permissions.py 4.12 KB
Newer Older
Mike Chen committed
1 2 3
from .models import Role, Permission
from django.db.models.signals import post_save
from django.dispatch import receiver
4 5
from student.models import CourseEnrollment

Mike Chen committed
6
import logging
7
from util.cache import cache
8 9
from django.core import cache
cache = cache.get_cache('default')
10

Calen Pennington committed
11

12
def cached_has_permission(user, permission, course_id=None):
Mike Chen committed
13 14
    """
    Call has_permission if it's not cached. A change in a user's role or
15
    a role's permissions will only become effective after CACHE_LIFESPAN seconds.
Mike Chen committed
16 17
    """
    CACHE_LIFESPAN = 60
18 19 20 21
    key = "permission_%d_%s_%s" % (user.id, str(course_id), permission)
    val = cache.get(key, None)
    if val not in [True, False]:
        val = has_permission(user, permission, course_id=course_id)
Mike Chen committed
22
        cache.set(key, val, CACHE_LIFESPAN)
23 24
    return val

Calen Pennington committed
25

26
def has_permission(user, permission, course_id=None):
27 28 29
    for role in user.roles.filter(course_id=course_id):
        if role.has_permission(permission):
            return True
Mike Chen committed
30 31 32
    return False


33
CONDITIONS = ['is_open', 'is_author']
Calen Pennington committed
34 35


36 37
def check_condition(user, condition, course_id, data):
    def check_open(user, condition, course_id, data):
Rocky Duan committed
38 39 40 41
        try:
            return data and not data['content']['closed']
        except KeyError:
            return False
Mike Chen committed
42

43
    def check_author(user, condition, course_id, data):
Rocky Duan committed
44 45 46 47
        try:
            return data and data['content']['user_id'] == str(user.id)
        except KeyError:
            return False
Mike Chen committed
48

49
    handlers = {
Calen Pennington committed
50 51
        'is_open': check_open,
        'is_author': check_author,
52
    }
Mike Chen committed
53

54
    return handlers[condition](user, condition, course_id, data)
55

56 57

def check_conditions_permissions(user, permissions, course_id, **kwargs):
58 59
    """
    Accepts a list of permissions and proceed if any of the permission is valid.
60
    Note that ["can_view", "can_edit"] will proceed if the user has either
61 62
    "can_view" or "can_edit" permission. To use AND operator in between, wrap them in
    a list.
63
    """
64 65 66 67 68

    def test(user, per, operator="or"):
        if isinstance(per, basestring):
            if per in CONDITIONS:
                return check_condition(user, per, course_id, kwargs)
69
            return cached_has_permission(user, per, course_id=course_id)
70 71
        elif isinstance(per, list) and operator in ["and", "or"]:
            results = [test(user, x, operator="and") for x in per]
72 73 74 75
            if operator == "or":
                return True in results
            elif operator == "and":
                return not False in results
76

Kevin Chugh committed
77
    return test(user, permissions, operator="or")
78 79 80


VIEW_PERMISSIONS = {
81 82
    'update_thread'     :       ['edit_content', ['update_thread', 'is_open', 'is_author']],
    'create_comment'    :       [["create_comment", "is_open"]],
83
    'delete_thread'     :       ['delete_thread', ['update_thread', 'is_author']],
84
    'update_comment'    :       ['edit_content', ['update_comment', 'is_open', 'is_author']],
85 86 87
    'endorse_comment'   :       ['endorse_comment'],
    'openclose_thread'  :       ['openclose_thread'],
    'create_sub_comment':       [['create_sub_comment', 'is_open']],
88
    'delete_comment'    :       ['delete_comment', ['update_comment', 'is_open', 'is_author']],
89 90 91 92
    'vote_for_comment'  :       [['vote', 'is_open']],
    'undo_vote_for_comment':    [['unvote', 'is_open']],
    'vote_for_thread'   :       [['vote', 'is_open']],
    'undo_vote_for_thread':     [['unvote', 'is_open']],
Your Name committed
93 94
    'pin_thread':    ['create_comment'],
    'un_pin_thread':    ['create_comment'],
95
    'follow_thread'     :       ['follow_thread'],
96
    'follow_commentable':       ['follow_commentable'],
97 98 99 100 101
    'follow_user'       :       ['follow_user'],
    'unfollow_thread'   :       ['unfollow_thread'],
    'unfollow_commentable':     ['unfollow_commentable'],
    'unfollow_user'     :       ['unfollow_user'],
    'create_thread'     :       ['create_thread'],
Calen Pennington committed
102
    'update_moderator_status': ['manage_moderator'],
103 104
}

105 106

def check_permissions_by_view(user, course_id, content, name):
107 108 109 110
    try:
        p = VIEW_PERMISSIONS[name]
    except KeyError:
        logging.warning("Permission for view named %s does not exist in permissions.py" % name)
111
    return check_conditions_permissions(user, p, course_id, content=content)