You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Wagtail权限配置:允许创建发布LabPage,禁用编辑删除及发布后只读

实现LabPage的"创建发布后只读"权限配置(Wagtail)

Absolutely! You can pull this off with Wagtail's core permission system plus a couple of targeted custom hooks. Let's walk through exactly how to set this up, building on the permission registration code you already have:

1. Core Permission Group Setup

First, configure your user group's base permissions in the Wagtail admin:

  • Grant the add_labpage permission (lets users create new LabPage instances)
  • Grant the publish_labpage permission (lets users publish their own LabPages)
  • Do NOT grant the change_labpage permission (blocks general editing access)

Wait, you might be thinking: "How can users edit their draft before publishing if they don't have change permissions?" That's where a custom hook comes in to handle the draft vs published distinction.

2. Add a Hook to Block Editing of Published LabPages

We'll use Wagtail's before_edit_page hook to intercept edit requests for already-published LabPages. Add this to your wagtail_hooks.py:

from wagtail.core import hooks
from wagtail.core.models import UserGroup
from django.http import HttpResponseForbidden
from myapp.models import LabPage  # Replace with your actual model import

@hooks.register('before_edit_page')
def restrict_edited_published_labpages(request, page):
    # Check if we're dealing with a LabPage that's live (published)
    if isinstance(page.specific, LabPage) and page.live:
        # Fetch your target user group (replace 'Lab Content Contributors' with your group name)
        target_group = UserGroup.objects.get(name='Lab Content Contributors')
        # If the user is in this group and lacks full edit permissions
        if target_group in request.user.groups.all() and not request.user.has_perm('myapp.change_labpage'):
            return HttpResponseForbidden("Published LabPages are read-only. You cannot edit them.")

This hook lets users edit their draft LabPages (since the page isn't live yet) but blocks access as soon as the page is published.

3. Refine Your Permission Registration

Tweak your existing register_permissions hook to only show the relevant permissions in the group admin, avoiding accidental assignment of edit rights:

@hooks.register('register_permissions')
def register_labpage_permissions():
    from django.contrib.contenttypes.models import ContentType
    from myapp.models import LabPage
    from django.contrib.auth.models import Permission

    content_type = ContentType.objects.get_for_model(LabPage)
    # Return only add and publish permissions, exclude change/delete if needed
    return Permission.objects.filter(content_type=content_type).filter(
        codename__in=['add_labpage', 'publish_labpage']
    )

4. Verify the Workflow

Let's confirm the end-to-end behavior:

  • Users in the group can create a new LabPage, edit the draft freely
  • They can publish the page once it's ready
  • After publishing, the edit button disappears from the page list, and any direct attempt to edit the page is blocked with a forbidden message
  • Admins or users with change_labpage permissions can still edit published pages if needed

If you also want to block deletion of published LabPages, you can add a similar before_delete_page hook following the same pattern.

内容的提问来源于stack exchange,提问作者jcuot

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 11:12:24