Commit 7ba4ab25 authored by Ilham Maulana's avatar Ilham Maulana 💻

fix: simple jwt logout and permissions

parent e0da5b69
...@@ -51,7 +51,7 @@ class LibrarianLoginHistoryViewSet(viewsets.ModelViewSet): ...@@ -51,7 +51,7 @@ class LibrarianLoginHistoryViewSet(viewsets.ModelViewSet):
class MemberViewSet(viewsets.ModelViewSet): class MemberViewSet(viewsets.ModelViewSet):
permission_classes = [IsStaffUser] permission_classes = [IsNotStaffUser]
queryset = Member.objects.all().order_by("created_at") queryset = Member.objects.all().order_by("created_at")
serializer_class = MemberSerializer serializer_class = MemberSerializer
...@@ -63,16 +63,6 @@ class MemberViewSet(viewsets.ModelViewSet): ...@@ -63,16 +63,6 @@ class MemberViewSet(viewsets.ModelViewSet):
"user__last_name", "user__last_name",
] ]
def list(self, request):
if self.request.user.is_staff:
return Response(
{"message": "Access Denied"}, status=status.HTTP_406_NOT_ACCEPTABLE
)
queryset = self.filter_queryset(self.get_queryset())
serializer = self.get_serializer(queryset, many=True)
return Response(serializer.data)
def update(self, request, pk): def update(self, request, pk):
instance = self.get_object() instance = self.get_object()
serializer = self.get_serializer(instance, data=request.data, partial=True) serializer = self.get_serializer(instance, data=request.data, partial=True)
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment