam'>perms_map</span> <span class='op'>=</span> <span class='op'>{</span><span class='strut'> </span></p>
|
|
<p id='t100' class='pln'> <span class='str'>'GET'</span><span class='op'>:</span> <span class='op'>[</span><span class='op'>]</span><span class='op'>,</span><span class='strut'> </span></p>
|
|
<p id='t101' class='pln'> <span class='str'>'OPTIONS'</span><span class='op'>:</span> <span class='op'>[</span><span class='op'>]</span><span class='op'>,</span><span class='strut'> </span></p>
|
|
<p id='t102' class='pln'> <span class='str'>'HEAD'</span><span class='op'>:</span> <span class='op'>[</span><span class='op'>]</span><span class='op'>,</span><span class='strut'> </span></p>
|
|
<p id='t103' class='pln'> <span class='str'>'POST'</span><span class='op'>:</span> <span class='op'>[</span><span class='str'>'%(app_label)s.add_%(model_name)s'</span><span class='op'>]</span><span class='op'>,</span><span class='strut'> </span></p>
|
|
<p id='t104' class='pln'> <span class='str'>'PUT'</span><span class='op'>:</span> <span class='op'>[</span><span class='str'>'%(app_label)s.change_%(model_name)s'</span><span class='op'>]</span><span class='op'>,</span><span class='strut'> </span></p>
|
|
<p id='t105' class='pln'> <span class='str'>'PATCH'</span><span class='op'>:</span> <span class='op'>[</span><span class='str'>'%(app_label)s.change_%(model_name)s'</span><span class='op'>]</span><span class='op'>,</span><span class='strut'> </span></p>
|
|
<p id='t106' class='pln'> <span class='str'>'DELETE'</span><span class='op'>:</span> <span class='op'>[</span><span class='str'>'%(app_label)s.delete_%(model_name)s'</span><span class='op'>]</span><span class='op'>,</span><span class='strut'> </span></p>
|
|
<p id='t107' class='pln'> <span class='op'>}</span><span class='strut'> </span></p>
|
|
<p id='t108' class='pln'><span class='strut'> </span></p>
|
|
<p id='t109' class='stm run hide_run'> <span class='nam'>authenticated_users_only</span> <span class='op'>=</span> <span class='nam'>True</span><span class='strut'> </span></p>
|
|
<p id='t110' class='pln'><span class='strut'> </span></p>
|
|
<p id='t111' class='stm run hide_run'> <span class='key'>def</span> <span class='nam'>get_required_permissions</span><span class='op'>(</span><span class='nam'>self</span><span class='op'>,</span> <span class='nam'>method</span><span class='op'>,</span> <span class='nam'>model_cls</span><span class='op'>)</span><span class='op'>:</span><span class='strut'> </span></p>
|
|
<p id='t112' class='pln'> <span class='str'>"""</span><span class='strut'> </span></p>
|
|
<p id='t113' class='pln'><span class='str'> Given a model and an HTTP method, return the list of permission</span><span class='strut'> </span></p>
|
|
<p id='t114' class='pln'><span class='str'> codes that the user is required to have.</span><span class='strut'> </span></p>
|
|
<p id='t115' class='pln'><span class='str'> """</span><span class='strut'> </span></p>
|
|
<p id='t116' class='stm run hide_run'> <span class='nam'>kwargs</span> <span class='op'>=</span> <span class='op'>{</span><span class='strut'> </span></p>
|
|
<p id='t117' class='pln'> <span class='str'>'app_label'</span><span class='op'>:</span> <span class='nam'>model_cls</span><span class='op'>.</span><span class='nam'>_meta</span><span class='op'>.</span><span class='nam'>app_label</span><span class='op'>,</span><span class='strut'> </span></p>
|
|
<p id='t118' class='pln'> <span class='str'>'model_name'</span><span class='op'>:</span> <span class='nam'>model_cls</span><span class='op'>.</span><span class='nam'>_meta</span><span class='op'>.</span><span class='nam'>module_name</span><span class='strut'> </span></p>
|
|
<p id='t119' class='pln'> <span class='op'>}</span><span class='strut'> </span></p>
|
|
<p id='t120' class='stm run hide_run'> <span class='key'>return</span> <span class='op'>[</span><span class='nam'>perm</span> <span class='op'>%</span> <span class='nam'>kwargs</span> <span class='key'>for</span> <span class='nam'>perm</span> <span class='key'>in</span> <span class='nam'>self</span><span class='op'>.</span><span class='nam'>perms_map</span><span class='op'>[</span><span class='nam'>method</span><span class='op'>]</span><span class='op'>]</span><span class='strut'> </span></p>
|
|
<p id='t121' class='pln'><span class='strut'> </span></p>
|
|
<p id='t122' class='stm run hide_run'> <span class='key'>def</span> <span class='nam'>has_permission</span><span class='op'>(</span><span class='nam'>self</span><span class='op'>,</span> <span class='nam'>request</span><span class='op'>,</span> <span class='nam'>view</span><span class='op'>)</span><span class='op'>:</span><span class='strut'> </span></p>
|
|
<p id='t123' class='stm run hide_run'> <span class='nam'>model_cls</span> <span class='op'>=</span> <span class='nam'>getattr</span><span class='op'>(</span><span class='nam'>view</span><span class='op'>,</span> <span class='str'>'model'</span><span class='op'>,</span> <span class='nam'>None</span><span class='op'>)</span><span class='strut'> </span></p>
|
|
<p id='t124' class='stm run hide_run'> <span class='nam'>queryset</span> <span class='op'>=</span> <span class='nam'>getattr</span><span class='op'>(</span><span class='nam'>view</span><span class='op'>,</span> <span class='str'>'queryset'</span><span class='op'>,</span> <span class='nam'>None</span><span class='op'>)</span><span class='strut'> </span></p>
|
|
<p id='t125' class='pln'><span class='strut'> </span></p>
|
|
<p id='t126' class='stm run hide_run'> <span class='key'>if</span> <span class='nam'>model_cls</span> <span class='key'>is</span> <span class='nam'>None</span> <span class='key'>and</span> <span class='nam'>queryset</span> <span class='key'>is</span> <span class='key'>not</span> <span class='nam'>None</span><span class='op'>:</span><span class='strut'> </span></p>
|
|
<p id='t127' class='stm mis'> <span class='nam'>model_cls</span> <span class='op'>=</span> <span class='nam'>queryset</span><span class='op'>.</span><span class='nam'>model</span><span class='strut'> </span></p>
|
|
<p id='t128' class='pln'><span class='strut'> </span></p>
|
|
<p id='t129' class='pln'> <span class='com'># Workaround to ensure DjangoModelPermissions are not applied</span><span class='strut'> </span></p>
|
|
<p id='t130' class='pln'> <span class='com'># to the root view when using DefaultRouter.</span><span class='strut'> </span></p>
|
|
<p id='t131' class='stm run hide_run'> <span class='key'>if</span> <span class='nam'>model_cls</span> <span class='key'>is</span> <span class='nam'>None</span> <span class='key'>and</span> <span class='nam'>getattr</span><span class='op'>(</span><span class='nam'>view</span><span class='op'>,</span> <span class='str'>'_ignore_model_permissions'</span><span class='op'>,</span> <span class='nam'>False</span><span class='op'>)</span><span class='op'>:</span><span class='strut'> </span></p>
|
|
<p id='t132' class='stm mis'> <span class='key'>return</span> <span class='nam'>True</span><span class='strut'> </span></p>
|
|
<p id='t133' class='pln'><span class='strut'> </span></p>
|
|
<p id='t134' class='stm run hide_run'> <span class='key'>assert</span> <span class='nam'>model_cls</span><span class='op'>,</span> <span class='op'>(</span><span class='str'>'Cannot apply DjangoModelPermissions on a view that'</span><span class='strut'> </span></p>
|
|
<p id='t135' class='pln'> <span class='str'>' does not have `.model` or `.queryset` property.'</span><span class='op'>)</span><span class='strut'> </span></p>
|
|
<p id='t136' class='pln'><span class='strut'> </span></p>
|
|
<p id='t137' class='stm run hide_run'> <span class='nam'>perms</span> <span class='op'>=</span> <span class='nam'>self</span><span class='op'>.</span><span class='nam'>get_required_permissions</span><span class='op'>(</span><span class='nam'>request</span><span class='op'>.</span><span class='nam'>method</span><span class='op'>,</span> <span class='nam'>model_cls</span><span class='op'>)</span><span class='strut'> </span></p>
|
|
<p id='t138' class='pln'><span class='strut'> </span></p>
|
|
<p id='t139' class='stm run hide_run'> <span class='key'>if</span> <span class='op'>(</span><span class='nam'>request</span><span class='op'>.</span><span class='nam'>user</span> <span class='key'>and</span><span class='strut'> </span></p>
|
|
<p id='t140' class='pln'> <span class='op'>(</span><span class='nam'>request</span><span class='op'>.</span><span class='nam'>user</span><span class='op'>.</span><span class='nam'>is_authenticated</span><span class='op'>(</span><span class='op'>)</span> <span class='key'>or</span> <span class='key'>not</span> <span class='nam'>self</span><span class='op'>.</span><span class='nam'>authenticated_users_only</span><span class='op'>)</span> <span class='key'>and</span><span class='strut'> </span></p>
|
|
<p id='t141' class='pln'> <span class='nam'>request</span><span class='op'>.</span><span class='nam'>user</span><span class='op'>.</span><span class='nam'>has_perms</span><span class='op'>(</span><span class='nam'>perms</span><span class='op'>)</span><span class='op'>)</span><span class='op'>:</span><span class='strut'> </span></p>
|
|
<p id='t142' class='stm run hide_run'> <span class='key'>return</span> <span class='nam'>True</span><span class='strut'> </span></p>
|
|
<p id='t143' class='stm run hide_run'> <span class='key'>return</span> <span class='nam'>False</span><span class='strut'> </span></p>
|
|
<p id='t144' class='pln'><span class='strut'> </span></p>
|
|
<p id='t145' class='pln'><span class='strut'> </span></p>
|
|
<p id='t146' class='stm run hide_run'><span class='key'>class</span> <span class='nam'>DjangoModelPermissionsOrAnonReadOnly</span><span class='op'>(</span><span class='nam'>DjangoModelPermissions</span><span class='op'>)</span><span class='op'>:</span><span class='strut'> </span></p>
|
|
<p id='t147' class='pln'> <span class='str'>"""</span><span class='strut'> </span></p>
|
|
<p id='t148' class='pln'><span class='str'> Similar to DjangoModelPermissions, except that anonymous users are</span><span class='strut'> </span></p>
|
|
<p id='t149' class='pln'><span class='str'> allowed read-only access.</span><span class='strut'> </span></p>
|
|
<p id='t150' class='pln'><span class='str'> """</span><span class='strut'> </span></p>
|
|
<p id='t151' class='stm run hide_run'> <span class='nam'>authenticated_users_only</span> <span class='op'>=</span> <span class='nam'>False</span><span class='strut'> </span></p>
|
|
<p id='t152' class='pln'><span class='strut'> </span></p>
|
|
<p id='t153' class='pln'><span class='strut'> </span></p>
|
|
<p id='t154' class='stm run hide_run'><span class='key'>class</span> <span class='nam'>TokenHasReadWriteScope</span><span class='op'>(</span><span class='nam'>BasePermission</span><span class='op'>)</span><span class='op'>:</span><span class='strut'> </span></p>
|
|
<p id='t155' class='pln'> <span class='str'>"""</span><span class='strut'> </span></p>
|
|
<p id='t156' class='pln'><span class='str'> The request is authenticated as a user and the token used has the right scope</span><span class='strut'> </span></p>
|
|
<p id='t157' class='pln'><span class='str'> """</span><span class='strut'> </span></p>
|
|
<p id='t158' class='pln'><span class='strut'> </span></p>
|
|
<p id='t159' class='stm run hide_run'> <span class='key'>def</span> <span class='nam'>has_permission</span><span class='op'>(</span><span class='nam'>self</span><span class='op'>,</span> <span class='nam'>request</span><span class='op'>,</span> <span class='nam'>view</span><span class='op'>)</span><span class='op'>:</span><span class='strut'> </span></p>
|
|
<p id='t160' class='stm run hide_run'> <span class='nam'>token</span> <span class='op'>=</span> <span class='nam'>request</span><span class='op'>.</span><span class='nam'>auth</span><span class='strut'> </span></p>
|
|
<p id='t161' class='stm run hide_run'> <span class='nam'>read_only</span> <span class='op'>=</span> <span class='nam'>request</span><span class='op'>.</span><span class='nam'>method</span> <span class='key'>in</span> <span class='nam'>SAFE_METHODS</span><span class='strut'> </span></p>
|
|
<p id='t162' class='pln'><span class='strut'> </span></p>
|
|
<p id='t163' class='stm run hide_run'> <span class='key'>if</span> <span class='key'>not</span> <span class='nam'>token</span><span class='op'>:</span><span class='strut'> </span></p>
|
|
<p id='t164' class='stm mis'> <span class='key'>return</span> <span class='nam'>False</span><span class='strut'> </span></p>
|
|
<p id='t165' class='pln'><span class='strut'> </span></p>
|
|
<p id='t166' class='stm run hide_run'> <span class='key'>if</span> <span class='nam'>hasattr</span><span class='op'>(</span><span class='nam'>token</span><span class='op'>,</span> <span class='str'>'resource'</span><span class='op'>)</span><span class='op'>:</span> <span class='com'># OAuth 1</span><span class='strut'> </span></p>
|
|
<p id='t167' class='stm run hide_run'> <span class='key'>return</span> <span class='nam'>read_only</span> <span class='key'>or</span> <span class='key'>not</span> <span class='nam'>request</span><span class='op'>.</span><span class='nam'>auth</span><span class='op'>.</span><span class='nam'>resource</span><span class='op'>.</span><span class='nam'>is_readonly</span><span class='strut'> </span></p>
|
|
<p id='t168' class='stm run hide_run'> <span class='key'>elif</span> <span class='nam'>hasattr</span><span class='op'>(</span><span class='nam'>token</span><span class='op'>,</span> <span class='str'>'scope'</span><span class='op'>)</span><span class='op'>:</span> <span class='com'># OAuth 2</span><span class='strut'> </span></p>
|
|
<p id='t169' class='stm run hide_run'> <span class='nam'>required</span> <span class='op'>=</span> <span class='nam'>oauth2_constants</span><span class='op'>.</span><span class='nam'>READ</span> <span class='key'>if</span> <span class='nam'>read_only</span> <span class='key'>else</span> <span class='nam'>oauth2_constants</span><span class='op'>.</span><span class='nam'>WRITE</span><span class='strut'> </span></p>
|
|
<p id='t170' class='stm run hide_run'> <span class='key'>return</span> <span class='nam'>oauth2_provider_scope</span><span class='op'>.</span><span class='nam'>check</span><span class='op'>(</span><span class='nam'>required</span><span class='op'>,</span> <span class='nam'>request</span><span class='op'>.</span><span class='nam'>auth</span><span class='op'>.</span><span class='nam'>scope</span><span class='op'>)</span><span class='strut'> </span></p>
|
|
<p id='t171' class='pln'><span class='strut'> </span></p>
|
|
<p id='t172' class='stm mis'> <span class='key'>assert</span> <span class='nam'>False</span><span class='op'>,</span> <span class='op'>(</span><span class='str'>'TokenHasReadWriteScope requires either the'</span><span class='strut'> </span></p>
|
|
<p id='t173' class='pln'> <span class='str'>'`OAuthAuthentication` or `OAuth2Authentication` authentication '</span><span class='strut'> </span></p>
|
|
<p id='t174' class='pln'> <span class='str'>'class to be used.'</span><span class='op'>)</span><span class='strut'> </span></p>
|
|
|
|
</td>
|
|
</tr>
|
|
</table>
|
|
</div>
|
|
|
|
<div id='footer'>
|
|
<div class='content'>
|
|
<p>
|
|
<a class='nav' href='index.html'>« index</a> <a class='nav' href='http://nedbatchelder.com/code/coverage'>coverage.py v3.5.1</a>
|
|
</p>
|
|
</div>
|
|
</div>
|
|
|
|
</body>
|
|
</html>
|