Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[issue1020] Fix django-inplaceedit permissions to allow public editing #1346

Merged
merged 1 commit into from Aug 8, 2014
Merged
Changes from all commits
Commits
File filter...
Filter file types
Jump to…
Jump to file or symbol
Failed to load files and symbols.

Always

Just for now

@@ -18,6 +18,8 @@
# You should have received a copy of the GNU Affero General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.

import mysite.bugsets.models

from django.conf import settings


@@ -28,4 +30,8 @@ def can_edit(cls, adaptor_field):
if settings.DEBUG:
return True # All users can edit

# Only allow django-inplaceedit to edit AnnotatedBug objects
if isinstance(adaptor_field.obj, mysite.bugsets.models.AnnotatedBug):
return True

return False
@@ -185,6 +185,26 @@ def test_will_inplaceedit_allow_us_to_pwn_ourselves(self):

self.assertEqual(User.objects.get(pk=u.pk).username, u'paulproteus')

def test_modify_annotatedbug_object(self):
b = mysite.bugsets.models.AnnotatedBug.objects.create(
url="http://openhatch.org/bugs/issue995",
mentor="Elana",
)
b.save()

self.client.post(
'/inplaceeditform/save/',
{
"app_label": "bugsets",
"module_name": "annotatedbug",
"field_name": "mentor",
"obj_id": b.pk,
"value": '"Asheesh"'
})

self.assertEqual(mysite.bugsets.models.AnnotatedBug.objects.get(
pk=b.pk).mentor, 'Asheesh')


class BasicBugsetCreateViewTests(TwillTests):
event_name = "Party at Asheesh's Place"
ProTip! Use n and p to navigate between commits in a pull request.
You can’t perform that action at this time.