Authorization in Django

This video features Hiroki Kiyohara at DjangoCongress JP 2019 in Tokyo, Japan.

Authorization in Django
0:45:29
Published June 9, 2019
150 views

#django #python #programming

Speaker: Hiroki Kiyohara

Do you use Django's permission feature? Or How do you handle permissions in Django?
If you write view functions containing lots of "if" sequence, it will be mess.
On this talk, I'll talk about nicer way of handling permissions / implementing Authorization in Django.
I'll introduce django-keeper which is a django library for providing authorization.
So, this talk will be practical!

Summary

Authentication establishes who a requester is, while authorization determines what that requester may do with a particular object or resource. Hiroki Kiyohara compares authorization implemented directly in views, custom decorators, and Django’s built-in permissions, explaining that each can become difficult to maintain when plans, subscriptions, teams, roles, and object state interact. He presents Django Keeper, his declarative authorization library, which defines access rules in an ACL method and applies them through decorators, templates, operators, and configurable failure responses without changing view code when policies change. Django Keeper is intended for complex projects rather than small applications; it does not filter querysets or cache ACL results, and the speaker recommends testing the ACL behavior with realistic data.

Key takeaways

  • Authentication identifies the user, whereas authorization checks whether that user may perform an action on a specific target.
  • Authorization logic in views is easy to start with but becomes difficult to maintain as subscriptions, plans, groups, and object states add conditions.
  • Django’s built-in permissions integrate well with the admin but are less convenient for changing, data-driven authorization policies.
  • Django Keeper stores rules declaratively in an ACL method and supports view decorators, template checks, custom operators, and alternative denial responses.
  • Django Keeper is best suited to complex applications and does not provide queryset filtering or ACL-result caching, so simpler projects may be better served by ordinary decorators or inline checks.

Summarised automatically from the transcript.

Chapters

  1. 0:00 Talk Overview An introduction to authorization in Django, the talk structure, and the Django Keeper library.
  2. 0:54 Speaker and Projects Hiroki Kiyohara introduces himself and the Python-focused services he builds.
  3. 3:11 Authentication and Authorization A comparison of identifying users through authentication and determining what they can do through authorization.
  4. 7:01 View-Level Authorization The simplest approach to authorization: checking permissions directly inside Django views.
  5. 10:09 Authorization Decorators How custom view decorators can centralize permission checks and reduce duplicated view logic.
  6. 13:11 Django Permissions Django’s built-in permission system, including its strengths and limitations for dynamic authorization rules.
  7. 15:39 Django Keeper and ACLs An introduction to Django Keeper and its ACL method for expressing object-level permissions.
  8. 21:45 Dynamic ACL Rules Using dynamic ACLs to handle states such as draft and published posts without changing view code.
  9. 26:20 Custom Authorization Operators Creating reusable operators for conditions such as subscriptions, plans, and premium access.
  10. 31:40 Advanced Django Keeper Features Target lookup, alternative denied responses, template checks, global contexts, and other integration features.
  11. 35:26 Limitations and Recommendations What Django Keeper cannot do, when it is appropriate, related libraries, production use, and the talk’s conclusion.
  12. 41:15 Questions Audience questions about testing ACLs, database access, reused objects, and Django REST framework integration.

Transcript

5,463 words · auto-generated Show

Automatically transcribed, so expect mistakes in names and technical terms.

0:08

Speaker 1: I'll talk about the authorization in Django and I introduce the difference between the authentication and all authorization and wait and the next topic is wait to have to permission for authorization in Jango. And the third topic is the library I created in the Jungle Keeper. And On this talk, uh I studied about this talk and on this talk you can learn the difference between authentication and authoritation. Data something uh two words. A in Japanese niche is uh authentication. NIMCA is authorization. And I will produce an ISO way to handle the authorization check. So the authorization is a NIMCA.

0:54

Speaker 1: NICA is a to NINSO authentication. I've got oscillation. Oscillation is a lot more simple than it means what you can do. So oscillation is a system to handle what you can do. The disco is uh origin based on this talk I talked about uh also vision and uh uh in general in Python JP 2019 but I updated for slides and all libraries and I updated all saying that today I will introduce the newer version of my book. Okay. Um so um Let me introduce myself. My name is Hiroki and please call me Hiroki KY

1:40

Speaker 1: or just KY or Hiroki Sang or at all. My name is Hiroki Kyoha and I created a fine cube. Uh PyQ is a web service to learn Python through the web. And the second one is DPM. com. This is a web service to analyze your uh English sentences and it will tell you How much later you need to read some English sentences? And so it's by B, it's some nice uh notebook application. Uh you can write some notice in one. Okay, and I also am a chair person of this event and I founded this Jump For TV in 2018.

2:26

Speaker 1: and I will share for some example complexity 2018 and in this year too. Okay, this is Python. This is a web service to learn the Python through the web. So you can write some Python code. uh through the browser and then you can run your uh terminal and you can run the um check script and uh the fight will say that your program is great or not and you can learn how to write the Python. And it includes some contents to improve your icing skills and it also has some exercises like to let's create some sales web applications and so on. And I'm creating this web services

3:11

Speaker 1: in my company named ePrab and I'm using my home library to handle authorization in general and with this uh production environment. Okay. But I have authentication and authorization. I use that this short of M is means authentication. And also C means that all authorization because it's too wrong to write all authorization is to write so I read this chosen pattern And authentication is means authentication. Authuration means a new car And authentication means that it there's some system or program to detect who you are, like a

3:57

Speaker 1: lobby. So uh when you use the Django you will um apply the authentication middleware in Django and you can take the user with it through the request of the user. uh attribute and because it's authenticated Django's uh authenticated middleware authenticated the authenticator user through the cookie inside the request and apply the request of the user in inject it and you can use it. So this is because the authenticator wheel is the Providing an authentication mechanism. Then the second topic is authorization. On this guy

4:42

Speaker 1: talk about the authorization, and authorization is assistant to what you can do. Imagine that if you go to some reception or a hotel or restaurant and some staff will recognize you. Like uh I will show some ID card or uh driver license and some reception will say ah you are the uh you are uh hero sent. So uh the staff will regularize me. uh it means an authentication and uh the section will consider distinguish what I can do like uh you reserve this sheet so you can take uh uh you can sit here or you can eat this dinner service or you can use this private food

5:29

Speaker 1: or you can go um this private farm but but you can't use this Some brow programs on this. Uh this hundred, what you can do, and what you can do is all three So, uh what is what unit? Well, in this case uh authorizing the system to distinguish the Distinguish what answer to this question can somebody doing something, do something. So for example, chang kiroki ky edit the article More like a cam, Europe , KY , average, they are true. So the first two is the user, regulated user or request.

6:15

Speaker 1: And the second to do is action, right? Before I use action like an edit or harmishing or delay or user private or building exclusive uh private protocols and so on. And this, the third one, this means uh a like a target context, like a disposhift or this book or like a um something you want to hand with a permission. Okay, and uh when we talk about the authorization, so there's some related words like a permission or like a score or like a HTTP for a bidding. If you use these kind of words like an action or a scope or

7:01

Speaker 1: a forbidden response, so it means you're handy for searching. Okay, so this is um that is the difference between authentication and authorization. Again, authentication is regular as a user And the authorization is recognized what the user can do next. Okay, so I introduced the authorization in general. So um the most primitive or most easy easiest way is to handle the permission or authorization in the views. Right? So for example, in this case the post underscore any to be function, imagine

7:46

Speaker 1: this uh this application contains some cost model, world cost model And uh this view will retrieve the protocols uh corresponding with post underscore IE And if the post. alcer is the same as the request of the user, the user can edit. The user can edit the article. But uh the user is not uh author, uh so the requested user can edit the view so that the view function will return the HTTP response part. Uh

8:38

Speaker 1: So in this way is really easy to implement. The first process is that it's easy to implement and easy to understand. Regardless of what uh they're doing. But uh this some tons like uh it's complicated, complic it will be complicated or uh it will cause some irrigation. So for example in this case it's pretty easy, uh like it it 's uh it's its thing is really easy to understand. So the previous to user is the same as the postal closer. The user will be able to edit the view. It's in simple But uh for example

9:24

Speaker 1: that so imagine that there's some three plants like a standard plant, a light plant, and some premium plant And uh user or some teams or groups to chance subscribe these kind of plans And also that these plants has a has some corresponding features, like a premium feature, premium viewing, premium articles and uh premium editing or like uh something blah blah blah. And having this kind of the subscription and permission and some features is really a hard and it will be messed. So having this kind of complex condition is

10:09

Speaker 1: In this kind of view will be really complex. And the second point is the deprecation. So if you write this type of if statement, or if you want to create some similar function you need to copy and paste this if statement. So so writing an information in the view function is really easy to write but it will cause a complicated view or a um some deportation. So the second approach is to write some own view decorator. So Django has deported its own view decorator named have

10:54

Speaker 1: not been required. It means that a tab view hospital view a can be only viewed by uh authenticated user. And the second view decorator is named the premium subscription required view It's not provided by a jungle, it's default, but uh uh imagine that I created this decorator and this premium subscript bequire decorator will check the user User request as a subscription. Subscription for premium. Premium plan. And if user will request as a premium plan , user can access it. uh post-interview. But if user can

11:40

Speaker 1: add asked the brain number, the UDP data will return the HD version for video So this decorator way is really much smarter than a hiding permission condition inside a field. And it will in a report. It's really nice nice already. So I recommend you to create new sound beauty for it as well. related is your business works for something and apply the view decorators D to each a view function But uh it can't use any temporary. So if you create some beauty bridges, uh you can't use the beauty bridges in the template. And so

12:26

Speaker 1: So sometimes uh you will want to you want to the you want to uh display some link to delete queue, but uh But the if user don't find the delay permission there, it's not all uh you you don't want to display it illegally. It's really embarrassing for that. You may want to handle the function inside the template, not just a U function. So, and imagine that some user has a pressure feature if the users have a subscribing a brand new feature. But now the standard user can use some brand new features. I mean

13:11

Speaker 1: the The specification of the web services will be changed sometimes. So if there's some specific change or like a service spec rechange, you need to get rid of all of these premium service. decorators uh from these related view functions it's a little bit hard and uh unique You may inject some bugs and so on. So especially in start of project like the IQ, the service specification will often change dramatically. And uh some way of handling permission in Django is age. It's to use Django's permission.

14:07

Speaker 1: Django has uh permission feature by the order, but I don't use that so Django's permission, Django permission so much. but I will introduce about it. So uh first thing you need to do is create some permission object permission data right in this case I created an average force permission For post model. The post model, imagine that the post model is inside a block jungle application. And I created a palm stream. and then apply the permission to some end user. So and you can use this permission by receiving A permission require beauty correct. This beauty

14:53

Speaker 1: correct is provided by JammuDem. Jamboards by default And yes on what I 'm the good way, the good thing is that it's provided by a default feature and it can be integrated with Adam so you can apply some permission to some starting users through the army, it's really nice. But there's a problem that, for example, it's dynamic data sort of you need to apply that partition to some users or some groups. So it's hard to change conditions. So for example uh user hub so it's the same as the building, but that if you change some condition that what kind of condition

15:39

Speaker 1: will be gotten by a user. You need to change all over applied hard mission in from the US users. So I created the jungle key, but this is the main topic of this talk and uh There is some some three ways to handle authorization example. The first one is to write in the if statement in the views The second one second way is to write in your beauty or items and third one is to using a Django permission by it provided by default. And I created this Django keeper library. It's really nice library to handle the authorization.

16:25

Speaker 1: in general but it's a bit complicated and it's sometimes it is too much for your tiny project. I created for my own project It's a little bit uh big project like it has that basic has a three plant and a subscription or non-subscription user or like a a customer user and a team user. or uh campaign user like uh um april april champagne for UV something like that so There's much more conditions, so it's really hard to handle permissions. So I created a jam keeper and I should have brought. So first thing you need to do

17:11

Speaker 1: uh when using a jam keeper, you need to write ACL method. It's a special method recognized by Jan Kiva. And in this case I added the ACL ACL method in the post model. And in this case it means uh it returns the sub two tuples inside of this. And First element to allow anonymous all users to view the post. So everyone can view this post. Or all of the user is the author of this post. So imagine that

17:57

Speaker 1: this post model has a also field. The all -sar field is relation field. with the Django's authentication model. And if the requested user is the therapy author, the user will edit the model. Oh, this actually is not the process is decorative thing it's just a decorative and you can apply some cheaper decorator is provided by them keeper and uh The first element of the view decorator is required permission. So like uh edit permission. The post -edit view is requiring

18:42

Speaker 1: any permission for each request. And the second and third uh keyword argument is to detect that what kind of object will be used here. the view. So in this case this post -edit view is related with some proposed. So the post -edit view will use some sub -king proposed. And uh people are thinking some way to get which broad cost is used. Like in this case there um The key part will reduce the post underscore ID is uh request the URL arguments and getting the broad

19:28

Speaker 1: post by this ID fail. So um the keeper will detect the corresponding protocol and check The request has any function to the proper. So you don't need to write any qualities inside a view function. And you can also get the This k underscore context attribute is uh will be uh injected by a key duty correction.

20:14

Speaker 1: Okay, um also you can use the template inside a template So for example uh if you want to check the request has the uh delete function to This also, this false, this false, you can write, you can use this pass function and creator. So if the request has They read a permission to the boss, the channel delete variable will be true. If the request don't have the permission to delete permission to this boss, the channel delete will be. So you can use the count the rate variable in the x statement

20:59

Speaker 1: in the distinct, and if it 's variable is true, you can display this. a lady to uh brought a lady to this Uh I thought I I mentioned that you're one of it. I'm publishing this at General Keeper Library in my GitHub account, github. com structural g by structures and general keeper. So if you are fishing or you want to see some source code for uh for the general keypad, please

21:45

Speaker 1: report the URL Okay. Um I'll I didn't mention earlier that a model for it's okay by not using a model for okay uh if you apply the HTML method to a sum class um you can uh take a relatively a apply the punishment or like that. So anyway that first role is the ACL contains

22:30

Speaker 1: some tuples. If each tuple has three elements, the first element will be the action And the second one is who, so what kind of request? And third element is the will be the permission. So in this case hello the if hello the if user is the author uh acquiring the eight function. So it just returning some risk for Hubble, but uh jump keeper So the library will recognize what list means and handle the function. So you don't need to write a process, you you just need to write some list. It's I think it's really similar to

23:17

Speaker 1: you uh UFW. Uh we go to firewall or fireball city or so. And we'll identify what I will condition is with heart. So if possible. author some some process author is a same as a request. the boss and you can also write a dynamic ACL. That ACL is not a static one, it can be uh dynamic It's a it's uh implemented by a mess of that. So in this case users can users can view the draft robost

24:02

Speaker 1: but the user's champ or among us users champ view these uh oral robots it means If the propose was a draft, uh imagine that uh the proposed model has a draft a sum. Or Berge and Field to our eyes are published out. A to time field or something Anyway, you can handle by its attribute. So the protocol was a draft one. Only the author user, author request, can view and edit and delete. So but the propose is published one. Uh all people should be able to see the propose.

24:49

Speaker 1: So if it says if it's a published one uh every anonymous user can view this protocol. And also that if the user, the request of the user is the same as that. um all the OES proposed the preference can age and drink. I think it's a really nice way though. Um having this permission like that if broad hold is draft and the request of user is uh also it can be viewed. But if it's uh draft the broad force the anonymous request can view it's proposed. You need to write some kind of this if statement inside a view function

25:34

Speaker 1: or view decorators. It's really hard and I don't like to write it. Write it. So I created the jump keeper. If you're using a jam keeper, all you need to do is just writing an ACL C it. We can notice that the if the proposed rough one, so everyone can't view and all of the Also jump view a hit the three. It's really nice I think and If you change the HL, HCL method, so you can change these conditions, so what kind of conditions you want to apply to the request. So you don't need to change, you don't need, you don't need to change this

26:20

Speaker 1: view integrated. The beauty really is just requires, just saying, just saying that require permission. So for example, well, post -edit view is required edit permission. And the post -d view is just required. And this factory uh keyword keyword argument is to retrieve their broadband So last example I wrote by model g value argument and map by gval unit, but in this case I'm using this uh Function a function. You can use it.

27:05

Speaker 1: Uh you can use most ways Okay. In ACL I say that there's an every one for its user. to detect what what kind of request has each function. So in this case every anonymous user will have will get this view function. So what is this everyone for its user classes? So this is I call this operator. This everyone for its user are called the operator. It's just a callable.

27:50

Speaker 1: Which takes a HTTP HTTP request as its argument and it will return the book boom. So it will operate that. So the end is Some default Americans like its tough one. It's authenticated or its alumni or something like that. And also you can create your own operators like a half subscription operator. So uh in this case there are if If you apply some CRM code to Hascription area, it will detect the request. users subscribing CRAM code and it will return through WOPOs. It can be used inside

28:36

Speaker 1: your ACL. So for example, in this case the proto is exclusive ones like 3D Pie exclusive expensive sum editors news or something An exclusive robust can be only theme for the request, which has a premium run. So imagine that the user has a subscription and fun and fun code is created by another application. It's not provided by a channel keeper. It's not provided featured by a channel keeper, but you can create some substitution model or plan model in your project and you can use these values with

29:23

Speaker 1: your own keypad operator and you can use it inside the ACF. So in this case um also you don't need to change the view functions. So In this case uh some subscript some requests subscribing some framework framework and the protocol was uh some exclusive one it will have the request will have that view file machine. So the handling are machine It's provided by ACM facet and a view function. So skill need you don't need to change this This few decorators you don't need to change.

30:09

Speaker 1: The hardware partition is calculated inside this operators and SEO. So JumpTip are only to handle really really complex association. So imagine that if your project has some really complex function handling, like say the subscription, Multiple clients, then some parts model user and the team user, and so on. It's really hard to have handle all of conditions that you function or decorators. But if you use a jump keeper, you can just write. ACL or your own operators and you can hunt your own function inside this

30:55

Speaker 1: ACL and the jam keeper. So it's really nice And if you change some condition for applying the function, you don't need to change the view function. You just need to change ACL method. I introduced about what Jamkeeper is and I introduced for now I introduce about the way to use the Jamkeeper. But uh way to use a JamKeeper uh to know where to use JamKeeper, you can refer the uh read to me inside my project, the GitHub or slash jam keeper so you know

31:40

Speaker 1: may you you know make need to hear this part but I should do. In Kiva Decorda you can apply, you can specify the way to get target models. like a broad code. It's the easiest way. Um it's specifying the way to get the broadcast column by using the post underscore ID. The post underscore ID is a similar Value as the the arguments, the arguments for the view function. So the post ID will be uh detected inside a U outlet like a slash post ID slash. And the keypad view

32:25

Speaker 1: decorator will get host objects by using this argument And you can change on pay direction. So if you if the request if the request don't have the permission to access to some subject infuse. So The common way is returning the File V response, 403, but something you want to return the not file So for example, uh if you access to if you access to the GitHub private repository uh results logging before logging, it will return 403, not one. So because The

33:10

Speaker 1: Eta wants to hide the existence of the private people 's eating. So it will just say no one. It won't say that for bills. If it says a part V, it means there's some private industry. Like GitHub slash BPR slash PyT slash And you can access to the VBR slash Python slash, but you will get the not found. Not found response. Instead of the plugin, because GitHub wants to hide the existence of the Py2 repository The action is A. So um point to import these kind of features, Java Keeper can get the

33:55

Speaker 1: uh own fail action. So you can import the note on action from GPS. views and applying it to the JavaGifr, you can change the behavior after the permission. is not permitted. No request is permitted. So as I mentioned, uh you can use the temporary times inside the temporary geometry provider key or temporary. And you can house publishing. And also you can use a global context. It's a little bit complicated. As I mentioned the

34:41

Speaker 1: all of Publish Hundry, then no, most of Publish Hundred inside the junkie but is related with some user and some objects. But if something you want to handle the a permission or authorization without the models like a user channel search post or like a user uh user channel you could write a new propos So the permission for writing a new protocol is not related with any kind, any something of this, right? So you can use in this case you can use a global context. You can write the global context class and you can search through the settings

35:26

Speaker 1: setting value Okay, so there's something the Jamokeeper can't do. Can't do. So Jamokeeper provides a nicer way to handle permission, but you can't filter some queries uh queries are always the buyer function like uh sometimes you want to filter the blog calls Only you can edit. So there's a library near the giant guardian. So giant guardian can handle this kind of feature but uh uh jump keeper can't have it this case. Uh JavaKeeper doesn't cache the response of the ACM method, but it will be improved.

36:12

Speaker 1: Okay, um I'll count up. I'll go you'll need to be wrong about you can come. If I like. Uh my credit asked me, should I use a junkie bar scroll now? I answer that it will be too much for small projects. So you need to write an ACL and you need to fly a keypad It's a little bit complicated. So it's most easiest, the easiest way is to write in the x stage of the inside of the function. So if you are handling and you are creating a small program, if you don't need a gem deeper. And should you have some problems

36:59

Speaker 1: about handling punishment? Yeah, it's great weight, great counts, great timing to use the genitive I think. Or um some question is that should I use that keeper for all the views. Like so for example, some views is a some views won't need to use so complex some function handling like this view. can be seen by only an authenticated user. In this case you just need to use a low-bing for a decorator. You don't need to up keep a decorator. So I think that you you shouldn't too so obsessive to use a general keeper. So if it's enough to use a like

37:45

Speaker 1: log ring require unicorner or some beauty corrector you created for hydrogen function. It's if it's enough, I think it's okay. You don't need to use uh Django G, but for all of these. Okay, um there is similar libraries like a Django's Publishing or like a Django Guardian. Django Key is a more and more nicer version of Django's Publishing. Django rule is similarly to Django, Django Chipa, my library, is similar to my library, but it's a little bit more like a process you see. I want to write down that a I will create a somewhat declarative version of it

38:30

Speaker 1: of to provide a handling moderation. Okay. So The junk keeper is ready for production environment. Yes, I think yes. Um but I can't guarantee the safety. So it's the library to have the permission so I can say it's totally safe and you can use it in production. So I can't guarantee you are really safe by using the GemKeeper. I can't guarantee guarantee. But if you um can if you can read and contribute to the Gemekeeper and uh what keeper we do you can understand what will

39:15

Speaker 1: what the keeper will do yeah you can use in production and actually I'm using the demo keeper in production environment Okay, this is some use case. So if the your project has some two kind of users, like a password users and T users And also there are some multiple plans and subscriptions. I got writing plan, a free plan , campaign plan, a premium plan, or I got an enterprising plan, or I got exclusive plan. or like uh something like that and also it either some a contents some components like a default contents or like exclusive components So if you have

40:01

Speaker 1: this kind of complex condition about the authorization, I recommend you use the Japan Keeper. Okay, so please try Jumpkeeper and Sensor Request. It's a tiny and baby project, so uh it's best of you. to uh send it up for request. The conclusion, authorization is what each request can do. And uh many ways, there's a many ways for handling authorization. So handling authentication is really simple. It's just uh using the authorization video or like you are implementing some jobs or cool authorization. authentication blah blah blah but uh there's multiple ways to handle my machine or

40:46

Speaker 1: a authorization. And then keep up will help you a complex project. It's not for IN project. It's if your project is very complex, it will be helpful. Okay, that's all for I did.

41:15

Speaker 2: Alright, so since um the authorization that you can set up is pretty complex Would it be sufficient to write tests for only the views, or would you want to test the double imp score ACL method in your model as well?

41:27

Speaker 1: Uh alright. Um So I will write some uh test for uh only the method, but I won't I won't write for the method because the method will just write a return to some public body so that I will create some actual data. Data picture and checking the harmission will be detected or not And I won't I won't write to check the all of permission to all of you because it's the same thing, so I won't write it. But I will write it I will write the sum this by using some actual data lecture featured. Yeah Oh by not

42:12

Speaker 1: the video.

42:19

Speaker 3: I was wondering when you're so in the keeper decorator you're accessing the database, right? You first removal and check the information?

42:27

Speaker 1: Yes.

42:28

Speaker 3: And is maybe I missed it. Is there a way to an inside view? to again access the model aspect.

42:35

Speaker 1: Yes, yes, yes, you can handle it. I didn't mention that the Channel Keeper provides some function to check the permission. to certain an object at some certain request. So you can retrieve some model inside of use and you can check that a request has a function to the return model you can write. Uh in the option one

43:01

Speaker 3: sure if I understood. I was wondering more like you know in the access I think he said like it can directly from the view check the permissions. Yes, it is. I was more wondering like if you use that decorator. And then you know if for example you get the post and it will check that you have to write permissions. But then maybe inside the view I want to do something else with that post right or maybe for some other service so do I have to fetch it again or I can use that from the that is fetched from the tech code

43:30

Speaker 1: Uh no no no you can't. Uh it the Jam Keeper decorator will face only one object, so you can handle for multiple objects uh for a inside uh decorator. Uh yeah, I d I I didn't provides a feature by by default. But it will be nice feature. Thank you, thank you. Hi, Diki Master. So the manka are the foundation cancer.

44:18

Speaker 1: The path of such a change of the thousands of task can.

44:47

Speaker 4: Um do you use DRS general screen over because it has interesting publishing? as well. It might be interesting to integrate details.

44:58

Speaker 1: Yes, yes, yes. Yeah, I yeah, yeah, yeah, yeah. I didn't say how about the JavaScript framework inside the disk guys like that. it has jump keeper has an integration with the Django Resprayboard and it can integrate the permission inside the Django uh res framework. It's implemented, so you need it. Hi, are you not going to be able to do this?

Questions this talk answers

What is the difference between authentication and authorization in Django?

Authentication identifies who the user is, while authorization determines what that user is allowed to do. Django’s authentication middleware identifies the user from the request, and authorization checks that user’s permitted actions on a target object.

Discussed at 3:11

What are the main ways to implement authorization in Django?

The talk covers checking permissions directly in views, using custom view decorators, and using Django’s built-in permission system. For complex authorization involving subscriptions, plans, teams, or changing conditions, the speaker presents Django Keeper as another option.

Discussed at 15:39

How do you define permissions with Django Keeper?

Add an `ACL` method to the model that returns rules describing an action, the type of requester, and the required permission. Django Keeper’s decorators then identify the target object from the URL and enforce those rules without putting the authorization logic in each view.

Discussed at 17:11

How can I check Django Keeper permissions in a template?

Django Keeper can expose a permission result in the template context, allowing a template to conditionally show or hide controls such as a delete link. The template can test whether the current request has the relevant permission for the object.

Discussed at 20:14

What can’t Django Keeper do?

Django Keeper does not filter querysets to return only objects the user can edit; the speaker points to Django Guardian for that kind of feature. It also does not cache the results of the ACL method, although caching might be added later.

Discussed at 35:26

When should I use Django Keeper instead of Django’s built-in decorators or simple checks?

Use simple checks or standard decorators for small projects and straightforward views, such as views restricted to authenticated users. Django Keeper is more appropriate when authorization has complex, changing rules involving subscriptions, multiple plans, teams, or different user types.

Discussed at 36:12

How should I test Django Keeper authorization rules?

The speaker tests the ACL method using realistic data fixtures and checks whether permission is detected correctly. He does not test every view’s permissions separately because the views use the same authorization mechanism.

Discussed at 41:27

Can Django Keeper’s decorator-fetched object be reused inside the view?

The decorator fetches one object and makes it available for the permission check, but it does not provide a built-in feature for handling multiple objects or reusing that fetched object for other purposes in the view. The speaker says that capability would be a useful feature.

Discussed at 43:30

Note: We understand that names change, people change, and bodies change. We respect each individual's journey and privacy. If you have any concerns about a video or need us to remove content, please don't hesitate to contact us. We will handle your request with care and promptly address any issues.

More videos by Hiroki Kiyohara

More videos from DjangoCongress JP