blob: f58581cf5b568e5991b5e9b73c8129d5c99c89cf (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
|
from opendc.models.model import Model
from opendc.models.user import User
from opendc.util.rest import Response
class Simulation(Model):
collection_name = 'simulations'
def validate_user_access(self, google_id, edit_access):
user = User.from_google_id(google_id)
authorizations = list(
filter(lambda x: str(x['simulationId']) == str(self.obj['_id']), user.obj['authorizations']))
if len(authorizations) == 0 or (edit_access and authorizations[0]['authorizationLevel'] == 'VIEW'):
return Response(403, "Forbidden from retrieving simulation.")
return None
|