Commit 6cea294
committed
6009: add organizations to invitation querysets, serializer, and sync
Extends organization invitations (Invitation.organization, added in
#6008) end-to-end through the existing channel-invitation permission
model and /sync mechanism, per #6009.
- Organization.filter_edit_queryset/filter_view_queryset - new
classmethods based on active OrganizationRole membership (admin for
edit, admin/editor/viewer for view; excludes soft-deleted
organizations), mirroring the existing Channel pattern.
- Invitation.filter_edit_queryset/filter_view_queryset - extended with
the same organization-role checks, in a single filter() so the
multi-valued OrganizationRole join matches one row rather than
across rows.
- InvitationSerializer - organization is now a field alongside
channel (via UserFilteredPrimaryKeyRelatedField, scoped by
Organization.filter_edit_queryset); channel becomes optional and
validate() requires exactly one of channel/organization.
- get_fields() - match the invitee on email rather than the `invited`
FK, since `invited` is only ever populated by the channel
email-invite flow and is never set for invitations created through
the sync API. Unlock `revoked` for any active org admin of the
invitation's organization, not just the original sender. Lock
`share_mode` read-only for anyone but the sender/org-admin, so an
invitee can't self-escalate (e.g. request "admin" access) before
accepting.
- update() - read accepted/revoked from validated_data, not
initial_data, so get_fields' read-only flags can't be bypassed by
the raw client payload; only trigger accept() on an actual incoming
toggle rather than re-running it on every later update to an
already-accepted invitation. Tag user_id on the accept/decline echo
events (both the sync-based update() and the REST actions) so
they're routable.
- InvitationFilter/InvitationViewSet - organization filter and
field_map entry alongside the existing channel ones.
- /sync's handle_changes() is untouched - organization-scoped
invitation changes route the same way any other self-only change
does (client tags user_id as its own id), relying entirely on the
model-layer filter_edit_queryset checks above for authorization
when the change is actually applied.
Test coverage: OrganizationTestCase/InvitationOrganizationTestCase in
test_models.py exercise the querysets directly.
OrganizationInvitationSyncTestCase in test_invitation.py covers
create/accept/revoke/delete via /sync, non-admin rejection, cross-org
isolation, an org admin unable to force-accept on behalf of the real
invitee, an invitee unable to raise their own share_mode before
accepting, the channel/organization mutual-exclusivity and
"at-least-one" validation, and that org-scoped changes require a
self-tagged user_id (missing or mismatched is rejected, not silently
dropped or re-routed). Also a channel-invitation test locking in that
the "admin" (co-owner) share_mode currently grants the same editor
access as "edit". The REST create route (POST /invitation/) has no
org-specific test, since InvitationViewSet has no create route at all
for either channel or organization invitations - creation is /sync
only, and the existing non-org 405 test already covers that; the
?organization= list filter is exercised directly instead.1 parent 4c74c10 commit 6cea294
5 files changed
Lines changed: 749 additions & 6 deletions
File tree
- contentcuration/contentcuration
- tests
- viewsets
- viewsets
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1895 | 1895 | | |
1896 | 1896 | | |
1897 | 1897 | | |
| 1898 | + | |
| 1899 | + | |
| 1900 | + | |
| 1901 | + | |
| 1902 | + | |
| 1903 | + | |
| 1904 | + | |
| 1905 | + | |
| 1906 | + | |
| 1907 | + | |
| 1908 | + | |
| 1909 | + | |
| 1910 | + | |
| 1911 | + | |
| 1912 | + | |
| 1913 | + | |
| 1914 | + | |
| 1915 | + | |
| 1916 | + | |
| 1917 | + | |
| 1918 | + | |
| 1919 | + | |
| 1920 | + | |
| 1921 | + | |
| 1922 | + | |
| 1923 | + | |
| 1924 | + | |
| 1925 | + | |
| 1926 | + | |
| 1927 | + | |
| 1928 | + | |
| 1929 | + | |
| 1930 | + | |
| 1931 | + | |
1898 | 1932 | | |
1899 | 1933 | | |
1900 | 1934 | | |
| |||
3807 | 3841 | | |
3808 | 3842 | | |
3809 | 3843 | | |
3810 | | - | |
| 3844 | + | |
| 3845 | + | |
| 3846 | + | |
| 3847 | + | |
| 3848 | + | |
| 3849 | + | |
| 3850 | + | |
| 3851 | + | |
3811 | 3852 | | |
3812 | 3853 | | |
3813 | 3854 | | |
| |||
3822 | 3863 | | |
3823 | 3864 | | |
3824 | 3865 | | |
| 3866 | + | |
| 3867 | + | |
| 3868 | + | |
| 3869 | + | |
| 3870 | + | |
| 3871 | + | |
| 3872 | + | |
| 3873 | + | |
| 3874 | + | |
3825 | 3875 | | |
3826 | 3876 | | |
3827 | 3877 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
19 | 28 | | |
20 | 29 | | |
21 | 30 | | |
| |||
34 | 43 | | |
35 | 44 | | |
36 | 45 | | |
| 46 | + | |
| 47 | + | |
37 | 48 | | |
38 | 49 | | |
39 | 50 | | |
| |||
309 | 320 | | |
310 | 321 | | |
311 | 322 | | |
| 323 | + | |
| 324 | + | |
| 325 | + | |
| 326 | + | |
| 327 | + | |
| 328 | + | |
| 329 | + | |
| 330 | + | |
| 331 | + | |
| 332 | + | |
| 333 | + | |
| 334 | + | |
| 335 | + | |
| 336 | + | |
| 337 | + | |
| 338 | + | |
| 339 | + | |
| 340 | + | |
| 341 | + | |
| 342 | + | |
| 343 | + | |
| 344 | + | |
| 345 | + | |
| 346 | + | |
| 347 | + | |
| 348 | + | |
| 349 | + | |
| 350 | + | |
| 351 | + | |
| 352 | + | |
| 353 | + | |
| 354 | + | |
| 355 | + | |
| 356 | + | |
| 357 | + | |
| 358 | + | |
| 359 | + | |
| 360 | + | |
| 361 | + | |
| 362 | + | |
| 363 | + | |
| 364 | + | |
| 365 | + | |
| 366 | + | |
| 367 | + | |
| 368 | + | |
| 369 | + | |
| 370 | + | |
| 371 | + | |
| 372 | + | |
| 373 | + | |
| 374 | + | |
| 375 | + | |
| 376 | + | |
| 377 | + | |
| 378 | + | |
| 379 | + | |
| 380 | + | |
| 381 | + | |
| 382 | + | |
| 383 | + | |
| 384 | + | |
| 385 | + | |
| 386 | + | |
| 387 | + | |
| 388 | + | |
| 389 | + | |
| 390 | + | |
| 391 | + | |
| 392 | + | |
| 393 | + | |
| 394 | + | |
| 395 | + | |
| 396 | + | |
| 397 | + | |
| 398 | + | |
| 399 | + | |
| 400 | + | |
| 401 | + | |
| 402 | + | |
| 403 | + | |
| 404 | + | |
| 405 | + | |
| 406 | + | |
| 407 | + | |
| 408 | + | |
| 409 | + | |
| 410 | + | |
| 411 | + | |
| 412 | + | |
| 413 | + | |
| 414 | + | |
| 415 | + | |
| 416 | + | |
| 417 | + | |
| 418 | + | |
| 419 | + | |
| 420 | + | |
| 421 | + | |
| 422 | + | |
| 423 | + | |
| 424 | + | |
| 425 | + | |
| 426 | + | |
| 427 | + | |
| 428 | + | |
| 429 | + | |
| 430 | + | |
| 431 | + | |
| 432 | + | |
| 433 | + | |
| 434 | + | |
| 435 | + | |
| 436 | + | |
| 437 | + | |
| 438 | + | |
| 439 | + | |
| 440 | + | |
| 441 | + | |
| 442 | + | |
| 443 | + | |
| 444 | + | |
| 445 | + | |
| 446 | + | |
| 447 | + | |
| 448 | + | |
| 449 | + | |
| 450 | + | |
| 451 | + | |
| 452 | + | |
| 453 | + | |
| 454 | + | |
| 455 | + | |
| 456 | + | |
| 457 | + | |
| 458 | + | |
| 459 | + | |
| 460 | + | |
| 461 | + | |
| 462 | + | |
| 463 | + | |
| 464 | + | |
| 465 | + | |
| 466 | + | |
| 467 | + | |
| 468 | + | |
| 469 | + | |
| 470 | + | |
| 471 | + | |
| 472 | + | |
| 473 | + | |
| 474 | + | |
| 475 | + | |
| 476 | + | |
| 477 | + | |
| 478 | + | |
| 479 | + | |
| 480 | + | |
| 481 | + | |
312 | 482 | | |
313 | 483 | | |
314 | 484 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
19 | 19 | | |
20 | 20 | | |
21 | 21 | | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
22 | 26 | | |
23 | 27 | | |
24 | 28 | | |
| |||
253 | 257 | | |
254 | 258 | | |
255 | 259 | | |
| 260 | + | |
| 261 | + | |
| 262 | + | |
| 263 | + | |
| 264 | + | |
| 265 | + | |
| 266 | + | |
| 267 | + | |
| 268 | + | |
| 269 | + | |
| 270 | + | |
| 271 | + | |
256 | 272 | | |
257 | 273 | | |
258 | 274 | | |
| |||
0 commit comments