diff --git a/api/v1/views.py b/api/v1/views.py index c2bc1f07..04e2beb5 100644 --- a/api/v1/views.py +++ b/api/v1/views.py @@ -1,7 +1,7 @@ from django.contrib.auth import get_user_model from rest_framework import status, views, viewsets, generics -from rest_framework.decorators import detail_route, list_route, action +from rest_framework.decorators import detail_route, list_route, action, permission_classes from rest_framework.response import Response from . import ExtendedModelViewSet @@ -451,7 +451,6 @@ class CommentViewSet(ExtendedModelViewSet): class ObjectCommentsViewSet(ExtendedModelViewSet): queryset = Comment.objects.all() serializer_class = CommentCreateSerializer - permission_classes = (IsAuthorObjectOrAdmin,) ordering_fields = ('update_at', ) def get_queryset(self): @@ -495,6 +494,7 @@ class ObjectCommentsViewSet(ExtendedModelViewSet): except Exception as e: print(e) + @permission_classes((IsAuthorObjectOrAdmin,)) def perform_destroy(self, instance): obj_type = None obj_id = None diff --git a/project/templates/blocks/lil_store_js.html b/project/templates/blocks/lil_store_js.html index 968ded1a..77e179b8 100644 --- a/project/templates/blocks/lil_store_js.html +++ b/project/templates/blocks/lil_store_js.html @@ -2,6 +2,12 @@ {% load setting from settings %}