Clean up and consolidate permissions.#3100
Merged
rtibbles merged 2 commits intolearningequality:unstablefrom Apr 15, 2021
Merged
Clean up and consolidate permissions.#3100rtibbles merged 2 commits intolearningequality:unstablefrom
rtibbles merged 2 commits intolearningequality:unstablefrom
Conversation
Make ContentNode filter_edit_queryset consistent with other methods.
Codecov Report
@@ Coverage Diff @@
## unstable #3100 +/- ##
===========================================
Coverage ? 85.85%
===========================================
Files ? 298
Lines ? 15825
Branches ? 0
===========================================
Hits ? 13586
Misses ? 2239
Partials ? 0 Continue to review full report at Codecov.
|
Member
|
Tested and verified as fix at https://hotfixes.studio.learningequality.org/ |
24 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Description of the change(s) you made
Consolidates all our permission checking against
filter_view_querysetandfilter_edit_querysetclass methods.Removes permissions from users for the now unused orphan tree.
Manual verification steps performed
Did not change the semantics for internal views - but wondering if we want to move completely to 404s instead of 403s.
Reviewer guidance
How can a reviewer test these changes?
These endpoints should be covered by unit tests.
Are there any risky areas that deserve extra testing?
This might need some integration testing with ricecooker.
References
Fixes #3071 by making
filter_edit_querysetfilter nothing for admins.Contributor's Checklist
PR process:
CHANGELOGlabel been added to this PR. Note: items with this label will be added to the CHANGELOG at a later timedocslabel has been added if this introduces a change that needs to be updated in the user docs?requirements.txtfiles also included in this PRStudio-specifc:
notranslateclass been added to elements that shouldn't be translated by Google Chrome's automatic translation feature (e.g. icons, user-generated text)pages,components, andlayoutsdirectories as described in the docsTesting:
Reviewer's Checklist
This section is for reviewers to fill out.
yarnandpip)