#28131: Template variable "perms" single-attribute lookup does not work as
expected
-------------------------------------------+------------------------
Reporter: Meiyer | Owner: nobody
Type: Bug | Status: new
Component: Template system | Version: 1.8
Severity: Normal | Keywords:
Triage Stage: Unreviewed | Has patch: 0
Needs documentation: 0 | Needs tests: 0
Patch needs improvement: 0 | Easy pickings: 0
UI/UX: 0 |
-------------------------------------------+------------------------
The
[https://docs.djangoproject.com/en/1.11/topics/auth/default/#permissions
documentation] states that the template variable `perms` may be used with
single-attribute lookup `{{ perms.foo }}` to check for module-level
permissions, proxying to `User.has_module_perms`.
This is not the case in reality. Using single-attribute lookup causes the
tag to output all permissions the user has in the module `foo`, as text.
This is caused by `django.contrib.auth.context_processors.PermWrapper`’s
method
{{{#!python
def __getitem__(self, app_label):
return PermLookupDict(self.user, app_label)
}}}
which in turn invokes the `PermLookupDict`’s method
{{{#!python
def __repr__(self):
return str(self.user.get_all_permissions())
}}}
The behaviour is different from the `{{ "foo" in perms }}` construct,
which resolves to `PermWrapper`’s `__contains__` that correctly casts the
operation to a boolean, causing the `PermLookupDict`’s method
{{{#!python
def __bool__(self):
return self.user.has_module_perms(self.app_label)
}}}
to be used instead.
This issue goes back to at least version 1.6 and forward through all
versions up to 1.11 (and apparently the single-attribute lookup feature is
not used by anyone because this issue went unreported for at least four
years).
--
Ticket URL: <https://code.djangoproject.com/ticket/28131>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.
--
You received this message because you are subscribed to the Google Groups
"Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To post to this group, send email to [email protected].
To view this discussion on the web visit
https://groups.google.com/d/msgid/django-updates/052.a1ae44e2aa3b0ef9e73fb2c5e4020b43%40djangoproject.com.
For more options, visit https://groups.google.com/d/optout.