Skip to content
Projects
Groups
Snippets
Help
This project
Loading...
Sign in / Register
Toggle navigation
D
django-rest-framework
Overview
Overview
Details
Activity
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Charts
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
edx
django-rest-framework
Commits
c8773671
Commit
c8773671
authored
Aug 25, 2017
by
Denis Untevskiy
Committed by
Ryan P Kilby
Aug 30, 2017
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
+ Rejecting anonymous in DjangoModelPermissions *before* the .get_queryset call
parent
2ea368e8
Hide whitespace changes
Inline
Side-by-side
Showing
1 changed file
with
5 additions
and
5 deletions
+5
-5
rest_framework/permissions.py
+5
-5
No files found.
rest_framework/permissions.py
View file @
c8773671
...
...
@@ -120,6 +120,10 @@ class DjangoModelPermissions(BasePermission):
if
getattr
(
view
,
'_ignore_model_permissions'
,
False
):
return
True
if
not
request
.
user
or
(
not
is_authenticated
(
request
.
user
)
and
self
.
authenticated_users_only
):
return
False
if
hasattr
(
view
,
'get_queryset'
):
queryset
=
view
.
get_queryset
()
assert
queryset
is
not
None
,
(
...
...
@@ -135,11 +139,7 @@ class DjangoModelPermissions(BasePermission):
perms
=
self
.
get_required_permissions
(
request
.
method
,
queryset
.
model
)
return
(
request
.
user
and
(
is_authenticated
(
request
.
user
)
or
not
self
.
authenticated_users_only
)
and
request
.
user
.
has_perms
(
perms
)
)
return
request
.
user
.
has_perms
(
perms
)
class
DjangoModelPermissionsOrAnonReadOnly
(
DjangoModelPermissions
):
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment