过滤过滤器:按用户权限限制django admin过滤器中的选择

时间:2018-08-24 19:07:20

标签: django django-admin

好,所以我现在可以限制更改表中的可用选择,如下所示:

def formfield_for_foreignkey(self, db_field, request, **kwargs):
    from login.models import Room
    groups = [group.name for group in request.user.groups.all()]
    if 'principal' in groups:
        schoolname = request.user.principal.school.name
        if db_field.name == 'room':
            print("match")
            kwargs['queryset'] = Room.objects.filter(school__name=schoolname)
    return super().formfield_for_foreignkey(db_field, request, **kwargs)

list_display = ('surname','givennames', 'room')
list_filter = ('room',)

也就是说,上面的方法成功地向用户显示了仅在其学校就读的学生。

我的麻烦是,用户仍然会在list_filter上看到他们未连接的学校房间,而忽略了formfield_for_foreignkey

因此,下拉菜单显示的是该地区所有学校的数百个教室,而不是将六个教室作为过滤器的选择。我试图找到一个相当简单的答案,但没有提出任何建议。我想要的是类似formfield_for_foreignkey的东西,可以应用于我的过滤器选择。

我要过滤过滤器的选择!难怪谷歌没有帮助!

这很难清楚地表达出来,所以我将重复我自己,希望我的冗余有一定的明确性。

我正在尝试过滤可供用户过滤的选项,仅过滤用户具有写权限的那些选项。我想要一些可供学校校长过滤学生名单的房间;相反,我得到了很多,但大多数都不适用,因为该委托人在那里没有读取或写入权限。

根据我的经验,我发现似乎可能相关的示例对我来说是完全不透明的。

那里有简单的食谱吗?谢谢!

1 个答案:

答案 0 :(得分:1)

这是我完整的解决方案;

class StudentAdmin(admin.ModelAdmin):

    def get_queryset(self,request):
        # if principal (not district user) only show students
        # whose classroom is in principal's school

        qs = super(StudentAdmin, self).get_queryset(request)
        if request.user.is_superuser:
            return qs
        else:
            groups = [group.name for group in request.user.groups.all()]
            if 'principal' in groups:
                school = request.user.principal.school
                return qs.filter(room__school=school)
            else:
                return qs

    def formfield_for_foreignkey(self, db_field, request, **kwargs):
        # if principal (not district administrator) 
        # limit transfer to within principal's school

        from login.models import Room
        groups = [group.name for group in request.user.groups.all()]
        if 'principal' in groups:
            schoolname = request.user.principal.school.name
            print(db_field)
            print(type(db_field))
            if db_field.name == 'room':
                print("match")
                kwargs['queryset'] = Room.objects.filter(school__name=schoolname)
        return super().formfield_for_foreignkey(db_field, request, **kwargs)


    class CustomRoom(admin.SimpleListFilter):
        # if principal (not district user)
        # only offer filter to classrooms in principal's school  

        title = 'Classroom'
        parameter_name = 'classroom'

        def lookups(self,request,model_admin):
            from login.models import Room,School
            groups = [group.name for group in request.user.groups.all()]
            if 'principal' in groups:
                school = request.user.principal.school
                rooms = Room.objects.filter(school=school)
                return ((room.id,room.roomno) for room in rooms)
            else:
                rooms = Room.objects.all()
                return ((room.id,room.roomno) for room in rooms)

        def queryset(self,request,queryset):
            selected = self.value()

            # WAS return queryset.filter(room=selected)
            # this does not handle All case correctly 

            if selected:
                return queryset.filter(room=selected)
            else:
                 return queryset


    list_display = ('surname','givennames', 'room')
    list_filter=('enrolled',CustomRoom,)

# Register the admin class with the associated model
admin.site.register(Student, StudentAdmin)

比我想要的要混乱的多,但是如果您将其视为三个独立的小步骤,那就不是太可怕了。