Here are the different methods:
- Decorators like login_required,
permission_required, staff_required
- Mixins like UserPassesTestMixin
- has_permission function
- Checks directly in a views dispatch function
Could not the 4 items be quite easily replaced by 2?
Things like permissions to delete a model I think should use permission_required. Then each organisation can configure the permissions for each group as they see fit.
The goal is to make the permissions as easy as possible to understand and test.
What is the best way forward?
Here are the different methods:
permission_required, staff_requiredCould not the 4 items be quite easily replaced by 2?
Things like permissions to delete a model I think should use
permission_required. Then each organisation can configure the permissions for each group as they see fit.The goal is to make the permissions as easy as possible to understand and test.
What is the best way forward?