Coverage for conf/settings/rest_framework.py: 91%
18 statements
« prev ^ index » next coverage.py v7.15.2, created at 2026-10-07 06:14 +0000
« prev ^ index » next coverage.py v7.15.2, created at 2026-10-07 06:14 +0000
1from decouple import config
3from conf.settings.base import INSTALLED_APPS
6if "rest_framework" not in INSTALLED_APPS: 6 ↛ 10line 6 didn't jump to line 10 because the condition on line 6 was always true
7 INSTALLED_APPS.append("rest_framework")
10THROTTLE_ANON_BURST = config("THROTTLE_ANON_BURST", default="5/hour")
11THROTTLE_ANON_SUSTAINED = config("THROTTLE_ANON_SUSTAINED", default="100/day")
12THROTTLE_ANON_THUMBS = config("THROTTLE_ANON_THUMBS", default="150/minute")
13THROTTLE_OAUTH2_THUMBS = config("THROTTLE_OAUTH2_THUMBS", default="500/minute")
14THROTTLE_ANON_HEALTHCHECK = config("THROTTLE_ANON_HEALTHCHECK", default="3/minute")
16THROTTLE_OV_REFERRER_BURST = config(
17 "THROTTLE_OV_REFERRER_BURST", default=THROTTLE_ANON_BURST
18)
19THROTTLE_OV_REFERRER_SUSTAINED = config(
20 "THROTTLE_OV_REFERRER_SUSTAINED", default=THROTTLE_ANON_SUSTAINED
21)
22THROTTLE_OV_REFERRER_THUMBS = config(
23 "THROTTLE_OV_REFERRER_THUMBS", default=THROTTLE_ANON_THUMBS
24)
26DEFAULT_THROTTLE_RATES = {
27 "anon_burst": THROTTLE_ANON_BURST,
28 "anon_sustained": THROTTLE_ANON_SUSTAINED,
29 "anon_healthcheck": THROTTLE_ANON_HEALTHCHECK,
30 "anon_thumbnail": THROTTLE_ANON_THUMBS,
31 "ov_referrer_burst": THROTTLE_OV_REFERRER_BURST,
32 "ov_referrer_sustained": THROTTLE_OV_REFERRER_SUSTAINED,
33 "ov_referrer_thumbnail": THROTTLE_OV_REFERRER_THUMBS,
34 "oauth2_client_credentials_thumbnail": THROTTLE_OAUTH2_THUMBS,
35 "oauth2_client_credentials_sustained": "10000/day",
36 "oauth2_client_credentials_burst": "100/min",
37 "enhanced_oauth2_client_credentials_sustained": "20000/day",
38 "enhanced_oauth2_client_credentials_burst": "200/min",
39 # ``None`` completely by-passes the rate limiting
40 "exempt_oauth2_client_credentials": None,
41}
43DEFAULT_THROTTLE_CLASSES = (
44 "api.utils.throttle.BurstRateThrottle",
45 "api.utils.throttle.SustainedRateThrottle",
46 "api.utils.throttle.OpenverseReferrerBurstRateThrottle",
47 "api.utils.throttle.OpenverseReferrerSustainedRateThrottle",
48 "api.utils.throttle.OAuth2IdBurstRateThrottle",
49 "api.utils.throttle.OAuth2IdSustainedRateThrottle",
50 "api.utils.throttle.EnhancedOAuth2IdBurstRateThrottle",
51 "api.utils.throttle.EnhancedOAuth2IdSustainedRateThrottle",
52 "api.utils.throttle.ExemptOAuth2IdRateThrottle",
53)
55REST_FRAMEWORK = {
56 "DEFAULT_AUTHENTICATION_CLASSES": ("conf.oauth2_extensions.OAuth2Authentication",),
57 "DEFAULT_VERSIONING_CLASS": "rest_framework.versioning.URLPathVersioning",
58 "DEFAULT_RENDERER_CLASSES": (
59 "rest_framework.renderers.JSONRenderer",
60 "api.utils.drf_renderer.BrowsableAPIRendererWithoutForms",
61 ),
62 "DEFAULT_THROTTLE_CLASSES": DEFAULT_THROTTLE_CLASSES,
63 "DEFAULT_THROTTLE_RATES": DEFAULT_THROTTLE_RATES.copy(),
64 "EXCEPTION_HANDLER": "api.utils.exceptions.exception_handler",
65 "DEFAULT_SCHEMA_CLASS": "api.docs.base_docs.MediaSchema",
66 # https://www.django-rest-framework.org/api-guide/throttling/#how-clients-are-identified
67 # Live environments should configure this to an appropriate number
68 "NUM_PROXIES": config(
69 "NUM_PROXIES", default=None, cast=lambda x: int(x) if x is not None else None
70 ),
71}
73if config("DISABLE_GLOBAL_THROTTLING", default=True, cast=bool): 73 ↛ exitline 73 didn't exit the module because the condition on line 73 was always true
74 # Set all to ``None`` rather than deleting so that explicitly configured
75 # throttled views in tests still have the default rates to fall back onto
76 REST_FRAMEWORK["DEFAULT_THROTTLE_RATES"].update(
77 **{k: None for k, _ in REST_FRAMEWORK["DEFAULT_THROTTLE_RATES"].items()}
78 )
79 del REST_FRAMEWORK["DEFAULT_THROTTLE_CLASSES"]