Skip to content

Commit

Permalink
Store privacy policy acceptance records (#4095)
Browse files Browse the repository at this point in the history
  • Loading branch information
marcoacierno authored Oct 1, 2024
1 parent 962062e commit b5d5d5e
Show file tree
Hide file tree
Showing 11 changed files with 95 additions and 0 deletions.
3 changes: 3 additions & 0 deletions backend/api/orders/mutations.py
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,7 @@
from urllib.parse import urljoin

from api.context import Info
from privacy_policy.record import record_privacy_policy_acceptance
from pretix import CreateOrderErrors
import strawberry
from django.conf import settings
Expand Down Expand Up @@ -60,6 +61,8 @@ def create_order(
except PretixError as e:
return CreateOrderErrors.with_error("non_field_errors", str(e))

record_privacy_policy_acceptance(info.context.request, "checkout-order")

return_url = urljoin(
settings.FRONTEND_URL,
f"/{input.locale}/orders/{pretix_order.code}/confirmation",
Expand Down
5 changes: 5 additions & 0 deletions backend/api/tests/schema/test_create_order.py
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
from privacy_policy.models import PrivacyPolicyAcceptanceRecord
from billing.tests.factories import BillingAddressFactory
from billing.models import BillingAddress
from conferences.tests.factories import ConferenceFactory
Expand Down Expand Up @@ -158,6 +159,10 @@ def test_calls_create_order(graphql_client, user, mocker):
assert billing_address.vat_id == ""
assert billing_address.fiscal_code == "GNLNCH22T27L523A"

assert PrivacyPolicyAcceptanceRecord.objects.filter(
user=user, privacy_policy="checkout-order"
).exists()


@override_settings(FRONTEND_URL="http://test.it")
def test_handles_payment_url_set_to_none(graphql_client, user, mocker):
Expand Down
Empty file.
6 changes: 6 additions & 0 deletions backend/privacy_policy/apps.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
from django.apps import AppConfig


class PrivacyPolicyConfig(AppConfig):
default_auto_field = "django.db.models.BigAutoField"
name = "privacy_policy"
28 changes: 28 additions & 0 deletions backend/privacy_policy/migrations/0001_initial.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
# Generated by Django 5.1.1 on 2024-09-30 23:48

import django.db.models.deletion
from django.conf import settings
from django.db import migrations, models


class Migration(migrations.Migration):

initial = True

dependencies = [
migrations.swappable_dependency(settings.AUTH_USER_MODEL),
]

operations = [
migrations.CreateModel(
name='PrivacyPolicyAcceptanceRecord',
fields=[
('id', models.BigAutoField(auto_created=True, primary_key=True, serialize=False, verbose_name='ID')),
('accepted_at', models.DateTimeField(auto_now_add=True)),
('ip_address', models.GenericIPAddressField()),
('user_agent', models.TextField()),
('privacy_policy', models.CharField(max_length=1024)),
('user', models.ForeignKey(on_delete=django.db.models.deletion.PROTECT, to=settings.AUTH_USER_MODEL)),
],
),
]
Empty file.
9 changes: 9 additions & 0 deletions backend/privacy_policy/models.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
from django.db import models


class PrivacyPolicyAcceptanceRecord(models.Model):
user = models.ForeignKey("users.User", on_delete=models.PROTECT)
accepted_at = models.DateTimeField(auto_now_add=True)
ip_address = models.GenericIPAddressField()
user_agent = models.TextField()
privacy_policy = models.CharField(max_length=1024)
18 changes: 18 additions & 0 deletions backend/privacy_policy/record.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
from django.http.request import HttpRequest
from api.utils import get_ip
from privacy_policy.models import PrivacyPolicyAcceptanceRecord


def record_privacy_policy_acceptance(
request: HttpRequest, privacy_policy: str
) -> PrivacyPolicyAcceptanceRecord:
user = request.user
ip = get_ip(request)
user_agent = request.headers.get("User-Agent", "")

return PrivacyPolicyAcceptanceRecord.objects.create(
user=user,
ip_address=ip,
user_agent=user_agent,
privacy_policy=privacy_policy,
)
Empty file.
25 changes: 25 additions & 0 deletions backend/privacy_policy/tests/test_record.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
import time_machine
from django.utils import timezone

from privacy_policy.record import record_privacy_policy_acceptance
from users.tests.factories import UserFactory


def test_record_privacy_policy_acceptance(rf):
request = rf.get("/")
request.user = UserFactory(username="testuser", password="testpassword")
request.headers = {
"User-Agent": "Test User Agent",
"x-forwarded-for": "192.168.0.1",
}

accepted_at = timezone.now()

with time_machine.travel(accepted_at, tick=False):
record = record_privacy_policy_acceptance(request, "test-privacy-policy")

assert record.user_id == request.user.id
assert record.accepted_at == accepted_at
assert record.ip_address == "192.168.0.1"
assert record.user_agent == "Test User Agent"
assert record.privacy_policy == "test-privacy-policy"
1 change: 1 addition & 0 deletions backend/pycon/settings/base.py
Original file line number Diff line number Diff line change
Expand Up @@ -128,6 +128,7 @@
"video_uploads.apps.VideoUploadsConfig",
"organizers.apps.OrganizersConfig",
"billing.apps.BillingConfig",
"privacy_policy.apps.PrivacyPolicyConfig",
]

MIDDLEWARE = [
Expand Down

0 comments on commit b5d5d5e

Please sign in to comment.