Skip to content
Projeler
Gruplar
Parçacıklar
Yardım
Yükleniyor...
Oturum aç / Kaydol
Gezinmeyi değiştir
D
django
Proje
Proje
Ayrıntılar
Etkinlik
Cycle Analytics
Depo (repository)
Depo (repository)
Dosyalar
Kayıtlar (commit)
Dallar (branch)
Etiketler
Katkıda bulunanlar
Grafik
Karşılaştır
Grafikler
Konular (issue)
0
Konular (issue)
0
Liste
Pano
Etiketler
Kilometre Taşları
Birleştirme (merge) Talepleri
0
Birleştirme (merge) Talepleri
0
CI / CD
CI / CD
İş akışları (pipeline)
İşler
Zamanlamalar
Grafikler
Paketler
Paketler
Wiki
Wiki
Parçacıklar
Parçacıklar
Üyeler
Üyeler
Collapse sidebar
Close sidebar
Etkinlik
Grafik
Grafikler
Yeni bir konu (issue) oluştur
İşler
Kayıtlar (commit)
Konu (issue) Panoları
Kenar çubuğunu aç
Batuhan Osman TASKAYA
django
Commits
5b733171
Kaydet (Commit)
5b733171
authored
Haz 18, 2018
tarafından
Carlton Gibson
Kaydeden (comit)
Tim Graham
Haz 18, 2018
Dosyalara gözat
Seçenekler
Dosyalara Gözat
İndir
Eposta Yamaları
Sade Fark
Fixed #29502 -- Allowed users with the view permission to use autocomplete_fields.
üst
958c7b30
Hide whitespace changes
Inline
Side-by-side
Showing
3 changed files
with
16 additions
and
11 deletions
+16
-11
autocomplete.py
django/contrib/admin/views/autocomplete.py
+1
-1
index.txt
docs/ref/contrib/admin/index.txt
+3
-0
test_autocomplete_view.py
tests/admin_views/test_autocomplete_view.py
+12
-10
No files found.
django/contrib/admin/views/autocomplete.py
Dosyayı görüntüle @
5b733171
...
@@ -49,4 +49,4 @@ class AutocompleteJsonView(BaseListView):
...
@@ -49,4 +49,4 @@ class AutocompleteJsonView(BaseListView):
def
has_perm
(
self
,
request
,
obj
=
None
):
def
has_perm
(
self
,
request
,
obj
=
None
):
"""Check if user has permission to access the related model."""
"""Check if user has permission to access the related model."""
return
self
.
model_admin
.
has_
change
_permission
(
request
,
obj
=
obj
)
return
self
.
model_admin
.
has_
view
_permission
(
request
,
obj
=
obj
)
docs/ref/contrib/admin/index.txt
Dosyayı görüntüle @
5b733171
...
@@ -1117,6 +1117,9 @@ subclass::
...
@@ -1117,6 +1117,9 @@ subclass::
You must define :attr:`~ModelAdmin.search_fields` on the related object's
You must define :attr:`~ModelAdmin.search_fields` on the related object's
``ModelAdmin`` because the autocomplete search uses it.
``ModelAdmin`` because the autocomplete search uses it.
To avoid unauthorized data disclosure, users must have the ``view`` or
``change`` permission to the related object in order to use autocomplete.
Ordering and pagination of the results are controlled by the related
Ordering and pagination of the results are controlled by the related
``ModelAdmin``'s :meth:`~ModelAdmin.get_ordering` and
``ModelAdmin``'s :meth:`~ModelAdmin.get_ordering` and
:meth:`~ModelAdmin.get_paginator` methods.
:meth:`~ModelAdmin.get_paginator` methods.
...
...
tests/admin_views/test_autocomplete_view.py
Dosyayı görüntüle @
5b733171
...
@@ -69,7 +69,7 @@ class AutocompleteJsonViewTests(AdminViewBasicTestCase):
...
@@ -69,7 +69,7 @@ class AutocompleteJsonViewTests(AdminViewBasicTestCase):
response
=
self
.
client
.
get
(
self
.
url
,
{
'term'
:
''
})
response
=
self
.
client
.
get
(
self
.
url
,
{
'term'
:
''
})
self
.
assertEqual
(
response
.
status_code
,
302
)
self
.
assertEqual
(
response
.
status_code
,
302
)
def
test_has_change_permission_required
(
self
):
def
test_has_
view_or_
change_permission_required
(
self
):
"""
"""
Users require the change permission for the related model to the
Users require the change permission for the related model to the
autocomplete view for it.
autocomplete view for it.
...
@@ -81,15 +81,17 @@ class AutocompleteJsonViewTests(AdminViewBasicTestCase):
...
@@ -81,15 +81,17 @@ class AutocompleteJsonViewTests(AdminViewBasicTestCase):
response
=
AutocompleteJsonView
.
as_view
(
**
self
.
as_view_args
)(
request
)
response
=
AutocompleteJsonView
.
as_view
(
**
self
.
as_view_args
)(
request
)
self
.
assertEqual
(
response
.
status_code
,
403
)
self
.
assertEqual
(
response
.
status_code
,
403
)
self
.
assertJSONEqual
(
response
.
content
.
decode
(
'utf-8'
),
{
'error'
:
'403 Forbidden'
})
self
.
assertJSONEqual
(
response
.
content
.
decode
(
'utf-8'
),
{
'error'
:
'403 Forbidden'
})
# Add the change permission and retry.
for
permission
in
(
'view'
,
'change'
):
p
=
Permission
.
objects
.
get
(
with
self
.
subTest
(
permission
=
permission
):
content_type
=
ContentType
.
objects
.
get_for_model
(
Question
),
self
.
user
.
user_permissions
.
clear
()
codename
=
'change_question'
,
p
=
Permission
.
objects
.
get
(
)
content_type
=
ContentType
.
objects
.
get_for_model
(
Question
),
self
.
user
.
user_permissions
.
add
(
p
)
codename
=
'
%
s_question'
%
permission
,
request
.
user
=
User
.
objects
.
get
(
pk
=
self
.
user
.
pk
)
)
response
=
AutocompleteJsonView
.
as_view
(
**
self
.
as_view_args
)(
request
)
self
.
user
.
user_permissions
.
add
(
p
)
self
.
assertEqual
(
response
.
status_code
,
200
)
request
.
user
=
User
.
objects
.
get
(
pk
=
self
.
user
.
pk
)
response
=
AutocompleteJsonView
.
as_view
(
**
self
.
as_view_args
)(
request
)
self
.
assertEqual
(
response
.
status_code
,
200
)
def
test_search_use_distinct
(
self
):
def
test_search_use_distinct
(
self
):
"""
"""
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment