view gpp/forums/views/attachments.py @ 575:acfa5162d72f

For Django 1.4, add clickjacking protection via new middleware.
author Brian Neal <bgneal@gmail.com>
date Sat, 05 May 2012 14:06:16 -0500
parents 72fd300685d5
children
line wrap: on
line source
"""
This module contains views for working with post attachments.
"""
from django.http import HttpResponse
from django.http import HttpResponseForbidden
from django.http import HttpResponseBadRequest
from django.http import HttpResponseNotFound
import django.utils.simplejson as json

from forums.models import Post


def fetch_attachments(request):
    """
    This view is the target of an AJAX GET request to retrieve the
    attachment embed data for a given forum post.

    """
    if not request.user.is_authenticated():
        return HttpResponseForbidden('Please login or register.')

    post_id = request.GET.get('pid')
    if post_id is None:
        return HttpResponseBadRequest('Missing post ID.')

    try:
        post = Post.objects.get(pk=post_id)
    except Post.DoesNotExist:
        return HttpResponseNotFound("That post doesn't exist.")

    embeds = post.attachments.all().select_related('embed')
    data = [{'id': embed.id, 'html': embed.html} for embed in embeds]

    return HttpResponse(json.dumps(data), content_type='application/json')