🔥(api) remove possibility to force document id on creation

This feature poses security issues in the way it is implemented.
We decide to remove it while clarifying the use case.
This commit is contained in:
Samuel Paccoud - DINUM
2024-09-08 23:29:08 +02:00
committed by Samuel Paccoud
parent 1e432cfdc2
commit dec1a1a870
2 changed files with 0 additions and 38 deletions

View File

@@ -321,19 +321,6 @@ class DocumentViewSet(
queryset = models.Document.objects.all()
ordering = ["-updated_at"]
def perform_create(self, serializer):
"""
Override perform_create to use the provided ID in the payload if it exists
"""
document_id = self.request.data.get("id")
document = serializer.save(id=document_id) if document_id else serializer.save()
self.access_model_class.objects.create(
user=self.request.user,
role=models.RoleChoices.OWNER,
**{self.resource_field_name: document},
)
def list(self, request, *args, **kwargs):
"""Restrict resources returned by the list endpoint"""
queryset = self.filter_queryset(self.get_queryset())