2020-02-19 18:53:43 +00:00
|
|
|
# Copyright © 2017 Tom Hacohen
|
|
|
|
#
|
|
|
|
# This program is free software: you can redistribute it and/or modify
|
|
|
|
# it under the terms of the GNU Affero General Public License as
|
|
|
|
# published by the Free Software Foundation, version 3.
|
|
|
|
#
|
|
|
|
# This library is distributed in the hope that it will be useful,
|
|
|
|
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
# GNU General Public License for more details.
|
|
|
|
#
|
|
|
|
# You should have received a copy of the GNU General Public License
|
|
|
|
# along with this program. If not, see <http://www.gnu.org/licenses/>.
|
2020-02-19 12:55:56 +00:00
|
|
|
|
2020-04-14 13:21:51 +00:00
|
|
|
from django.conf import settings
|
2020-02-26 12:21:14 +00:00
|
|
|
from django.contrib.auth import get_user_model
|
2020-02-26 19:11:29 +00:00
|
|
|
from django.db import IntegrityError
|
2020-04-14 13:21:51 +00:00
|
|
|
from django.http import HttpResponseBadRequest, HttpResponse, Http404
|
2020-02-19 18:53:43 +00:00
|
|
|
from django.shortcuts import get_object_or_404
|
|
|
|
|
|
|
|
from rest_framework import status
|
|
|
|
from rest_framework import viewsets
|
2020-02-20 11:56:16 +00:00
|
|
|
from rest_framework import parsers
|
2020-02-20 13:39:52 +00:00
|
|
|
from rest_framework.decorators import action as action_decorator
|
2020-02-19 18:53:43 +00:00
|
|
|
from rest_framework.response import Response
|
|
|
|
|
|
|
|
from . import app_settings, paginators
|
2020-02-26 19:11:29 +00:00
|
|
|
from .models import Collection, CollectionItem
|
2020-02-19 18:53:43 +00:00
|
|
|
from .serializers import (
|
|
|
|
CollectionSerializer,
|
|
|
|
CollectionItemSerializer,
|
2020-02-20 20:41:39 +00:00
|
|
|
CollectionItemRevisionSerializer,
|
2020-02-19 18:53:43 +00:00
|
|
|
CollectionItemChunkSerializer
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
|
|
User = get_user_model()
|
|
|
|
|
|
|
|
|
|
|
|
class BaseViewSet(viewsets.ModelViewSet):
|
|
|
|
authentication_classes = tuple(app_settings.API_AUTHENTICATORS)
|
|
|
|
permission_classes = tuple(app_settings.API_PERMISSIONS)
|
|
|
|
|
|
|
|
def get_serializer_class(self):
|
|
|
|
serializer_class = self.serializer_class
|
|
|
|
|
|
|
|
if self.request.method == 'PUT':
|
|
|
|
serializer_class = getattr(self, 'serializer_update_class', serializer_class)
|
|
|
|
|
|
|
|
return serializer_class
|
|
|
|
|
|
|
|
def get_collection_queryset(self, queryset=Collection.objects):
|
2020-02-26 19:13:33 +00:00
|
|
|
user = self.request.user
|
|
|
|
return queryset.filter(members__user=user)
|
2020-02-19 18:53:43 +00:00
|
|
|
|
|
|
|
|
|
|
|
class CollectionViewSet(BaseViewSet):
|
|
|
|
allowed_methods = ['GET', 'POST', 'DELETE']
|
|
|
|
permission_classes = BaseViewSet.permission_classes
|
|
|
|
queryset = Collection.objects.all()
|
|
|
|
serializer_class = CollectionSerializer
|
|
|
|
lookup_field = 'uid'
|
|
|
|
|
|
|
|
def get_queryset(self):
|
|
|
|
queryset = type(self).queryset
|
|
|
|
return self.get_collection_queryset(queryset)
|
|
|
|
|
2020-04-15 12:23:07 +00:00
|
|
|
def get_serializer_context(self):
|
|
|
|
context = super().get_serializer_context()
|
2020-04-16 08:35:58 +00:00
|
|
|
inline = 'inline' in self.request.query_params
|
2020-04-15 13:47:31 +00:00
|
|
|
context.update({'request': self.request, 'inline': inline})
|
2020-04-15 12:23:07 +00:00
|
|
|
return context
|
|
|
|
|
2020-02-19 18:53:43 +00:00
|
|
|
def destroy(self, request, uid=None):
|
|
|
|
# FIXME: implement
|
|
|
|
return Response(status=status.HTTP_405_METHOD_NOT_ALLOWED)
|
|
|
|
|
|
|
|
def create(self, request, *args, **kwargs):
|
2020-04-15 12:23:07 +00:00
|
|
|
serializer = self.serializer_class(data=request.data, context=self.get_serializer_context())
|
2020-02-19 18:53:43 +00:00
|
|
|
if serializer.is_valid():
|
|
|
|
try:
|
2020-02-26 19:11:29 +00:00
|
|
|
serializer.save(owner=self.request.user)
|
2020-02-19 18:53:43 +00:00
|
|
|
except IntegrityError:
|
|
|
|
content = {'code': 'integrity_error'}
|
|
|
|
return Response(content, status=status.HTTP_400_BAD_REQUEST)
|
|
|
|
|
|
|
|
return Response({}, status=status.HTTP_201_CREATED)
|
|
|
|
|
|
|
|
return Response(serializer.errors, status=status.HTTP_400_BAD_REQUEST)
|
|
|
|
|
|
|
|
def list(self, request):
|
|
|
|
queryset = self.get_queryset()
|
|
|
|
|
2020-04-15 12:23:07 +00:00
|
|
|
serializer = self.serializer_class(queryset, context=self.get_serializer_context(), many=True)
|
2020-02-19 18:53:43 +00:00
|
|
|
return Response(serializer.data)
|
|
|
|
|
|
|
|
|
|
|
|
class CollectionItemViewSet(BaseViewSet):
|
2020-02-26 13:53:25 +00:00
|
|
|
allowed_methods = ['GET', 'POST', 'PUT']
|
2020-02-19 18:53:43 +00:00
|
|
|
permission_classes = BaseViewSet.permission_classes
|
|
|
|
queryset = CollectionItem.objects.all()
|
|
|
|
serializer_class = CollectionItemSerializer
|
|
|
|
pagination_class = paginators.LinkHeaderPagination
|
|
|
|
lookup_field = 'uid'
|
|
|
|
|
|
|
|
def get_queryset(self):
|
|
|
|
collection_uid = self.kwargs['collection_uid']
|
|
|
|
try:
|
|
|
|
collection = self.get_collection_queryset(Collection.objects).get(uid=collection_uid)
|
|
|
|
except Collection.DoesNotExist:
|
|
|
|
raise Http404("Collection does not exist")
|
2020-02-20 20:41:39 +00:00
|
|
|
# XXX Potentially add this for performance: .prefetch_related('revisions__chunks')
|
2020-02-26 14:42:49 +00:00
|
|
|
queryset = type(self).queryset.filter(collection__pk=collection.pk,
|
|
|
|
revisions__current=True,
|
2020-02-26 14:55:47 +00:00
|
|
|
revisions__deleted=False)
|
2020-02-19 18:53:43 +00:00
|
|
|
|
|
|
|
return queryset
|
|
|
|
|
2020-04-15 12:23:07 +00:00
|
|
|
def get_serializer_context(self):
|
|
|
|
context = super().get_serializer_context()
|
2020-04-16 08:35:58 +00:00
|
|
|
inline = 'inline' in self.request.query_params
|
2020-04-15 13:47:31 +00:00
|
|
|
context.update({'request': self.request, 'inline': inline})
|
2020-04-15 12:23:07 +00:00
|
|
|
return context
|
|
|
|
|
2020-02-19 18:53:43 +00:00
|
|
|
def create(self, request, collection_uid=None):
|
2020-02-26 12:20:23 +00:00
|
|
|
collection_object = get_object_or_404(self.get_collection_queryset(Collection.objects), uid=collection_uid)
|
2020-02-19 18:53:43 +00:00
|
|
|
|
2020-02-26 12:20:52 +00:00
|
|
|
# FIXME: change this to also support bulk update, or have another endpoint for that.
|
|
|
|
# See https://www.django-rest-framework.org/api-guide/serializers/#customizing-multiple-update
|
2020-02-19 18:53:43 +00:00
|
|
|
many = isinstance(request.data, list)
|
|
|
|
serializer = self.serializer_class(data=request.data, many=many)
|
2020-02-20 11:56:16 +00:00
|
|
|
if serializer.is_valid():
|
|
|
|
try:
|
|
|
|
serializer.save(collection=collection_object)
|
|
|
|
except IntegrityError:
|
|
|
|
content = {'code': 'integrity_error'}
|
|
|
|
return Response(content, status=status.HTTP_400_BAD_REQUEST)
|
|
|
|
|
|
|
|
return Response({}, status=status.HTTP_201_CREATED)
|
|
|
|
|
|
|
|
return Response(serializer.errors, status=status.HTTP_400_BAD_REQUEST)
|
|
|
|
|
|
|
|
def destroy(self, request, collection_uid=None, uid=None):
|
2020-02-26 13:53:25 +00:00
|
|
|
# We can't have destroy because we need to get data from the user (in the body) such as hmac.
|
2020-02-20 11:56:16 +00:00
|
|
|
return Response(status=status.HTTP_405_METHOD_NOT_ALLOWED)
|
|
|
|
|
|
|
|
def partial_update(self, request, collection_uid=None, uid=None):
|
|
|
|
# FIXME: implement, or should it be implemented elsewhere?
|
|
|
|
return Response(status=status.HTTP_405_METHOD_NOT_ALLOWED)
|
|
|
|
|
2020-02-20 14:35:20 +00:00
|
|
|
@action_decorator(detail=True, methods=['GET'])
|
2020-02-20 20:41:39 +00:00
|
|
|
def revision(self, request, collection_uid=None, uid=None):
|
2020-02-26 19:13:33 +00:00
|
|
|
col = get_object_or_404(self.get_collection_queryset(Collection.objects), uid=collection_uid)
|
2020-02-20 14:35:20 +00:00
|
|
|
col_it = get_object_or_404(col.items, uid=uid)
|
|
|
|
|
2020-02-20 20:41:39 +00:00
|
|
|
serializer = CollectionItemRevisionSerializer(col_it.revisions.order_by('-id'), many=True)
|
2020-02-20 14:35:20 +00:00
|
|
|
return Response(serializer.data)
|
|
|
|
|
2020-02-26 12:20:52 +00:00
|
|
|
@action_decorator(detail=False, methods=['POST'])
|
|
|
|
def bulk_get(self, request, collection_uid=None):
|
|
|
|
queryset = self.get_queryset()
|
|
|
|
|
|
|
|
if isinstance(request.data, list):
|
|
|
|
queryset = queryset.filter(uid__in=request.data)
|
|
|
|
|
|
|
|
serializer = self.get_serializer_class()(queryset, many=True)
|
|
|
|
return Response(serializer.data, status=status.HTTP_200_OK)
|
|
|
|
|
2020-02-20 11:56:16 +00:00
|
|
|
|
|
|
|
class CollectionItemChunkViewSet(viewsets.ViewSet):
|
|
|
|
allowed_methods = ['GET', 'POST']
|
2020-02-20 12:42:35 +00:00
|
|
|
parser_classes = (parsers.MultiPartParser, )
|
2020-02-20 11:56:16 +00:00
|
|
|
authentication_classes = BaseViewSet.authentication_classes
|
|
|
|
permission_classes = BaseViewSet.permission_classes
|
2020-02-20 12:42:35 +00:00
|
|
|
serializer_class = CollectionItemChunkSerializer
|
2020-02-20 11:56:16 +00:00
|
|
|
lookup_field = 'uid'
|
|
|
|
|
2020-02-20 15:33:34 +00:00
|
|
|
def get_collection_queryset(self, queryset=Collection.objects):
|
2020-02-26 19:13:33 +00:00
|
|
|
user = self.request.user
|
|
|
|
return queryset.filter(members__user=user)
|
2020-02-20 15:33:34 +00:00
|
|
|
|
2020-02-20 12:42:35 +00:00
|
|
|
def create(self, request, collection_uid=None, collection_item_uid=None):
|
2020-02-20 15:33:34 +00:00
|
|
|
col = get_object_or_404(self.get_collection_queryset(), uid=collection_uid)
|
2020-02-20 12:42:35 +00:00
|
|
|
col_it = get_object_or_404(col.items, uid=collection_item_uid)
|
2020-02-20 11:56:16 +00:00
|
|
|
|
2020-02-20 12:42:35 +00:00
|
|
|
serializer = self.serializer_class(data=request.data)
|
2020-02-19 18:53:43 +00:00
|
|
|
if serializer.is_valid():
|
|
|
|
try:
|
2020-04-15 14:35:51 +00:00
|
|
|
serializer.save(item=col_it)
|
2020-02-19 18:53:43 +00:00
|
|
|
except IntegrityError:
|
|
|
|
content = {'code': 'integrity_error'}
|
|
|
|
return Response(content, status=status.HTTP_400_BAD_REQUEST)
|
|
|
|
|
|
|
|
return Response({}, status=status.HTTP_201_CREATED)
|
|
|
|
|
|
|
|
return Response(serializer.errors, status=status.HTTP_400_BAD_REQUEST)
|
2020-02-20 13:39:52 +00:00
|
|
|
|
|
|
|
@action_decorator(detail=True, methods=['GET'])
|
|
|
|
def download(self, request, collection_uid=None, collection_item_uid=None, uid=None):
|
|
|
|
import os
|
|
|
|
from django.views.static import serve
|
|
|
|
|
2020-02-20 15:33:34 +00:00
|
|
|
col = get_object_or_404(self.get_collection_queryset(), uid=collection_uid)
|
2020-02-20 13:39:52 +00:00
|
|
|
col_it = get_object_or_404(col.items, uid=collection_item_uid)
|
|
|
|
chunk = get_object_or_404(col_it.chunks, uid=uid)
|
|
|
|
|
|
|
|
filename = chunk.chunkFile.path
|
|
|
|
dirname = os.path.dirname(filename)
|
|
|
|
basename = os.path.basename(filename)
|
|
|
|
|
|
|
|
# FIXME: DO NOT USE! Use django-send file or etc instead.
|
|
|
|
return serve(request, basename, dirname)
|
2020-04-14 13:21:51 +00:00
|
|
|
|
|
|
|
|
|
|
|
class ResetViewSet(BaseViewSet):
|
|
|
|
allowed_methods = ['POST']
|
|
|
|
|
|
|
|
def post(self, request, *args, **kwargs):
|
|
|
|
# Only run when in DEBUG mode! It's only used for tests
|
|
|
|
if not settings.DEBUG:
|
|
|
|
return HttpResponseBadRequest("Only allowed in debug mode.")
|
|
|
|
|
|
|
|
# Only allow local users, for extra safety
|
|
|
|
if not getattr(request.user, User.USERNAME_FIELD).endswith('@localhost'):
|
|
|
|
return HttpResponseBadRequest("Endpoint not allowed for user.")
|
|
|
|
|
|
|
|
# Delete all of the journal data for this user for a clear test env
|
|
|
|
request.user.collection_set.all().delete()
|
|
|
|
|
|
|
|
# FIXME: also delete chunk files!!!
|
|
|
|
|
|
|
|
return HttpResponse()
|
|
|
|
|
|
|
|
|
|
|
|
reset = ResetViewSet.as_view({'post': 'post'})
|