rest_permissions.py 1.1 KB

12345678910111213141516171819202122232425262728293031323334353637
  1. from rest_framework.permissions import BasePermission, AllowAny, SAFE_METHODS
  2. from django.core.exceptions import PermissionDenied
  3. from django.utils.translation import ugettext as _
  4. from misago.users.bans import get_request_ip_ban
  5. __all__ = [
  6. 'AllowAny',
  7. 'IsAuthenticatedOrReadOnly',
  8. 'UnbannedAnonOnly'
  9. ]
  10. class IsAuthenticatedOrReadOnly(BasePermission):
  11. def has_permission(self, request, view):
  12. if request.user.is_anonymous() and request.method not in SAFE_METHODS:
  13. raise PermissionDenied(
  14. _("This action is not available to guests."))
  15. else:
  16. return True
  17. class UnbannedAnonOnly(BasePermission):
  18. def has_permission(self, request, view):
  19. if request.user.is_authenticated():
  20. raise PermissionDenied(
  21. _("This action is not available to signed in users."))
  22. ban = get_request_ip_ban(request)
  23. if ban:
  24. raise PermissionDenied(
  25. _("Your IP address is banned from performing this action."),
  26. {'ban': ban.get_serialized_message()})
  27. return True