【发布时间】:2015-10-28 20:17:47
【问题描述】:
我在 DRF 中有一个 Update 方法,允许用户更新他们自己的个人资料。 api 端点是PUT /api/users/{id}/,其中 id 是他自己的用户 id。如果他尝试更新任何其他用户配置文件,他将收到 HTTP403。
我现在的做法是
def update(self, request, *args, **kwargs):
"""
Update user profile
"""
if int(kwargs['id']) is not request.user.id:
return Response({}, status=status.HTTP_403_FORBIDDEN)
return super(UserViewSet, self).update(request, *args, **kwargs)
我希望以更优雅的方式来做这件事,也许用装饰器之类的?
【问题讨论】:
-
你在使用令牌认证吗?
-
是的,我正在使用令牌身份验证
标签: python django django-rest-framework