Coverage for src/backend/InvenTree/users/oauth2_scopes.py: 100%

11 statements  

« prev     ^ index     » next       coverage.py v7.15.2, created at 2026-10-07 17:47 +0000

1"""Static scope definitions for OAuth2 scopes.""" 

2 

3 

4def get_granular_scope(method, role=None, type='r'): 

5 """Generate a granular scope string for a given method and role.""" 

6 if role: 

7 return f'{type}:{method}:{role}' 

8 return f'{type}:{method}' 

9 

10 

11# region generated stuff 

12_roles = { 

13 'admin': 'Role Admin', 

14 'part_category': 'Role Part Categories', 

15 'part': 'Role Parts', 

16 'stock_location': 'Role Stock Locations', 

17 'stock': 'Role Stock Items', 

18 'bom': 'Role Bills of Material', 

19 'build': 'Role Build Orders', 

20 'purchase_order': 'Role Purchase Orders', 

21 'sales_order': 'Role Sales Orders', 

22 'return_order': 'Role Return Orders', 

23 'transfer_order': 'Role Transfer Orders', 

24} 

25_methods = {'view': 'GET', 'add': 'POST', 'change': 'PUT / PATCH', 'delete': 'DELETE'} 

26 

27calculated = { 

28 get_granular_scope(method[0], role[0]): f'{method[1]} for {role[1]}' 

29 for method in _methods.items() 

30 for role in _roles.items() 

31} 

32# endregion 

33 

34 

35DEFAULT_READ = get_granular_scope('read', type='g') 

36DEFAULT_STAFF = get_granular_scope('staff', type='a') 

37DEFAULT_SUPERUSER = get_granular_scope('superuser', type='a') 

38# This is actually used 

39oauth2_scopes = { 

40 DEFAULT_READ: 'General Read scope', 

41 'openid': 'OpenID Connect scope', 

42 # Admin scopes 

43 DEFAULT_STAFF: 'User Role Staff', 

44 DEFAULT_SUPERUSER: 'User Role Superuser', 

45} | calculated