(20250123) Listing permitted from disabled accounts, new activity not allowed.

This commit is contained in:
2025-01-23 12:54:52 +05:30
parent fe48b79c09
commit 44ff7719f3
14 changed files with 66 additions and 54 deletions
+5 -6
View File
@@ -157,10 +157,7 @@ async def list_sms_messages(
# If the session token is invalid/expired:
if kwargs.get("session_info") is None:
return ResponseModel(
status_code = StatusCodes.FAILED,
http_code = HttpCodes.UNAUTHORIZED
)
return constants.API_RESPONSE_UNAUTHORIZED
# ┏┓ ┓ • ┏┓┓ ┓
# ┃┃┓┏┏┏┓┏┓┏┓┏┣┓┓┏┓ ┃ ┣┓┏┓┏┃┏
@@ -171,13 +168,15 @@ async def list_sms_messages(
auth_tokens = await current_app.sms_controller.get_tokens_from_keys(
mongo_data_conn = current_app.data_mongo,
token_keys = inbound_data.tokenKeys,
limit = len(inbound_data.tokenKeys)
limit = len(inbound_data.tokenKeys),
must_be_active = False
)
if not auth_tokens: return constants.API_RESPONSE_NO_AUTH_TOKEN
token_ids = [ObjectId(t.authTokenId) for t in auth_tokens]
# Check if these tokens belong to the user claiming ownership:
if not await token_check.is_authorized(
mongo_conn = current_app.data_mongo,
mongo_data_conn = current_app.data_mongo,
user_info = CoreUserInfoModel(**kwargs["session_info"]),
token_ids = token_ids
): return ResponseModel(
+3 -6
View File
@@ -222,13 +222,10 @@ async def send_sms_messages_api(
# Get the token from the token key:
auth_token = await current_app.sms_controller.get_token_from_key(
mongo_data_conn = current_app.data_mongo,
token_key = inbound_data.tokenKey
)
if auth_token is None: return ResponseModel(
status_code = StatusCodes.FAILED,
http_code = HttpCodes.UNAUTHORIZED,
message = f"No such token key."
token_key = inbound_data.tokenKey,
must_be_active = True
)
if not auth_token: return constants.API_RESPONSE_NO_AUTH_TOKEN
# ┏┓ ┓ ┏┳┓┓ ┏┓┳┳┓┏┓
# ┗┓┏┓┏┓┏┫ ┃ ┣┓┏┓ ┗┓┃┃┃┗┓