Coverage for api/admin/oauth.py: 96%
28 statements
« prev ^ index » next coverage.py v7.15.2, created at 2026-10-07 06:14 +0000
« prev ^ index » next coverage.py v7.15.2, created at 2026-10-07 06:14 +0000
1from django import forms
2from django.contrib import admin
4from oauth2_provider.models import AccessToken
6from api.constants.restricted_features import RestrictedFeature
7from api.models.oauth import ThrottledApplication
10def register(site):
11 site.register(ThrottledApplication, ThrottledApplicationAdmin)
12 site.register(AccessToken, AccessTokenAdmin)
15class ThrottledApplicationAdminForm(forms.ModelForm):
16 class Meta:
17 model = ThrottledApplication
18 exclude = (
19 "client_type",
20 "redirect_uris",
21 "post_logout_redirect_uris",
22 "skip_authorization",
23 "algorithm",
24 "user",
25 )
27 # ArrayField doesn't have a good default field, so use a multiple choice field, but
28 # override default widget of multi-<select>, which is much more annoying to use
29 # and easy to accidentally un-select an option. The multi-checkbox is much easier to use
30 privileges = forms.MultipleChoiceField(
31 choices=RestrictedFeature.choices,
32 required=False,
33 widget=forms.CheckboxSelectMultiple,
34 )
37class ThrottledApplicationAdmin(admin.ModelAdmin):
38 form = ThrottledApplicationAdminForm
39 view_on_site = False
41 search_fields = ("client_id", "name", "rate_limit_model", "privileges")
42 list_display = ("client_id", "name", "created", "rate_limit_model", "privileges")
43 list_filter = ("rate_limit_model", "verified")
44 ordering = ("-created",)
46 readonly_fields = (
47 "name",
48 "created",
49 "client_id",
50 "verified",
51 "authorization_grant_type",
52 "client_secret",
53 )
55 def has_delete_permission(self, *args, **kwargs):
56 """
57 Disallow deleting throttled applications. Use ``revoke`` instead.
59 This also hides the delete button on the change view.
60 """
61 return False
64class AccessTokenAdmin(admin.ModelAdmin):
65 search_fields = ("token", "id")
66 list_display = ("token", "id", "created", "scope", "expires")
67 ordering = ("-created",)
69 readonly_fields = (
70 "id",
71 "user",
72 "source_refresh_token",
73 "token",
74 "id_token",
75 "application",
76 "expires",
77 "scope",
78 "created",
79 "updated",
80 )