Legal
Read-only REST surface for policy documents.
PolicyDocument is a global, non-tenant-scoped model (privacy policy, terms of use, SMS-messaging consent). This viewset intentionally does not build on the *VintaScheduleModelViewSet family: those bases mix in TenantScopedViewMixin (irrelevant — no organization here) and GenericVirtualModelViewMixin (requires a VirtualModelSerializer with a virtual_model, which this flat, no-N+1 serializer doesn't need). A plain DRF ReadOnlyModelViewSet mirrors the existing precedent in organizations.views.ServiceAccountViewSet for this shape.
Auth split:
- latest / latest_by_type are public (AllowAny) — the frontend must be able to render policy text before a session exists (mid-signup, pre-OAuth-completion).
- list (full history) / retrieve (by id) require authentication — these expose the full version history rather than just the currently-relevant text, so they stay behind the default auth gate.
No write surface is exposed anywhere on this viewset.
get/policy-documents/{id}/
Request
- The document declares no server URL.
- Auth: one of:
- HTTP bearer
- API key in cookie sessionid
Path parameters
idstring required
Response
Changes
- ○
endpoint added
- ○