-
Notifications
You must be signed in to change notification settings - Fork 24
ProfileAvatar doesn't specify permissions #74
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
👍 |
Added tests
|
Review Please? Yes I'm aware of the typo in the branch name. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Why are you setting request.user for an unauthenticated request?
user_management/api/avatar/views.py
Outdated
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I don't think IsAuthenticatedOrReadOnly is necessary.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The avatar will need to be gotten by unauthenticated users, so I think IsAuthenticatedOrReadOnly is correct.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
That's what the UserAvatar view is for I think.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
You don't care about this user any more.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
avatars.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
You're not actually testing post here.
|
@ian-foote That should do it |
1 similar comment
ProfileAvatar doesn't specify permissions
ProfileAvatardoesn't setpermission_classes. This should useIsAuthenticatedto avoid the possibility of misconfiguration.