A large batch of club-management features built up over one session: - Club dashboard banner warning admins 1 month before billing ends - Full Events/EventSeries CRUD (recurrence builder, occurrence lifecycle, per-team permissions), with match->game rename and game-specific fields (score, competition, live status, external game ID) - Django-admin competition dropdown, gated per-club by feature flag - Auto-import of RBIHF fixtures (scrape -> diff -> preview -> confirm), with location/opponent dropdowns suggested from existing club data - Feature-flag-gated Shop/Forms nav sections, reusing the same flag machinery for the RBIHF import button - Team roster now scoped to members active this season or next, sorted and grouped by position - Club sport type (ice hockey / other), shown in the control panel's club subtitle - Per-season team photo upload from the team page - New public read-only API (Django Ninja) at /api/v1/: news, team rosters, upcoming/live/per-team games, and sponsors -- auto-documented via Swagger UI, CORS-enabled for a club's own external website - Club sponsors: admin-only CRUD (logo, URL, active date window) plus a date-windowed, optionally randomized API endpoint - Assorted fixes: NullBooleanField dropdown rendering, cross-club event validation timing, searchable-select chip placement, btn-neutral -> default button style sweep, calendar-month chart windows Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01R1gj3J1QPfP38XWpnpbFpy
32 lines
1.1 KiB
Python
32 lines
1.1 KiB
Python
"""CORS for the public API only.
|
|
|
|
Every route under /api/v1/ is public, read-only, and unauthenticated -- no
|
|
cookies or credentials are ever involved, so there's no CSRF/session risk in
|
|
answering any origin. That's the whole reason this is a few lines here
|
|
instead of pulling in django-cors-headers for a handful of GET routes: the
|
|
rest of the site keeps Django's ordinary same-origin behaviour untouched.
|
|
"""
|
|
|
|
from django.http import HttpResponse
|
|
|
|
API_PATH_PREFIX = "/api/v1/"
|
|
|
|
|
|
class PublicApiCorsMiddleware:
|
|
def __init__(self, get_response):
|
|
self.get_response = get_response
|
|
|
|
def __call__(self, request):
|
|
if not request.path.startswith(API_PATH_PREFIX):
|
|
return self.get_response(request)
|
|
|
|
if request.method == "OPTIONS":
|
|
response = HttpResponse(status=204)
|
|
else:
|
|
response = self.get_response(request)
|
|
|
|
response["Access-Control-Allow-Origin"] = "*"
|
|
response["Access-Control-Allow-Methods"] = "GET, OPTIONS"
|
|
response["Access-Control-Allow-Headers"] = "Content-Type"
|
|
return response
|