Django REST Framework
API Permissions
IsAuthenticated and custom permissions
API Permissions
from rest_framework.permissions import BasePermission
class IsProjectOwner(BasePermission):
def has_object_permission(self, request, view, obj):
return obj.project.owner == request.user
class TaskViewSet(viewsets.ModelViewSet):
permission_classes = [IsAuthenticated, IsProjectOwner]