From 5b70c5aecb67fc8959b961985e86a81fc1c9eb72 Mon Sep 17 00:00:00 2001 From: Manuel Raynaud Date: Tue, 2 Jun 2026 14:43:19 +0200 Subject: [PATCH] =?UTF-8?q?=F0=9F=94=A7(backend)=20new=20setting=20DOCUMEN?= =?UTF-8?q?T=5FALL=5FENDPOINT=5FENABLED?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit We want to allow or not the usage of the /documents/all/ endpoint. It has been created to be used for an other purpose than the js client. For those who don't use it this new settings allow to disable it. By default it is set to True to keep the same behavior. --- CHANGELOG.md | 1 + docs/env.md | 1 + src/backend/core/api/viewsets.py | 4 ++++ .../tests/documents/test_api_documents_all.py | 15 +++++++++++++++ src/backend/impress/settings.py | 7 +++++++ 5 files changed, 28 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 479013943..b1039541b 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -16,6 +16,7 @@ and this project adheres to - ✨(backend) allow to leave a document #2365 - ✨(frontend) add the presenter mode - 📈(backend) create a utils to capture event with posthog +- 🔧(backend) new setting DOCUMENT_ALL_ENDPOINT_ENABLED ### Changed diff --git a/docs/env.md b/docs/env.md index 4e9e71fc5..af1a99568 100644 --- a/docs/env.md +++ b/docs/env.md @@ -76,6 +76,7 @@ These are the environment variables you can set for the `impress-backend` contai | DJANGO_SERVER_TO_SERVER_API_TOKENS | | [] | | DOCSPEC_API_URL | URL to endpoint of DocSpec conversion API | | | DOCUMENT_IMAGE_MAX_SIZE | Maximum size of document in bytes | 10485760 | +| DOCUMENT_ALL_ENDPOINT_ENABLED | Enable or not the endpoint /api/v1.0/documents/all/ | true | | FRONTEND_CSS_URL | To add a external css file to the app | | | FRONTEND_JS_URL | To add a external js file to the app | | | FRONTEND_HOMEPAGE_FEATURE_ENABLED | Frontend feature flag to display the homepage | false | diff --git a/src/backend/core/api/viewsets.py b/src/backend/core/api/viewsets.py index d62181ae2..6ccf95865 100644 --- a/src/backend/core/api/viewsets.py +++ b/src/backend/core/api/viewsets.py @@ -1186,6 +1186,10 @@ class DocumentViewSet( Unlike the list endpoint which only returns top-level documents, this endpoint returns all documents including children, grandchildren, etc. """ + + if not settings.DOCUMENT_ALL_ENDPOINT_ENABLED: + raise Http404() + user = self.request.user accessible_documents = self.get_queryset() diff --git a/src/backend/core/tests/documents/test_api_documents_all.py b/src/backend/core/tests/documents/test_api_documents_all.py index 051872b84..47adea090 100644 --- a/src/backend/core/tests/documents/test_api_documents_all.py +++ b/src/backend/core/tests/documents/test_api_documents_all.py @@ -425,3 +425,18 @@ def test_api_documents_all_comparison_with_list(): assert len(all_results) == 3 all_ids = {result["id"] for result in all_results} assert all_ids == {str(parent.id), str(child.id), str(grandchild.id)} + + +def test_api_documents_all_settings_diabled(settings): + """ + Test when DOCUMENT_ALL_ENDPOINT_ENABLED is set to False, /all/ endpoint should return a 404 + """ + + settings.DOCUMENT_ALL_ENDPOINT_ENABLED = False + + user = factories.UserFactory() + client = APIClient() + client.force_login(user) + + response = client.get("/api/v1.0/documents/all/") + assert response.status_code == 404 diff --git a/src/backend/impress/settings.py b/src/backend/impress/settings.py index b935ec138..991dfae06 100755 --- a/src/backend/impress/settings.py +++ b/src/backend/impress/settings.py @@ -273,6 +273,13 @@ class Base(Configuration): # Document versions DOCUMENT_VERSIONS_PAGE_SIZE = 50 + # Document /all endpoint + DOCUMENT_ALL_ENDPOINT_ENABLED = values.BooleanValue( + default=True, + environ_name="DOCUMENT_ALL_ENDPOINT_ENABLED", + environ_prefix=None, + ) + # Internationalization # https://docs.djangoproject.com/en/3.1/topics/i18n/