Django REST framework object level permissions
I have done this in the past using a custom permission and overridden has_object_permission like the following: from rest_framework import permissions class MyUserPermissions(permissions.BasePermission): “”” Handles permissions for users. The basic rules are – owner may GET, PUT, POST, DELETE – nobody else can access “”” def has_object_permission(self, request, view, obj): # check if user is … Read more