Interaction between global permission classes and object-level BasePermission logic
25K reputation · 06 Jan 2021, 13:11 UTC
In Django Rest Framework, the security lifecycle executes check_permission on the view before invoking has_object_permission. While setting a global DEFAULT_PERMISSION_CLASSES like IsAuthenticated provides a baseline, complex scenarios arise when custom permission classes are implemented to handle object-level ownership.
Specifically, if a custom permission class relies on the state of a model instance to determine access, there is a risk that the global view-level check may pass or fail before the object-specific logic is even evaluated. This becomes particularly problematic when using global filterbackends that modify querysets, as the permission logic might not align with the filtered data set if not strictly atomic.
How does the execution order between global default permissions and custom object-level permission checks affect security when a view depends on dynamic data? Is there a reliable way to ensure that object-level restrictions are not bypassed if the view-level check returns a positive result prematurely?