Skip to content

Commit b5d5d5e

Browse files
authored
Store privacy policy acceptance records (#4095)
1 parent 962062e commit b5d5d5e

File tree

11 files changed

+95
-0
lines changed

11 files changed

+95
-0
lines changed

backend/api/orders/mutations.py

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,7 @@
22
from urllib.parse import urljoin
33

44
from api.context import Info
5+
from privacy_policy.record import record_privacy_policy_acceptance
56
from pretix import CreateOrderErrors
67
import strawberry
78
from django.conf import settings
@@ -60,6 +61,8 @@ def create_order(
6061
except PretixError as e:
6162
return CreateOrderErrors.with_error("non_field_errors", str(e))
6263

64+
record_privacy_policy_acceptance(info.context.request, "checkout-order")
65+
6366
return_url = urljoin(
6467
settings.FRONTEND_URL,
6568
f"/{input.locale}/orders/{pretix_order.code}/confirmation",

backend/api/tests/schema/test_create_order.py

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
from privacy_policy.models import PrivacyPolicyAcceptanceRecord
12
from billing.tests.factories import BillingAddressFactory
23
from billing.models import BillingAddress
34
from conferences.tests.factories import ConferenceFactory
@@ -158,6 +159,10 @@ def test_calls_create_order(graphql_client, user, mocker):
158159
assert billing_address.vat_id == ""
159160
assert billing_address.fiscal_code == "GNLNCH22T27L523A"
160161

162+
assert PrivacyPolicyAcceptanceRecord.objects.filter(
163+
user=user, privacy_policy="checkout-order"
164+
).exists()
165+
161166

162167
@override_settings(FRONTEND_URL="http://test.it")
163168
def test_handles_payment_url_set_to_none(graphql_client, user, mocker):

backend/privacy_policy/__init__.py

Whitespace-only changes.

backend/privacy_policy/apps.py

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
from django.apps import AppConfig
2+
3+
4+
class PrivacyPolicyConfig(AppConfig):
5+
default_auto_field = "django.db.models.BigAutoField"
6+
name = "privacy_policy"
Lines changed: 28 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,28 @@
1+
# Generated by Django 5.1.1 on 2024-09-30 23:48
2+
3+
import django.db.models.deletion
4+
from django.conf import settings
5+
from django.db import migrations, models
6+
7+
8+
class Migration(migrations.Migration):
9+
10+
initial = True
11+
12+
dependencies = [
13+
migrations.swappable_dependency(settings.AUTH_USER_MODEL),
14+
]
15+
16+
operations = [
17+
migrations.CreateModel(
18+
name='PrivacyPolicyAcceptanceRecord',
19+
fields=[
20+
('id', models.BigAutoField(auto_created=True, primary_key=True, serialize=False, verbose_name='ID')),
21+
('accepted_at', models.DateTimeField(auto_now_add=True)),
22+
('ip_address', models.GenericIPAddressField()),
23+
('user_agent', models.TextField()),
24+
('privacy_policy', models.CharField(max_length=1024)),
25+
('user', models.ForeignKey(on_delete=django.db.models.deletion.PROTECT, to=settings.AUTH_USER_MODEL)),
26+
],
27+
),
28+
]

backend/privacy_policy/migrations/__init__.py

Whitespace-only changes.

backend/privacy_policy/models.py

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
from django.db import models
2+
3+
4+
class PrivacyPolicyAcceptanceRecord(models.Model):
5+
user = models.ForeignKey("users.User", on_delete=models.PROTECT)
6+
accepted_at = models.DateTimeField(auto_now_add=True)
7+
ip_address = models.GenericIPAddressField()
8+
user_agent = models.TextField()
9+
privacy_policy = models.CharField(max_length=1024)

backend/privacy_policy/record.py

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
from django.http.request import HttpRequest
2+
from api.utils import get_ip
3+
from privacy_policy.models import PrivacyPolicyAcceptanceRecord
4+
5+
6+
def record_privacy_policy_acceptance(
7+
request: HttpRequest, privacy_policy: str
8+
) -> PrivacyPolicyAcceptanceRecord:
9+
user = request.user
10+
ip = get_ip(request)
11+
user_agent = request.headers.get("User-Agent", "")
12+
13+
return PrivacyPolicyAcceptanceRecord.objects.create(
14+
user=user,
15+
ip_address=ip,
16+
user_agent=user_agent,
17+
privacy_policy=privacy_policy,
18+
)

backend/privacy_policy/tests/__init__.py

Whitespace-only changes.
Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
1+
import time_machine
2+
from django.utils import timezone
3+
4+
from privacy_policy.record import record_privacy_policy_acceptance
5+
from users.tests.factories import UserFactory
6+
7+
8+
def test_record_privacy_policy_acceptance(rf):
9+
request = rf.get("/")
10+
request.user = UserFactory(username="testuser", password="testpassword")
11+
request.headers = {
12+
"User-Agent": "Test User Agent",
13+
"x-forwarded-for": "192.168.0.1",
14+
}
15+
16+
accepted_at = timezone.now()
17+
18+
with time_machine.travel(accepted_at, tick=False):
19+
record = record_privacy_policy_acceptance(request, "test-privacy-policy")
20+
21+
assert record.user_id == request.user.id
22+
assert record.accepted_at == accepted_at
23+
assert record.ip_address == "192.168.0.1"
24+
assert record.user_agent == "Test User Agent"
25+
assert record.privacy_policy == "test-privacy-policy"

0 commit comments

Comments
 (0)