(api) update mailboxes

Allow update of mailboxes. Secondary email, first and last names can be updated
but not domain or local_part.
This commit is contained in:
Marie PUPO JEAMMET
2025-07-09 15:59:35 +02:00
committed by Marie
parent 79f8e5276a
commit e45cf8dd8b
8 changed files with 440 additions and 2 deletions

View File

@@ -29,7 +29,6 @@ class MailboxSerializer(serializers.ModelSerializer):
"secondary_email",
"status",
]
# everything is actually read-only as we do not allow update for now
read_only_fields = ["id", "status"]
def create(self, validated_data):
@@ -71,6 +70,22 @@ class MailboxSerializer(serializers.ModelSerializer):
return mailbox
class MailboxUpdateSerializer(MailboxSerializer):
"""A more restrictive serializer when updating mailboxes"""
class Meta:
model = models.Mailbox
fields = [
"id",
"first_name",
"last_name",
"local_part",
"secondary_email",
"status",
]
read_only_fields = ("id", "status", "local_part", "status")
class MailDomainSerializer(serializers.ModelSerializer):
"""Serialize mail domain."""

View File

@@ -228,9 +228,10 @@ class MailDomainAccessViewSet(
class MailBoxViewSet(
viewsets.GenericViewSet,
mixins.CreateModelMixin,
mixins.ListModelMixin,
viewsets.GenericViewSet,
mixins.UpdateModelMixin,
):
"""MailBox ViewSet
@@ -252,6 +253,12 @@ class MailBoxViewSet(
POST /api/<version>/mail-domains/<domain_slug>/mailboxes/<mailbox_id>/reset/
Send a request to mail-provider to reset password.
PUT /api/<version>/mail-domains/<domain_slug>/mailboxes/<mailbox_id>/
Send a request to update mailbox. Cannot modify domain or local_part.
PATCH /api/<version>/mail-domains/<domain_slug>/mailboxes/<mailbox_id>/
Send a request to partially update mailbox. Cannot modify domain or local_part.
"""
permission_classes = [permissions.MailBoxPermission]
@@ -267,6 +274,12 @@ class MailBoxViewSet(
return self.queryset.filter(domain__slug=domain_slug)
return self.queryset
def get_serializer_class(self):
"""Chooses list or detail serializer according to the action."""
if self.action in {"update", "partial_update"}:
return serializers.MailboxUpdateSerializer
return self.serializer_class
def perform_create(self, serializer):
"""Create new mailbox."""
domain_slug = self.kwargs.get("domain_slug", "")

View File

@@ -23,6 +23,11 @@ class MailBoxPermission(core_permissions.IsAuthenticated):
abilities = domain.get_abilities(request.user)
return abilities.get(request.method.lower(), False)
def has_object_permission(self, request, view, obj):
"""Check permission for a given object."""
abilities = obj.get_abilities(request.user)
return abilities.get(request.method.lower(), False)
class MailDomainAccessRolePermission(core_permissions.IsAuthenticated):
"""Permission class to manage mailboxes for a mail domain"""