♻️(backend) rework permission to better align with DRF responsibilities

If a viewset action is not implemented, the permission layer no longer returns
a 403. Instead, it lets DRF handle the request and return the appropriate 405
Method Not Allowed response, ensuring cleaner and more standard API error
handling.
This commit is contained in:
lebaudantoine
2026-02-09 00:22:30 +01:00
committed by aleb_the_flash
parent 5d6ad3f3f6
commit 3887255e9c
2 changed files with 7 additions and 8 deletions
@@ -611,15 +611,15 @@ def test_api_rooms_unknown_actions(settings):
client.credentials(HTTP_AUTHORIZATION=f"Bearer {token}")
response = client.delete(f"/external-api/v1.0/rooms/{room.id}/")
assert response.status_code == 403
assert "insufficient permissions. unknown action." in str(response.data).lower()
assert response.status_code == 405
assert 'method "delete" not allowed.' in str(response.data).lower()
client = APIClient()
client.credentials(HTTP_AUTHORIZATION=f"Bearer {token}")
response = client.patch(f"/external-api/v1.0/rooms/{room.id}/")
assert response.status_code == 403
assert "insufficient permissions. unknown action." in str(response.data).lower()
assert response.status_code == 405
assert 'method "patch" not allowed.' in str(response.data).lower()
def test_api_rooms_response_no_url(settings):