Add JWT auth with per-user data isolation and account settings.
Users can register, log in, and manage profile/password in a personal account page; server data is scoped by owner across contacts, maps, tags, and import. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -0,0 +1,25 @@
|
||||
from rest_framework.exceptions import PermissionDenied
|
||||
|
||||
from core.access import use_jwt_auth
|
||||
|
||||
|
||||
class OwnerScopedMixin:
|
||||
owner_field = 'owner'
|
||||
|
||||
def get_queryset(self):
|
||||
qs = super().get_queryset()
|
||||
if not use_jwt_auth():
|
||||
return qs
|
||||
user = self.request.user
|
||||
if user and user.is_authenticated:
|
||||
return qs.filter(**{self.owner_field: user})
|
||||
return qs.none()
|
||||
|
||||
def perform_create(self, serializer):
|
||||
if use_jwt_auth():
|
||||
user = self.request.user
|
||||
if not user or not user.is_authenticated:
|
||||
raise PermissionDenied()
|
||||
serializer.save(**{self.owner_field: user})
|
||||
return
|
||||
serializer.save()
|
||||
Reference in New Issue
Block a user