Full CRUD on PurchaseRound and WineOffering, org-scoped via two new
join-based dependencies.py helpers (get_round_in_organization,
get_wine_offering_in_organization) mirroring task 5's pattern. New
rounds always start as draft regardless of what the client posts,
avoiding a confusing creation-time constraint error.
POST /purchase-rounds/{id}/copy implements "kopiér fra forrige runde":
duplicates every round field (dates, texts) and every wine offering
(incl. category) into a fresh draft, leaving the source untouched.
PurchaseRound DELETE gets a three-tier policy based on status: draft
deletable by any admin, open never deletable, closed only by an
elevated superadmin. This is runtime-conditional on the loaded row, so
the elevation check was extracted out of get_current_active_superuser
into a standalone require_elevated_superuser(user, token) helper that
both the dependency and this handler call directly. WineOffering
delete has no such tier — an offering with real order lines is already
blocked by the existing RESTRICT FK, caught here as a 409.
Also seeds the 8 wine categories (empty table blocked any offering
creation) via a plain Alembic data migration, idempotent and
unconditional (no secret involved, unlike the task-4 superuser seed).
Verified end-to-end: dates-required 409, open round successfully
patched with dates, wine offerings created, round copied (new draft,
duplicated offerings with new ids/same category), open-round delete
403, closed-round delete 403 then 204 after /auth/elevate, wine
offering delete 204, draft round delete 204 (cascades its remaining
offering). DB left clean, participant count unaffected.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
13 lines
520 B
Python
13 lines
520 B
Python
from fastapi import APIRouter
|
|
from sqlmodel import select
|
|
|
|
from app.db import SessionDep
|
|
from app.dependencies import CurrentUser
|
|
from app.models.wine_category import WineCategory, WineCategoryPublic
|
|
|
|
router = APIRouter(prefix="/wine-categories", tags=["wine-categories"])
|
|
|
|
|
|
@router.get("", response_model=list[WineCategoryPublic])
|
|
def list_wine_categories(session: SessionDep, current_user: CurrentUser) -> list[WineCategory]:
|
|
return list(session.exec(select(WineCategory).order_by(WineCategory.sort_order)).all())
|