django-realworld-example-app icon indicating copy to clipboard operation
django-realworld-example-app copied to clipboard

Object level permissions not implemented

Open cliffordh opened this issue 5 years ago • 0 comments

Reviewing the code I do not see object level permissions implemented. Thus, it is possible for an authenticated user to update/delete objects in another users account. See https://www.django-rest-framework.org/tutorial/4-authentication-and-permissions/#object-level-permissions for information on implementing object level permissions using rest framework.

cliffordh avatar Dec 12 '18 17:12 cliffordh