* Use a relationship spanning lookup to get the list of a player's influences, inste...
[matthijs/projects/xerxes.git] / influences / views.py
index ba8e280aaa0a2bf177fe4af2e062d17e65f98d5a..cd8d4a942d61a30c3e0bd2aab72496bc56acd7bf 100644 (file)
@@ -62,8 +62,9 @@ def addCharacter(request):
 
 @login_required
 def index(request):
+    # Only show this player's characters and influences
     characters = request.user.character_set.all()
-    influences = Influence.objects.filter(character__in=characters)
+    influences = Influence.objects.filter(character__player=request.user)
     return render_to_response('influences/index.html', {'characters' : characters, 'influences' : influences}, RequestContext(request))
 
 @login_required
@@ -74,11 +75,20 @@ def character_list(request):
 @login_required
 def character_detail(request, object_id):
     o = Character.objects.get(pk=object_id)
+    if (o.player != request.user):
+        return HttpResponseForbidden("Forbidden -- Trying to view somebody else's character")
     return render_to_response('influences/character_detail.html', {'object' : o}, RequestContext(request))
 
+@login_required
+def influence_list(request):
+    os = Influence.objects.filter(character__player=request.user)
+    return render_to_response('influences/influence_list.html', {'object_list' : os}, RequestContext(request))
+
 @login_required
 def influence_detail(request, object_id):
     o = Influence.objects.get(pk=object_id)
+    if (o.character.player != request.user):
+        return HttpResponseForbidden("Forbidden -- Trying to view influences of somebody else's character")
     return render_to_response('influences/influence_detail.html', {'object' : o}, RequestContext(request))
 
 # vim: set sts=4 sw=4 expandtab: