threadposts.py 4.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142
  1. from django.core.exceptions import PermissionDenied
  2. from django.utils.translation import ugettext as _
  3. from rest_framework import viewsets
  4. from rest_framework.decorators import detail_route, list_route
  5. from rest_framework.response import Response
  6. from misago.core.shortcuts import get_int_or_404
  7. from misago.users.online.utils import make_users_status_aware
  8. from ..models import Post
  9. from ..permissions.threads import allow_edit_post, allow_reply_thread
  10. from ..serializers import PostSerializer
  11. from ..viewmodels.post import ThreadPost
  12. from ..viewmodels.posts import ThreadPosts
  13. from ..viewmodels.thread import ForumThread
  14. from .postingendpoint import PostingEndpoint
  15. class ViewSet(viewsets.ViewSet):
  16. thread = None
  17. posts = None
  18. def get_thread(self, request, pk):
  19. return self.thread(request, get_int_or_404(pk), read_aware=True, subscription_aware=True)
  20. def get_posts(self, request, thread, page):
  21. return self.posts(request, thread, page)
  22. def create(self, request, thread_pk):
  23. thread = self.thread(request, get_int_or_404(thread_pk))
  24. allow_reply_thread(request.user, thread.thread)
  25. post = Post(thread=thread.thread, category=thread.category)
  26. # Put them through posting pipeline
  27. posting = PostingEndpoint(
  28. request,
  29. PostingEndpoint.REPLY,
  30. thread=thread.thread,
  31. post=post
  32. )
  33. if posting.is_valid():
  34. user_posts = request.user.posts
  35. posting.save()
  36. # setup extra data for serialization
  37. post.is_read = False
  38. post.is_new = True
  39. post.poster.posts = user_posts + 1
  40. make_users_status_aware(request.user, [post.poster])
  41. return Response(PostSerializer(post).data)
  42. else:
  43. return Response(posting.errors, status=400)
  44. def update(self, request, thread_pk, pk):
  45. thread = self.thread(request, get_int_or_404(thread_pk))
  46. post = ThreadPost(request, thread, get_int_or_404(pk)).post
  47. allow_edit_post(request.user, post)
  48. posting = PostingEndpoint(
  49. request,
  50. PostingEndpoint.EDIT,
  51. thread=thread.thread,
  52. post=post
  53. )
  54. if posting.is_valid():
  55. post_edits = post.edits
  56. posting.save()
  57. post.is_read = True
  58. post.is_new = False
  59. post.edits = post_edits + 1
  60. if post.poster:
  61. make_users_status_aware(request.user, [post.poster])
  62. return Response(PostSerializer(post).data)
  63. else:
  64. return Response(posting.errors, status=400)
  65. return Response({})
  66. def list(self, request, thread_pk):
  67. page = get_int_or_404(request.query_params.get('page', 0))
  68. if page == 1:
  69. page = 0 # api allows explicit first page
  70. thread = self.get_thread(request, thread_pk)
  71. posts = self.get_posts(request, thread, page)
  72. data = thread.get_frontend_context()
  73. data['post_set'] = posts.get_frontend_context()
  74. return Response(data)
  75. @detail_route(methods=['get'], url_path='editor')
  76. def post_editor(self, request, thread_pk, pk):
  77. thread = self.thread(request, get_int_or_404(thread_pk))
  78. post = ThreadPost(request, thread, get_int_or_404(pk)).post
  79. allow_edit_post(request.user, post)
  80. return Response({
  81. 'id': post.pk,
  82. 'api': post.get_api_url(),
  83. 'post': post.original,
  84. 'can_protect': bool(thread.category.acl['can_protect_posts']),
  85. 'is_protected': post.is_protected,
  86. 'poster': post.poster_name
  87. })
  88. @list_route(methods=['get'], url_path='editor')
  89. def reply_editor(self, request, thread_pk):
  90. thread = self.thread(request, get_int_or_404(thread_pk))
  91. allow_reply_thread(request.user, thread.thread)
  92. if 'reply' in request.query_params:
  93. reply_to = ThreadPost(request, thread, get_int_or_404(request.query_params['reply'])).post
  94. if reply_to.is_hidden and not reply_to.acl['can_see_hidden']:
  95. raise PermissionDenied(_("You can't reply to hidden posts"))
  96. return Response({
  97. 'id': reply_to.pk,
  98. 'post': reply_to.original,
  99. 'poster': reply_to.poster_name
  100. })
  101. else:
  102. return Response({})
  103. class ThreadPostsViewSet(ViewSet):
  104. thread = ForumThread
  105. posts = ThreadPosts