Add JWT auth with per-user data isolation and account settings.
Users can register, log in, and manage profile/password in a personal account page; server data is scoped by owner across contacts, maps, tags, and import. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -0,0 +1,19 @@
|
||||
from django.conf import settings
|
||||
|
||||
|
||||
def use_jwt_auth():
|
||||
return getattr(settings, 'USE_JWT_AUTH', False)
|
||||
|
||||
|
||||
def scope_by_owner(queryset, user, owner_field='owner'):
|
||||
if not use_jwt_auth():
|
||||
return queryset
|
||||
if user and user.is_authenticated:
|
||||
return queryset.filter(**{owner_field: user})
|
||||
return queryset.none()
|
||||
|
||||
|
||||
def user_workspace_id(user):
|
||||
if user and user.is_authenticated:
|
||||
return str(user.pk)
|
||||
return settings.DEFAULT_WORKSPACE_ID
|
||||
Reference in New Issue
Block a user