__init__.py 3.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129
  1. from django.contrib import admin
  2. from django.contrib.auth.admin import UserAdmin as UserAdmin_
  3. from django.contrib.auth.models import Group, User
  4. from users.models import ObjectPermission, Token
  5. from . import filters, forms, inlines
  6. #
  7. # Users & groups
  8. #
  9. # Unregister the built-in GroupAdmin and UserAdmin classes so that we can use our custom admin classes below
  10. admin.site.unregister(Group)
  11. admin.site.unregister(User)
  12. @admin.register(Group)
  13. class GroupAdmin(admin.ModelAdmin):
  14. form = forms.GroupAdminForm
  15. list_display = ('name', 'user_count')
  16. ordering = ('name',)
  17. search_fields = ('name',)
  18. inlines = [inlines.GroupObjectPermissionInline]
  19. @staticmethod
  20. def user_count(obj):
  21. return obj.user_set.count()
  22. @admin.register(User)
  23. class UserAdmin(UserAdmin_):
  24. list_display = [
  25. 'username', 'email', 'first_name', 'last_name', 'is_superuser', 'is_staff', 'is_active'
  26. ]
  27. fieldsets = (
  28. (None, {'fields': ('username', 'password', 'first_name', 'last_name', 'email')}),
  29. ('Groups', {'fields': ('groups',)}),
  30. ('Status', {
  31. 'fields': ('is_active', 'is_staff', 'is_superuser'),
  32. }),
  33. ('Important dates', {'fields': ('last_login', 'date_joined')}),
  34. )
  35. filter_horizontal = ('groups',)
  36. list_filter = ('is_active', 'is_staff', 'is_superuser', 'groups__name')
  37. def get_inlines(self, request, obj):
  38. if obj is not None:
  39. return (inlines.UserObjectPermissionInline, inlines.UserConfigInline)
  40. return ()
  41. #
  42. # REST API tokens
  43. #
  44. @admin.register(Token)
  45. class TokenAdmin(admin.ModelAdmin):
  46. form = forms.TokenAdminForm
  47. list_display = [
  48. 'key', 'user', 'created', 'expires', 'last_used', 'write_enabled', 'description', 'list_allowed_ips'
  49. ]
  50. def list_allowed_ips(self, obj):
  51. return obj.allowed_ips or 'Any'
  52. list_allowed_ips.short_description = "Allowed IPs"
  53. #
  54. # Permissions
  55. #
  56. @admin.register(ObjectPermission)
  57. class ObjectPermissionAdmin(admin.ModelAdmin):
  58. actions = ('enable', 'disable')
  59. fieldsets = (
  60. (None, {
  61. 'fields': ('name', 'description', 'enabled')
  62. }),
  63. ('Actions', {
  64. 'fields': (('can_view', 'can_add', 'can_change', 'can_delete'), 'actions')
  65. }),
  66. ('Objects', {
  67. 'fields': ('object_types',)
  68. }),
  69. ('Assignment', {
  70. 'fields': ('groups', 'users')
  71. }),
  72. ('Constraints', {
  73. 'fields': ('constraints',),
  74. 'classes': ('monospace',)
  75. }),
  76. )
  77. filter_horizontal = ('object_types', 'groups', 'users')
  78. form = forms.ObjectPermissionForm
  79. list_display = [
  80. 'name', 'enabled', 'list_models', 'list_users', 'list_groups', 'actions', 'constraints', 'description',
  81. ]
  82. list_filter = [
  83. 'enabled', filters.ActionListFilter, filters.ObjectTypeListFilter, 'groups', 'users'
  84. ]
  85. search_fields = ['actions', 'constraints', 'description', 'name']
  86. def get_queryset(self, request):
  87. return super().get_queryset(request).prefetch_related('object_types', 'users', 'groups')
  88. def list_models(self, obj):
  89. return ', '.join([f"{ct}" for ct in obj.object_types.all()])
  90. list_models.short_description = 'Models'
  91. def list_users(self, obj):
  92. return ', '.join([u.username for u in obj.users.all()])
  93. list_users.short_description = 'Users'
  94. def list_groups(self, obj):
  95. return ', '.join([g.name for g in obj.groups.all()])
  96. list_groups.short_description = 'Groups'
  97. #
  98. # Admin actions
  99. #
  100. def enable(self, request, queryset):
  101. updated = queryset.update(enabled=True)
  102. self.message_user(request, f"Enabled {updated} permissions")
  103. def disable(self, request, queryset):
  104. updated = queryset.update(enabled=False)
  105. self.message_user(request, f"Disabled {updated} permissions")