diff --git a/plant_catalog/catalog/api_views.py b/plant_catalog/catalog/api_views.py index 44a9863..556ea27 100755 --- a/plant_catalog/catalog/api_views.py +++ b/plant_catalog/catalog/api_views.py @@ -3,9 +3,14 @@ from rest_framework import generics from rest_framework.parsers import MultiPartParser, FormParser, JSONParser from rest_framework.filters import SearchFilter +from rest_framework.response import Response +from rest_framework import status + +from rest_framework.views import APIView +from django.shortcuts import get_object_or_404 from .permissions import IsAuthenticatedOrReadOnly -from .models import Plant +from .models import Plant, PlantImage from .serializers import PlantSerializer # List and Create Plants @@ -22,4 +27,14 @@ class PlantRetrieveUpdateDestroyAPIView(generics.RetrieveUpdateDestroyAPIView): queryset = Plant.objects.all() serializer_class = PlantSerializer parser_classes = [JSONParser, MultiPartParser, FormParser] # Allow file uploads and form data - permission_classes = [IsAuthenticatedOrReadOnly] # Apply custom permission \ No newline at end of file + permission_classes = [IsAuthenticatedOrReadOnly] # Apply custom permission + + +class PlantImageDeleteAPIView(APIView): + permission_classes = [IsAuthenticatedOrReadOnly] # Ensure only authenticated users can delete + + def delete(self, request, image_id): + image = get_object_or_404(PlantImage, id=image_id) + image.delete() # Delete the image object from the database + return Response({"message": "Image deleted successfully"}, status=status.HTTP_204_NO_CONTENT) + diff --git a/plant_catalog/catalog/permissions.py b/plant_catalog/catalog/permissions.py old mode 100644 new mode 100755 diff --git a/plant_catalog/catalog/serializers.py b/plant_catalog/catalog/serializers.py index 47eddd7..2f4558d 100755 --- a/plant_catalog/catalog/serializers.py +++ b/plant_catalog/catalog/serializers.py @@ -8,13 +8,34 @@ class PlantImageSerializer(serializers.ModelSerializer): class PlantSerializer(serializers.ModelSerializer): - images = PlantImageSerializer(many=True, read_only=True) # Include related images + images = PlantImageSerializer(many=True, read_only=True) # Read existing images + uploaded_images = serializers.ListField(child=serializers.ImageField(), write_only=True, required=False) # Accept new images class Meta: model = Plant - fields = ['id', 'name', 'description', 'buy_price', 'sell_price', 'stock', 'images'] # Add the `images` field - extra_kwargs = { - 'buy_price': {'required': False, 'allow_null': True}, - 'sell_price': {'required': False, 'allow_null': True}, - 'description': {'required': False, 'allow_null': True}, - } + fields = ['id', 'name', 'description', 'buy_price', 'sell_price', 'stock', 'images', 'uploaded_images'] # Include uploaded_images + + def create(self, validated_data): + uploaded_images = validated_data.pop('uploaded_images', []) # Get images from request + plant = Plant.objects.create(**validated_data) + + for image in uploaded_images: + PlantImage.objects.create(plant=plant, image=image) # Save each image + + return plant + + def update(self, instance, validated_data): + uploaded_images = validated_data.pop('uploaded_images', []) + + instance.name = validated_data.get('name', instance.name) + instance.description = validated_data.get('description', instance.description) + instance.buy_price = validated_data.get('buy_price', instance.buy_price) + instance.sell_price = validated_data.get('sell_price', instance.sell_price) + instance.stock = validated_data.get('stock', instance.stock) + instance.save() + + for image in uploaded_images: + PlantImage.objects.create(plant=instance, image=image) # Save new images + + return instance + diff --git a/plant_catalog/catalog/urls.py b/plant_catalog/catalog/urls.py index 3376bb2..154dd55 100755 --- a/plant_catalog/catalog/urls.py +++ b/plant_catalog/catalog/urls.py @@ -3,7 +3,7 @@ from django.http import HttpResponseRedirect from django.urls import path from rest_framework_simplejwt.views import TokenObtainPairView, TokenRefreshView -from .api_views import PlantListCreateAPIView, PlantRetrieveUpdateDestroyAPIView +from .api_views import PlantListCreateAPIView, PlantRetrieveUpdateDestroyAPIView, PlantImageDeleteAPIView urlpatterns = [ path('', lambda request: HttpResponseRedirect('/api/plants/')), @@ -11,6 +11,7 @@ urlpatterns = [ path('api/plants//', PlantRetrieveUpdateDestroyAPIView.as_view(), name='plant_detail_update_delete'), # Retrieve, Update, Delete path('api/token/', TokenObtainPairView.as_view(), name='token_obtain_pair'), path('api/token/refresh/', TokenRefreshView.as_view(), name='token_refresh'), + path('api/plant-images//', PlantImageDeleteAPIView.as_view(), name='plant_image_delete'), ] diff --git a/plant_catalog/plant_catalog/settings.py b/plant_catalog/plant_catalog/settings.py index 6666d86..79f8ea0 100755 --- a/plant_catalog/plant_catalog/settings.py +++ b/plant_catalog/plant_catalog/settings.py @@ -26,7 +26,7 @@ SECRET_KEY = 'django-insecure-(e9sx(r=75hv%xni#rcm4)0&67c34+her^!%7dqlghem1=l0lc # SECURITY WARNING: don't run with debug turned on in production! DEBUG = False -ALLOWED_HOSTS = ['gonzalohd.eu', 'plantsapi.gonzalohd.eu', 'localhost', '192.168.1.139', '127.0.0.1'] +ALLOWED_HOSTS = ['gonzalohd.com', 'plantsapi.gonzalohd.com', 'localhost', '192.168.1.139', '127.0.0.1'] # ALLOWED_HOSTS = ['*']