diff --git a/CHANGELOG.md b/CHANGELOG.md index 479013943..b1039541b 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -16,6 +16,7 @@ and this project adheres to - ✨(backend) allow to leave a document #2365 - ✨(frontend) add the presenter mode - 📈(backend) create a utils to capture event with posthog +- 🔧(backend) new setting DOCUMENT_ALL_ENDPOINT_ENABLED ### Changed diff --git a/docs/env.md b/docs/env.md index 4e9e71fc5..af1a99568 100644 --- a/docs/env.md +++ b/docs/env.md @@ -76,6 +76,7 @@ These are the environment variables you can set for the `impress-backend` contai | DJANGO_SERVER_TO_SERVER_API_TOKENS | | [] | | DOCSPEC_API_URL | URL to endpoint of DocSpec conversion API | | | DOCUMENT_IMAGE_MAX_SIZE | Maximum size of document in bytes | 10485760 | +| DOCUMENT_ALL_ENDPOINT_ENABLED | Enable or not the endpoint /api/v1.0/documents/all/ | true | | FRONTEND_CSS_URL | To add a external css file to the app | | | FRONTEND_JS_URL | To add a external js file to the app | | | FRONTEND_HOMEPAGE_FEATURE_ENABLED | Frontend feature flag to display the homepage | false | diff --git a/src/backend/core/api/viewsets.py b/src/backend/core/api/viewsets.py index d62181ae2..6ccf95865 100644 --- a/src/backend/core/api/viewsets.py +++ b/src/backend/core/api/viewsets.py @@ -1186,6 +1186,10 @@ class DocumentViewSet( Unlike the list endpoint which only returns top-level documents, this endpoint returns all documents including children, grandchildren, etc. """ + + if not settings.DOCUMENT_ALL_ENDPOINT_ENABLED: + raise Http404() + user = self.request.user accessible_documents = self.get_queryset() diff --git a/src/backend/core/tests/documents/test_api_documents_all.py b/src/backend/core/tests/documents/test_api_documents_all.py index 051872b84..47adea090 100644 --- a/src/backend/core/tests/documents/test_api_documents_all.py +++ b/src/backend/core/tests/documents/test_api_documents_all.py @@ -425,3 +425,18 @@ def test_api_documents_all_comparison_with_list(): assert len(all_results) == 3 all_ids = {result["id"] for result in all_results} assert all_ids == {str(parent.id), str(child.id), str(grandchild.id)} + + +def test_api_documents_all_settings_diabled(settings): + """ + Test when DOCUMENT_ALL_ENDPOINT_ENABLED is set to False, /all/ endpoint should return a 404 + """ + + settings.DOCUMENT_ALL_ENDPOINT_ENABLED = False + + user = factories.UserFactory() + client = APIClient() + client.force_login(user) + + response = client.get("/api/v1.0/documents/all/") + assert response.status_code == 404 diff --git a/src/backend/impress/settings.py b/src/backend/impress/settings.py index b935ec138..991dfae06 100755 --- a/src/backend/impress/settings.py +++ b/src/backend/impress/settings.py @@ -273,6 +273,13 @@ class Base(Configuration): # Document versions DOCUMENT_VERSIONS_PAGE_SIZE = 50 + # Document /all endpoint + DOCUMENT_ALL_ENDPOINT_ENABLED = values.BooleanValue( + default=True, + environ_name="DOCUMENT_ALL_ENDPOINT_ENABLED", + environ_prefix=None, + ) + # Internationalization # https://docs.djangoproject.com/en/3.1/topics/i18n/