← Back to Django Course | Chapter 14: REST API with DRF | Lesson 6 of 6

DRF Authentication की मूल बातें

DRF authentication जांचता है कि request कौन कर रहा है, ताकि private data सिर्फ किसी को भी न दे दिया जाए।
Syntax
markup
from rest_framework.permissions import IsAuthenticated
from rest_framework.views import APIView

class ViewName(APIView):
    permission_classes = [IsAuthenticated]

    def get(self, request):
        return Response(data)

Authentication बनाम Permissions

Authentication जवाब देता है 'यह कौन है?' (जैसे एक session cookie या token जांचना)। Permissions जवाब देते हैं 'यह user क्या कर सकता है?' (जैसे सिर्फ authenticated users एक book create कर सकते हैं)। DRF इन दोनों को अलग रखता है ताकि इन्हें mix और match किया जा सके।

उदाहरण: Authentication vs Permissions

Authentication answers 'who is this?' (e.g. checking a session cookie or token). Permissions answer 'what can this user do?' (e.g. only authenticated users may create a book). DRF separates the two so they can be mixed and matched.

markup
# Authentication: identifies the user (or None for anonymous)
# Permissions: decides whether that user may perform this action
#
# request.user  -> set by authentication
# IsAuthenticated, AllowAny, IsAdminUser -> examples of permissions
{# Django-only code -- models.py/views.py/urls.py/settings.py snippets, or template markup using Django template tags/variables -- can't run standalone via Judge0 or the browser preview, since it needs a real Django project. Only this course's pure-Python examples (example_lang == 'python', no Django imports) are actually runnable, so those still get the button below. #}

एक View पर Authentication Require करना

एक APIView पर permission_classes access restrict करता है; IsAuthenticated किसी भी request को reject करता है जो logged in नहीं है, एक 401/403 response के साथ।

उदाहरण: Requiring Authentication on a View

permission_classes on an APIView restricts access; IsAuthenticated rejects any request that isn't logged in with a 401/403 response.

markup
from rest_framework.views import APIView
from rest_framework.permissions import IsAuthenticated
from rest_framework.response import Response

class BookListView(APIView):
    permission_classes = [IsAuthenticated]

    def get(self, request):
        return Response({'message': f'Hello {request.user.username}'})
{# Django-only code -- models.py/views.py/urls.py/settings.py snippets, or template markup using Django template tags/variables -- can't run standalone via Judge0 or the browser preview, since it needs a real Django project. Only this course's pure-Python examples (example_lang == 'python', no Django imports) are actually runnable, so those still get the button below. #}

Project-Wide Defaults

हर view पर permission_classes repeat करने के बजाय, settings.py में एक बार defaults set करें ताकि सारे API views authentication require करें जब तक कोई view explicitly इसे override न करे।

उदाहरण: Project-Wide Defaults

Instead of repeating permission_classes on every view, set defaults once in settings.py so all API views require authentication unless a view explicitly overrides it.

markup
REST_FRAMEWORK = {
    'DEFAULT_AUTHENTICATION_CLASSES': [
        'rest_framework.authentication.SessionAuthentication',
    ],
    'DEFAULT_PERMISSION_CLASSES': [
        'rest_framework.permissions.IsAuthenticated',
    ],
}
{# Django-only code -- models.py/views.py/urls.py/settings.py snippets, or template markup using Django template tags/variables -- can't run standalone via Judge0 or the browser preview, since it needs a real Django project. Only this course's pure-Python examples (example_lang == 'python', no Django imports) are actually runnable, so those still get the button below. #}
Related Topics
{# common_mistakes/chapter_summary/browser_support: on Hindi pages the view already swaps in the hi_ translation fields (or blanks these out if untranslated), so this renders correctly for both languages without a lang_code check here. #}
आम गलतियां
  1. किसी authentication class को configure किए बिना IsAuthenticated जैसी एक permission class enable करना, इसलिए हर request reject हो जाती है क्योंकि DRF के पास user identify करने का कोई तरीका नहीं।
  2. यह मान लेना कि Django का session login अपने आप API endpoints protect करता है, जब DRF views को अपने खुद के authentication_classes/permission_classes configure करने होते हैं।
  3. हर view में permissions hardcode करना settings.py में sensible project-wide defaults set करने के बजाय, जो endpoints के बीच inconsistent access rules की ओर ले जाता है।
चैप्टर सारांश
  • Authentication identify करता है कि request कौन कर रहा है; permissions decide करती हैं कि वह identified user क्या करने की अनुमति रखता है।
  • DRF कई authentication schemes support करता है, SessionAuthentication (Django के login को reuse करता है) और TokenAuthentication (API tokens) सहित।
  • settings.py में DEFAULT_AUTHENTICATION_CLASSES और DEFAULT_PERMISSION_CLASSES हर API view के लिए project-wide defaults set करते हैं।
🔒

Chapter Quiz — Complete all 6 topics to unlock

0/6 topics done

Complete these topics first:

Login to run this code

C/C++/Java/PHP execution requires a free account. Your code is saved — you'll land right back in the editor after logging in.