🔧(backend) new setting DOCUMENT_ALL_ENDPOINT_ENABLED

We want to allow or not the usage of the /documents/all/ endpoint. It has
been created to be used for an other purpose than the js client. For
those who don't use it this new settings allow to disable it. By default
it is set to True to keep the same behavior.
This commit is contained in:
Manuel Raynaud
2026-06-02 17:28:04 +02:00
parent b946080881
commit 5b70c5aecb
5 changed files with 28 additions and 0 deletions
+1
View File
@@ -16,6 +16,7 @@ and this project adheres to
- ✨(backend) allow to leave a document #2365
- ✨(frontend) add the presenter mode
- 📈(backend) create a utils to capture event with posthog
- 🔧(backend) new setting DOCUMENT_ALL_ENDPOINT_ENABLED
### Changed
+1
View File
@@ -76,6 +76,7 @@ These are the environment variables you can set for the `impress-backend` contai
| DJANGO_SERVER_TO_SERVER_API_TOKENS | | [] |
| DOCSPEC_API_URL | URL to endpoint of DocSpec conversion API | |
| DOCUMENT_IMAGE_MAX_SIZE | Maximum size of document in bytes | 10485760 |
| DOCUMENT_ALL_ENDPOINT_ENABLED | Enable or not the endpoint /api/v1.0/documents/all/ | true |
| FRONTEND_CSS_URL | To add a external css file to the app | |
| FRONTEND_JS_URL | To add a external js file to the app | |
| FRONTEND_HOMEPAGE_FEATURE_ENABLED | Frontend feature flag to display the homepage | false |
+4
View File
@@ -1186,6 +1186,10 @@ class DocumentViewSet(
Unlike the list endpoint which only returns top-level documents, this endpoint
returns all documents including children, grandchildren, etc.
"""
if not settings.DOCUMENT_ALL_ENDPOINT_ENABLED:
raise Http404()
user = self.request.user
accessible_documents = self.get_queryset()
@@ -425,3 +425,18 @@ def test_api_documents_all_comparison_with_list():
assert len(all_results) == 3
all_ids = {result["id"] for result in all_results}
assert all_ids == {str(parent.id), str(child.id), str(grandchild.id)}
def test_api_documents_all_settings_diabled(settings):
"""
Test when DOCUMENT_ALL_ENDPOINT_ENABLED is set to False, /all/ endpoint should return a 404
"""
settings.DOCUMENT_ALL_ENDPOINT_ENABLED = False
user = factories.UserFactory()
client = APIClient()
client.force_login(user)
response = client.get("/api/v1.0/documents/all/")
assert response.status_code == 404
+7
View File
@@ -273,6 +273,13 @@ class Base(Configuration):
# Document versions
DOCUMENT_VERSIONS_PAGE_SIZE = 50
# Document /all endpoint
DOCUMENT_ALL_ENDPOINT_ENABLED = values.BooleanValue(
default=True,
environ_name="DOCUMENT_ALL_ENDPOINT_ENABLED",
environ_prefix=None,
)
# Internationalization
# https://docs.djangoproject.com/en/3.1/topics/i18n/