Resolve "Add permissions/rules" #22

Merged
hansegucker merged 14 commits from 9-add-permissions-rules into frontend 2024-10-05 14:05:10 +02:00
Member

Closes #9

Closes #9
Author
Member

assigned to @yuha

assigned to @yuha
Author
Member

mentioned in merge request !20

mentioned in merge request !20
Author
Member

added 1 commit

  • 2f9de075 - Add basic permissions and rules

Compare with previous version

added 1 commit <ul><li>2f9de075 - Add basic permissions and rules</li></ul> [Compare with previous version](/AlekSIS/onboarding/AlekSIS-App-Maka/-/merge_requests/4/diffs?diff_id=48285&start_sha=24eecd84e91e7c492ddb0064a9240b06e1439a01)
Author
Member

added 2 commits

  • 4352f1c3 - Rename create rule names in mutations
  • 1a7da7d4 - Add dynamically added permissions

Compare with previous version

added 2 commits <ul><li>4352f1c3 - Rename create rule names in mutations</li><li>1a7da7d4 - Add dynamically added permissions</li></ul> [Compare with previous version](/AlekSIS/onboarding/AlekSIS-App-Maka/-/merge_requests/4/diffs?diff_id=48287&start_sha=2f9de075c48c0d45269f0067e4ef7df0090d45c5)
Author
Member

added 3 commits

  • 6f549d5e - Add basic permissions and rules
  • 70741b74 - Rename create rule names in mutations
  • e93567be - Add dynamically added permissions

Compare with previous version

added 3 commits <ul><li>6f549d5e - Add basic permissions and rules</li><li>70741b74 - Rename create rule names in mutations</li><li>e93567be - Add dynamically added permissions</li></ul> [Compare with previous version](/AlekSIS/onboarding/AlekSIS-App-Maka/-/merge_requests/4/diffs?diff_id=48289&start_sha=1a7da7d4d40095988d531e63db32404c43545796)
Author
Member

added 1 commit

  • eb139148 - Add permission checks to queryset filtering in types

Compare with previous version

added 1 commit <ul><li>eb139148 - Add permission checks to queryset filtering in types</li></ul> [Compare with previous version](/AlekSIS/onboarding/AlekSIS-App-Maka/-/merge_requests/4/diffs?diff_id=48296&start_sha=e93567be9724f04126c199616480cf0ca8bbe47a)
Author
Member

(kind of) needs https://edugit.org/AlekSIS/official/AlekSIS-Core/-/issues/1095 – otherwise non-admin group owners are not able to really manage grades

(kind of) needs https://edugit.org/AlekSIS/official/AlekSIS-Core/-/issues/1095 – otherwise non-admin group owners are not able to really manage grades
Owner

Nearly finished ;-)

Nearly finished ;-)
Author
Member

added 4 commits

  • 78d7c888 - Add permission checks to queryset filtering in types
  • 3469334c - Remove global permission checks for unsensitive models
  • 2c34edf3 - Actually allow for filtering grades & efforts by group ID as needed by group overview page
  • 9eca127e - Include subgroups in effort/grade query filtering

Compare with previous version

added 4 commits <ul><li>78d7c888 - Add permission checks to queryset filtering in types</li><li>3469334c - Remove global permission checks for unsensitive models</li><li>2c34edf3 - Actually allow for filtering grades &amp; efforts by group ID as needed by group overview page</li><li>9eca127e - Include subgroups in effort/grade query filtering</li></ul> [Compare with previous version](/AlekSIS/onboarding/AlekSIS-App-Maka/-/merge_requests/4/diffs?diff_id=48299&start_sha=eb139148ce2446237716c94915f0f73efec9c1c9)
Author
Member

good! :D

good! :D
Author
Member

update: this should be usable now (finally)

update: this should be usable now (finally)
Author
Member

TODO: respect perms in frontend (disable fields on read only permissions etc)

TODO: respect perms in frontend (disable fields on read only permissions etc)
Author
Member

TODO: check for/discuss student perspective

TODO: check for/discuss student perspective
Author
Member

resolved all threads

resolved all threads
Author
Member

@hansegucker would be great if you could do some testing tomorrow!

@hansegucker would be great if you could do some testing tomorrow!
Owner

Why is shared secret needed for managing grade sets and effort types

Why is shared secret needed for managing grade sets and effort types
Owner
        return user.person in obj.group.members.all()
```suggestion:-0+0 return user.person in obj.group.members.all() ```
Owner
        return user.person in obj.group.owners.all() or obj.group.parent_groups.filter(owners=user.person).exists()
```suggestion:-0+0 return user.person in obj.group.owners.all() or obj.group.parent_groups.filter(owners=user.person).exists() ```
Owner
        permissions = ("maka.create_gradechoice_rule",)
```suggestion:-0+0 permissions = ("maka.create_gradechoice_rule",) ```
Owner
        permissions = ("maka.create_gradeset_rule",)
```suggestion:-0+0 permissions = ("maka.create_gradeset_rule",) ```
Owner
        permissions = ("maka.create_grade_rule",)
```suggestion:-0+0 permissions = ("maka.create_grade_rule",) ```
Owner

Use super().get_queryset() as shared secret check won't work otherwise.

Use `super().get_queryset()` as shared secret check won't work otherwise.
Owner

Use super().get_queryset() as shared secret check won't work otherwise.

Use `super().get_queryset()` as shared secret check won't work otherwise.
Owner

Use super().get_queryset() as shared secret check won't work otherwise.

Use `super().get_queryset()` as shared secret check won't work otherwise.
Owner
        permissions = ("maka.create_efforttype_rule",)
```suggestion:-0+0 permissions = ("maka.create_efforttype_rule",) ```
Owner
        permissions = ("maka.create_effort_rule",)
```suggestion:-0+0 permissions = ("maka.create_effort_rule",) ```
Owner

This is probably wrong. With this check, a user would be able to see the grades of all the groups he is a member of. Instead include an or in the queryset.filter at the end checking for the person attribute.

This is probably wrong. With this check, a user would be able to see the grades of all the groups he is a member of. Instead include an or in the `queryset.filter` at the end checking for the person attribute.
Owner
add_perm("maka.create_effort_rule", add_effort_predicate)

and so on

```suggestion:-0+0 add_perm("maka.create_effort_rule", add_effort_predicate) ``` and so on
Owner

Separate into fetch and view permission (AS EVERYWHERE ELSE).

This is fetch_gradesets_rule

Separate into fetch and view permission (AS EVERYWHERE ELSE). This is `fetch_gradesets_rule`
Owner

This is view_gradesets_rule

This is `view_gradesets_rule`
Owner

as above

as above
Owner

as above

as above
Author
Member

added 1 commit

  • 01b96b63 - Remove shared secret check from grade set and effort type types/mutations/pages

Compare with previous version

added 1 commit <ul><li>01b96b63 - Remove shared secret check from grade set and effort type types/mutations/pages</li></ul> [Compare with previous version](/AlekSIS/onboarding/AlekSIS-App-Maka/-/merge_requests/4/diffs?diff_id=48355&start_sha=9eca127e68c59d2f3d94de43c1425186b518c195)
Author
Member

removed

removed
Author
Member

changed this line in version 7 of the diff

changed this line in [version 7 of the diff](/AlekSIS/onboarding/AlekSIS-App-Maka/-/merge_requests/4/diffs?diff_id=48357&start_sha=01b96b633b52928c444b3727043ba51b27de4537#fa304ec9f5bf8fc2591e1ddb4af7331dde4df5a0_20_20)
Author
Member

changed this line in version 7 of the diff

changed this line in [version 7 of the diff](/AlekSIS/onboarding/AlekSIS-App-Maka/-/merge_requests/4/diffs?diff_id=48357&start_sha=01b96b633b52928c444b3727043ba51b27de4537#fa304ec9f5bf8fc2591e1ddb4af7331dde4df5a0_32_32)
Author
Member

added 1 commit

  • f88817ba - Apply 2 suggestion(s) to 1 file(s)

Compare with previous version

added 1 commit <ul><li>f88817ba - Apply 2 suggestion(s) to 1 file(s)</li></ul> [Compare with previous version](/AlekSIS/onboarding/AlekSIS-App-Maka/-/merge_requests/4/diffs?diff_id=48357&start_sha=01b96b633b52928c444b3727043ba51b27de4537)
Author
Member

changed this line in version 8 of the diff

changed this line in [version 8 of the diff](/AlekSIS/onboarding/AlekSIS-App-Maka/-/merge_requests/4/diffs?diff_id=48359&start_sha=f88817baeb6c641811d7c78524c4a82169f3fc6e#f8b118ae331b058b12c6a6bd3f752fe3f60412ff_83_83)
Author
Member

changed this line in version 8 of the diff

changed this line in [version 8 of the diff](/AlekSIS/onboarding/AlekSIS-App-Maka/-/merge_requests/4/diffs?diff_id=48359&start_sha=f88817baeb6c641811d7c78524c4a82169f3fc6e#f8b118ae331b058b12c6a6bd3f752fe3f60412ff_43_43)
Author
Member

changed this line in version 8 of the diff

changed this line in [version 8 of the diff](/AlekSIS/onboarding/AlekSIS-App-Maka/-/merge_requests/4/diffs?diff_id=48359&start_sha=f88817baeb6c641811d7c78524c4a82169f3fc6e#1624b422ab6231b0e4a5ff69135bd1fe8d52f3cb_59_59)
Author
Member

changed this line in version 8 of the diff

changed this line in [version 8 of the diff](/AlekSIS/onboarding/AlekSIS-App-Maka/-/merge_requests/4/diffs?diff_id=48359&start_sha=f88817baeb6c641811d7c78524c4a82169f3fc6e#6951e25a2130c8f1fddf8d8dd6510338809aa5c9_48_48)
Author
Member

changed this line in version 8 of the diff

changed this line in [version 8 of the diff](/AlekSIS/onboarding/AlekSIS-App-Maka/-/merge_requests/4/diffs?diff_id=48359&start_sha=f88817baeb6c641811d7c78524c4a82169f3fc6e#6951e25a2130c8f1fddf8d8dd6510338809aa5c9_109_109)
Author
Member

changed this line in version 8 of the diff

changed this line in [version 8 of the diff](/AlekSIS/onboarding/AlekSIS-App-Maka/-/merge_requests/4/diffs?diff_id=48359&start_sha=f88817baeb6c641811d7c78524c4a82169f3fc6e#edd7084fd319086389578e80f9b50ffc27ccefeb_38_38)
Author
Member

added 1 commit

Compare with previous version

added 1 commit <ul><li>75681d41 - Rename rules</li></ul> [Compare with previous version](/AlekSIS/onboarding/AlekSIS-App-Maka/-/merge_requests/4/diffs?diff_id=48359&start_sha=f88817baeb6c641811d7c78524c4a82169f3fc6e)
Author
Member

added 1 commit

  • 9ec6b33d - Fix get_queryset with shared secret mixin

Compare with previous version

added 1 commit <ul><li>9ec6b33d - Fix get_queryset with shared secret mixin</li></ul> [Compare with previous version](/AlekSIS/onboarding/AlekSIS-App-Maka/-/merge_requests/4/diffs?diff_id=48361&start_sha=75681d41b3e0692c364b03921a3a34349377491d)
Author
Member

changed this line in version 10 of the diff

changed this line in [version 10 of the diff](/AlekSIS/onboarding/AlekSIS-App-Maka/-/merge_requests/4/diffs?diff_id=48363&start_sha=9ec6b33d623c85ab54c7b46a8a7cca9be1f85000#1624b422ab6231b0e4a5ff69135bd1fe8d52f3cb_49_52)
Author
Member

added 1 commit

  • 39d0aa7c - Fix permission filtering for viewing own grades

Compare with previous version

added 1 commit <ul><li>39d0aa7c - Fix permission filtering for viewing own grades</li></ul> [Compare with previous version](/AlekSIS/onboarding/AlekSIS-App-Maka/-/merge_requests/4/diffs?diff_id=48363&start_sha=9ec6b33d623c85ab54c7b46a8a7cca9be1f85000)
Author
Member

changed this line in version 11 of the diff

changed this line in [version 11 of the diff](/AlekSIS/onboarding/AlekSIS-App-Maka/-/merge_requests/4/diffs?diff_id=48378&start_sha=39d0aa7c04f83824fd7bd3747c8045668f3c89f1#edd7084fd319086389578e80f9b50ffc27ccefeb_95_94)
Author
Member

changed this line in version 11 of the diff

changed this line in [version 11 of the diff](/AlekSIS/onboarding/AlekSIS-App-Maka/-/merge_requests/4/diffs?diff_id=48378&start_sha=39d0aa7c04f83824fd7bd3747c8045668f3c89f1#edd7084fd319086389578e80f9b50ffc27ccefeb_110_110)
Author
Member

changed this line in version 11 of the diff

changed this line in [version 11 of the diff](/AlekSIS/onboarding/AlekSIS-App-Maka/-/merge_requests/4/diffs?diff_id=48378&start_sha=39d0aa7c04f83824fd7bd3747c8045668f3c89f1#edd7084fd319086389578e80f9b50ffc27ccefeb_114_114)
Author
Member

changed this line in version 11 of the diff

changed this line in [version 11 of the diff](/AlekSIS/onboarding/AlekSIS-App-Maka/-/merge_requests/4/diffs?diff_id=48378&start_sha=39d0aa7c04f83824fd7bd3747c8045668f3c89f1#edd7084fd319086389578e80f9b50ffc27ccefeb_128_128)
Author
Member

added 1 commit

  • 980c5cee - Separate fetch and view rules

Compare with previous version

added 1 commit <ul><li>980c5cee - Separate fetch and view rules</li></ul> [Compare with previous version](/AlekSIS/onboarding/AlekSIS-App-Maka/-/merge_requests/4/diffs?diff_id=48378&start_sha=39d0aa7c04f83824fd7bd3747c8045668f3c89f1)
Author
Member

resolved all threads

resolved all threads
Author
Member

assigned to @hansegucker and unassigned @yuha

assigned to @hansegucker and unassigned @yuha
Author
Member

marked this merge request as ready

marked this merge request as **ready**
Author
Member

added 1 commit

Compare with previous version

added 1 commit <ul><li>b9a63416 - Reformat</li></ul> [Compare with previous version](/AlekSIS/onboarding/AlekSIS-App-Maka/-/merge_requests/4/diffs?diff_id=48380&start_sha=980c5cee5504233d8d56f1355cbd662576d18081)
Owner

mentioned in commit a56a2fc6dd

mentioned in commit a56a2fc6dd4a78dd83f0a80c2c04dbe25a4fff43
hansegucker merged commit a56a2fc6dd into frontend 2024-10-05 14:05:10 +02:00
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
aleksis/AlekSIS-App-Maka!22
No description provided.