Users can register, log in, and manage profile/password in a personal account page; server data is scoped by owner across contacts, maps, tags, and import. Co-authored-by: Cursor <cursoragent@cursor.com>
26 lines
724 B
Python
26 lines
724 B
Python
from rest_framework.exceptions import PermissionDenied
|
|
|
|
from core.access import use_jwt_auth
|
|
|
|
|
|
class OwnerScopedMixin:
|
|
owner_field = 'owner'
|
|
|
|
def get_queryset(self):
|
|
qs = super().get_queryset()
|
|
if not use_jwt_auth():
|
|
return qs
|
|
user = self.request.user
|
|
if user and user.is_authenticated:
|
|
return qs.filter(**{self.owner_field: user})
|
|
return qs.none()
|
|
|
|
def perform_create(self, serializer):
|
|
if use_jwt_auth():
|
|
user = self.request.user
|
|
if not user or not user.is_authenticated:
|
|
raise PermissionDenied()
|
|
serializer.save(**{self.owner_field: user})
|
|
return
|
|
serializer.save()
|