summaryrefslogtreecommitdiff
path: root/postgresqleu/util/auth.py
blob: aeb4311d19f76d7ac2457b53462edf856176b4f9 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
from django.core.exceptions import PermissionDenied
from postgresqleu.util.middleware import RedirectException
from django.conf import settings

import urllib.parse


PERMISSION_GROUPS = (
    'Invoice managers',
    'News administrators',
    'Membership administrators',
    'Election administrators',
    'Accounting managers',
)


def authenticate_backend_group(request, groupname):
    if not request.user.is_authenticated:
        raise RedirectException("{0}?{1}".format(settings.LOGIN_URL, urllib.parse.urlencode({'next': request.build_absolute_uri()})))

    if groupname not in PERMISSION_GROUPS:
        raise PermissionDenied("Group name not known")

    if request.user.is_superuser:
        return
    if request.user.groups.filter(name=groupname).exists():
        return

    raise PermissionDenied("Access denied")