← Back to Django Course | Chapter 10: Authentication & Authorization | Lesson 7 of 12

permission_required नामक Decorator

permission_required एक VIP wristband check जैसा है — यह सिर्फ उन लोगों को आने देता है जिन्हें वह specific permission दी गई हो।
Syntax
markup
from django.contrib.auth.decorators import permission_required

@permission_required('app_label.permission_codename')
def view_name(request):
    ...

@permission_required('app_label.permission_codename', raise_exception=True)
def other_view(request):
    ...

एक Specific Permission चाहिए बनाना

@permission_required एक permission string लेता है 'app_label.action_modelname' के form में, जैसे 'library.add_book'।

उदाहरण: Requiring a Specific Permission

Only users (or groups) granted the 'library.add_book' permission can reach this view; others get redirected.

markup
from django.contrib.auth.decorators import permission_required
from django.shortcuts import render

@permission_required('library.add_book')
def add_book_view(request):
    return render(request, 'add_book.html')
{# Django-only code -- models.py/views.py/urls.py/settings.py snippets, or template markup using Django template tags/variables -- can't run standalone via Judge0 or the browser preview, since it needs a real Django project. Only this course's pure-Python examples (example_lang == 'python', no Django imports) are actually runnable, so those still get the button below. #}

Redirect करने के बजाय 403 Return करना

Default रूप से एक denied user LOGIN_URL पर redirect होता है। raise_exception=True set करना इसके बजाय एक HTTP 403 error page return करता है।

उदाहरण: Returning 403 Instead of Redirecting

raise_exception=True is useful when the user IS logged in but simply lacks the permission — a redirect to login would be misleading.

markup
from django.contrib.auth.decorators import permission_required

@permission_required('library.delete_book', raise_exception=True)
def delete_book_view(request):
    return delete_book(request)
{# Django-only code -- models.py/views.py/urls.py/settings.py snippets, or template markup using Django template tags/variables -- can't run standalone via Judge0 or the browser preview, since it needs a real Django project. Only this course's pure-Python examples (example_lang == 'python', no Django imports) are actually runnable, so those still get the button below. #}

Templates में Permissions जांचना

Templates request.user.has_perm के आधार पर links hide या show कर सकते हैं, उसी permission string को match करते हुए।

उदाहरण: Checking Permissions in Templates

has_perm() mirrors the decorator's check, so the link only appears for users who could actually use it.

markup
{% if user.has_perm('library.add_book') %}
  <a href="{% url 'add_book' %}">Add Book</a>
{% endif %}
{# Django-only code -- models.py/views.py/urls.py/settings.py snippets, or template markup using Django template tags/variables -- can't run standalone via Judge0 or the browser preview, since it needs a real Django project. Only this course's pure-Python examples (example_lang == 'python', no Django imports) are actually runnable, so those still get the button below. #}
Related Topics
{# common_mistakes/chapter_summary/browser_support: on Hindi pages the view already swaps in the hi_ translation fields (or blanks these out if untranslated), so this renders correctly for both languages without a lang_code check here. #}
आम गलतियां
  1. Permission string में app_label prefix भूल जाना, जैसे add_book लिखना बजाय 'library.add_book' के।
  2. यह मान लेना कि permission_required login भी check करता है — यह करता है, लेकिन सिर्फ redirect करता है, यह user को यह नहीं बताता कि access क्यों denied हुआ जब तक raise_exception set न हो।
  3. सिर्फ एक narrow permission चाहिए होने पर is_superuser देना बजाय specific permission के।
चैप्टर सारांश
  • @permission_required 'app_label.action_modelname' जैसी एक specific permission string जांचता है।
  • Default रूप से यह unauthenticated या unauthorized users को redirect करता है, बिल्कुल login_required जैसे।
  • raise_exception=True इसे redirect करने के बजाय 403 Forbidden return करवाता है।

Login to run this code

C/C++/Java/PHP execution requires a free account. Your code is saved — you'll land right back in the editor after logging in.