How do I prevent permission escalation in Django admin when granting “user change” permission?

后端 未结 5 1985
天命终不由人
天命终不由人 2020-12-23 21:49

I have a django site with a large customer base. I would like to give our customer service department the ability to alter normal user accounts, doing things like changing p

5条回答
  •  太阳男子
    2020-12-23 22:28

    Great thanks to Clément. What I came up with when doing the same for my site is that I needed additionally to make all fields readonly for users you other than self. So basing on Clément's answer I addeed readonly fields and password field hiding when viewing not self

    class MyUserAdmin(UserAdmin):
        model = User
        staff_self_fieldsets = (
            (None, {'fields': ('username', 'password')}),
            (_('Personal info'), {'fields': ('first_name', 'last_name', 'email')}),
            # No permissions
            (_('Important dates'), {'fields': ('last_login', 'date_joined')}),
        )
    
        staff_other_fieldsets = (
            (None, {'fields': ('username', )}),
            (_('Personal info'), {'fields': ('first_name', 'last_name', 'email')}),
            # No permissions
            (_('Important dates'), {'fields': ('last_login', 'date_joined')}),
        )
    
        staff_self_readonly_fields = ('last_login', 'date_joined')
    
        def change_view(self, request, object_id, form_url='', extra_context=None, *args, **kwargs):
            # for non-superuser
            if not request.user.is_superuser:
                try:
                    if int(object_id) != request.user.id:
                        self.readonly_fields = User._meta.get_all_field_names()
                        self.fieldsets = self.staff_other_fieldsets
                    else:
                        self.readonly_fields = self.staff_self_readonly_fields
                        self.fieldsets = self.staff_self_fieldsets
    
                    response = super(MyUserAdmin, self).change_view(request, object_id, form_url, extra_context, *args, **kwargs)
                except:
                    logger.error('Admin change view error. Returned all readonly fields')
    
                    self.fieldsets = self.staff_other_fieldsets
                    self.readonly_fields = ('first_name', 'last_name', 'email', 'username', 'password', 'last_login', 'date_joined')
                    response = super(MyUserAdmin, self).change_view(request, object_id, form_url, extra_context, *args, **kwargs)
                finally:
                    # Reset fieldsets to its original value
                    self.fieldsets = UserAdmin.fieldsets
                    self.readonly_fields = UserAdmin.readonly_fields
                return response
            else:
                return super(MyUserAdmin, self).change_view(request, object_id, form_url, extra_context, *args, **kwargs)
    

提交回复
热议问题