Coverage for api/admin/oauth.py: 96%

28 statements  

« prev     ^ index     » next       coverage.py v7.15.2, created at 2026-10-07 06:14 +0000

1from django import forms 

2from django.contrib import admin 

3 

4from oauth2_provider.models import AccessToken 

5 

6from api.constants.restricted_features import RestrictedFeature 

7from api.models.oauth import ThrottledApplication 

8 

9 

10def register(site): 

11 site.register(ThrottledApplication, ThrottledApplicationAdmin) 

12 site.register(AccessToken, AccessTokenAdmin) 

13 

14 

15class ThrottledApplicationAdminForm(forms.ModelForm): 

16 class Meta: 

17 model = ThrottledApplication 

18 exclude = ( 

19 "client_type", 

20 "redirect_uris", 

21 "post_logout_redirect_uris", 

22 "skip_authorization", 

23 "algorithm", 

24 "user", 

25 ) 

26 

27 # ArrayField doesn't have a good default field, so use a multiple choice field, but 

28 # override default widget of multi-<select>, which is much more annoying to use 

29 # and easy to accidentally un-select an option. The multi-checkbox is much easier to use 

30 privileges = forms.MultipleChoiceField( 

31 choices=RestrictedFeature.choices, 

32 required=False, 

33 widget=forms.CheckboxSelectMultiple, 

34 ) 

35 

36 

37class ThrottledApplicationAdmin(admin.ModelAdmin): 

38 form = ThrottledApplicationAdminForm 

39 view_on_site = False 

40 

41 search_fields = ("client_id", "name", "rate_limit_model", "privileges") 

42 list_display = ("client_id", "name", "created", "rate_limit_model", "privileges") 

43 list_filter = ("rate_limit_model", "verified") 

44 ordering = ("-created",) 

45 

46 readonly_fields = ( 

47 "name", 

48 "created", 

49 "client_id", 

50 "verified", 

51 "authorization_grant_type", 

52 "client_secret", 

53 ) 

54 

55 def has_delete_permission(self, *args, **kwargs): 

56 """ 

57 Disallow deleting throttled applications. Use ``revoke`` instead. 

58 

59 This also hides the delete button on the change view. 

60 """ 

61 return False 

62 

63 

64class AccessTokenAdmin(admin.ModelAdmin): 

65 search_fields = ("token", "id") 

66 list_display = ("token", "id", "created", "scope", "expires") 

67 ordering = ("-created",) 

68 

69 readonly_fields = ( 

70 "id", 

71 "user", 

72 "source_refresh_token", 

73 "token", 

74 "id_token", 

75 "application", 

76 "expires", 

77 "scope", 

78 "created", 

79 "updated", 

80 )