1
0
mirror of https://gitlab.crans.org/bde/nk20 synced 2025-04-27 17:12:38 +00:00

Compare commits

...

20 Commits

Author SHA1 Message Date
thomasl
9a90b1cb5e Merge branch 'respo_comm_permissions' into 'main'
Draft: Respo comm permissions

See merge request bde/nk20!281
2025-02-13 00:54:58 +01:00
thomasl
238ba78f4f Forgot to import PermissionBackend 2025-02-13 00:54:55 +01:00
thomasl
0ec771b5ee Add some security 2025-02-13 00:39:05 +01:00
thomasl
c841fb6068 Some corrections for report_frequency 2025-02-12 23:46:19 +01:00
quark
f6649f155a linters 2025-02-09 16:51:31 +01:00
thomasl
5707abf9e2 Update file views.py 2025-02-09 16:22:03 +01:00
thomasl
056c4029f8 Update file views.py 2025-02-09 16:19:26 +01:00
thomasl
bfd865b3e3 Update file views.py 2025-02-09 16:14:28 +01:00
thomasl
6ceb43cb66 Update file views.py 2025-02-09 16:07:30 +01:00
thomasl
9635004520 Update file views.py 2025-02-09 15:56:12 +01:00
thomasl
05e21ed229 Update file views.py 2025-02-09 15:51:05 +01:00
thomasl
b2ccc4aede Update file views.py 2025-02-09 15:50:13 +01:00
thomasl
6229652dea Update file views.py 2025-02-09 15:47:32 +01:00
thomasl
eee87dcf13 Update file views.py 2025-02-09 15:42:20 +01:00
thomasl
bcf21507e5 Update file views.py 2025-02-09 15:39:08 +01:00
thomasl
6127ced143 Update file views.py 2025-02-09 15:33:37 +01:00
thomasl
f63e5dcb5a Update file views.py 2025-02-09 15:26:39 +01:00
thomasl
73aa0098bf Update file views.py 2025-02-09 15:20:03 +01:00
thomasl
694a5c7bd8 Update file initial.json 2025-02-09 13:05:10 +01:00
thomasl
a4480258d7 Update file initial.json 2025-02-09 12:45:46 +01:00
5 changed files with 104 additions and 18 deletions

View File

@ -15,6 +15,7 @@ from django.utils.translation import gettext_lazy as _
from note.models import NoteSpecial, Alias
from note_kfet.inputs import Autocomplete, AmountInput
from permission.models import PermissionMask, Role
from permission.backends import PermissionBackend
from PIL import Image, ImageSequence
from .models import Profile, Club, Membership
@ -44,10 +45,10 @@ class ProfileForm(forms.ModelForm):
"""
A form for the extras field provided by the :model:`member.Profile` model.
"""
# Remove widget=forms.HiddenInput() if you want to use report frequency.
report_frequency = forms.IntegerField(required=False, initial=0, label=_("Report frequency"), widget=forms.HiddenInput())
last_report = forms.DateTimeField(required=False, disabled=True, label=_("Last report date"))
report_frequency = forms.IntegerField(required=False, initial=0, label=_("Statement frequency (in days)"))
last_report = forms.DateTimeField(required=False, disabled=True, label=_("Last statement date"))
VSS_charter_read = forms.BooleanField(
required=True,
@ -66,6 +67,14 @@ class ProfileForm(forms.ModelForm):
super().__init__(*args, **kwargs)
self.fields['address'].widget.attrs.update({"placeholder": "4 avenue des Sciences, 91190 GIF-SUR-YVETTE"})
self.fields['promotion'].widget.attrs.update({"max": timezone.now().year})
def clean(self):
"""Force the values of fields that the user does not have permission to modify.."""
cleaned_data = super().clean()
for field_name in self.fields.keys():
if not PermissionBackend.check_perm(self.request, f"member.change_profile_{field_name}", self.instance):
cleaned_data[field_name] = getattr(self.instance, field_name) # Force the old value
return cleaned_data
@transaction.atomic
def save(self, commit=True):

View File

@ -114,12 +114,12 @@ class Profile(models.Model):
)
report_frequency = models.PositiveSmallIntegerField(
verbose_name=_("report frequency (in days)"),
verbose_name=_("Statement frequency (in days)"),
default=0,
)
last_report = models.DateTimeField(
verbose_name=_("last report date"),
verbose_name=_("Last statement date"),
default=timezone.now,
)

View File

@ -26,6 +26,7 @@ from note_kfet.middlewares import _set_current_request
from permission.backends import PermissionBackend
from permission.models import Role
from permission.views import ProtectQuerysetMixin, ProtectedCreateView
from django import forms
from .forms import UserForm, ProfileForm, ImageForm, ClubForm, MembershipForm, \
CustomAuthenticationForm, MembershipRolesForm
@ -72,11 +73,19 @@ class UserUpdateView(ProtectQuerysetMixin, LoginRequiredMixin, UpdateView):
form.fields['email'].required = True
form.fields['email'].help_text = _("This address must be valid.")
if PermissionBackend.check_perm(self.request, "member.change_profile", context['user_object'].profile):
context['profile_form'] = self.profile_form(instance=context['user_object'].profile,
data=self.request.POST if self.request.POST else None)
if not self.object.profile.report_frequency:
del context['profile_form'].fields["last_report"]
profile_form = self.profile_form(instance=context['user_object'].profile,
data=self.request.POST if self.request.POST else None)
if not self.object.profile.report_frequency:
del profile_form.fields["last_report"]
fields_to_check = list(profile_form.fields.keys())
# Delete the fields for which the user does not have the permission to modify
for field_name in fields_to_check:
if not PermissionBackend.check_perm(self.request, f"member.change_profile_{field_name}", context['user_object'].profile):
profile_form.fields[field_name].widget = forms.HiddenInput()
context['profile_form'] = profile_form
return context

View File

@ -3832,6 +3832,74 @@
"description": "Voir les profils des membres du club"
}
},
{
"model": "permission.permission",
"pk": 244,
"fields": {
"model": [
"member",
"profile"
],
"query": "{}",
"type": "change",
"mask": 3,
"field": "ml_events_registration",
"permanent": false,
"description": "Modifier l'abonnement à la Newsletter BDE pour n'importe quel profil"
}
},
{
"model": "permission.permission",
"pk": 245,
"fields": {
"model": [
"member",
"profile"
],
"query": "{}",
"type": "change",
"mask": 3,
"field": "ml_art_registration",
"permanent": false,
"description": "Modifier l'abonnement à la Newsletter Art pour n'importe quel profil"
}
},
{
"model": "permission.permission",
"pk": 246,
"fields": {
"model": [
"member",
"profile"
],
"query": "{}",
"type": "change",
"mask": 3,
"field": "ml_sport_registration",
"permanent": false,
"description": "Modifier l'abonnement à la Newsletter Sport pour n'importe quel profil"
}
},
{
"model": "permission.permission",
"pk": 247,
"fields": {
"model": [
"member",
"profile"
],
"query": "{}",
"type": "view",
"mask": 3,
"field": [
"ml_events_registration",
"ml_art_registration",
"ml_sport_registration"
],
"permanent": false,
"description": "Voir les abonnements aux Newsletters de n'importe quel profil"
}
},
{
"model": "permission.role",
"pk": 1,

View File

@ -794,12 +794,12 @@ msgid "Permission mask"
msgstr "Masque de permissions"
#: apps/member/forms.py:46
msgid "Report frequency"
msgstr "Fréquence des rapports (en jours)"
msgid "Statement frequency (in days)"
msgstr "Fréquence des relevés (en jours)"
#: apps/member/forms.py:48
msgid "Last report date"
msgstr "Date de dernier rapport"
msgid "Last statement date"
msgstr "Date de dernier relevé"
#: apps/member/forms.py:52
msgid ""
@ -1044,12 +1044,12 @@ msgstr ""
"artistiques sur le campus (1 mail par semaine)"
#: apps/member/models.py:117
msgid "report frequency (in days)"
msgstr "fréquence des rapports (en jours)"
msgid "Statement frequency (in days)"
msgstr "Fréquence des relevés (en jours)"
#: apps/member/models.py:122
msgid "last report date"
msgstr "date de dernier rapport"
msgid "Last statement date"
msgstr "Date de dernier relevé"
#: apps/member/models.py:127
msgid "email confirmed"