fix(admin): custom admin permission class#3360
Merged
rtibbles merged 5 commits intolearningequality:unstablefrom Apr 12, 2022
Merged
fix(admin): custom admin permission class#3360rtibbles merged 5 commits intolearningequality:unstablefrom
rtibbles merged 5 commits intolearningequality:unstablefrom
Conversation
rtibbles
reviewed
Apr 7, 2022
Member
rtibbles
left a comment
There was a problem hiding this comment.
Can return early here - could in theory just pass and make no return as None is falsy, but the explicitness feels neater.
Co-authored-by: Richard Tibbles <richard@learningequality.org>
Co-authored-by: Richard Tibbles <richard@learningequality.org>
Member
Author
|
@rtibbles feedback addressed. Right now, I'm on my Windows (playing games), so did the changes from GitHub's UI. |
rtibbles
approved these changes
Apr 12, 2022
This was referenced Sep 15, 2022
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
When admins were added, on our backend we were setting
is_admin=Truebut DRF checks againstis_staffso this PR implements a customIsAdminUserDRF permission class to fix the issue.Manual verification steps performed
a@a.comon studio from theunstablebranch.user@b.comor any other user as an admin.user@b.com.Administration: http://localhost:8080/en/administration. Open networks tab on dev console, you'll see 403 errors.Administrationview is fully functional.Reviewer guidance
Now when we add admins do they get expected access?
References
Closes #3348.
Contributor's Checklist
PR process:
CHANGELOGlabel been added to this PR. Note: items with this label will be added to the CHANGELOG at a later timedocslabel has been added if this introduces a change that needs to be updated in the user docs?requirements.txtfiles also included in this PRStudio-specifc:
notranslateclass been added to elements that shouldn't be translated by Google Chrome's automatic translation feature (e.g. icons, user-generated text)pages,components, andlayoutsdirectories as described in the docsTesting:
Reviewer's Checklist
This section is for reviewers to fill out.
yarnandpip)