PageSourceSearch

https://softwarecrafts.uk/_next/static/chunks/pages/100-words/day-247-61aebb87b4181442.js

js softwarecrafts.uk collected 2026-10-01 14:06:04 UTC 2,618 bytes, 1 lines download raw bytes

1(self.webpackChunk_N_E=self.webpackChunk_N_E||[]).push([[2727],{38509:function(e,t,i){(window.__NEXT_P=window.__NEXT_P||[]).push(["/100-words/day-247",function(){return i(37354)}])},37354:function(e,t,i){"use strict";i.r(t),i.d(t,{meta:function(){return r}});var o=i(85893),s=i(11151),n=i(53841);let r={author:"Andrew Miller",date:"2024-12-19",title:"Working with Django Guardian",description:"Powering a Django project through permissions",tags:["100 words","django","permissions","guardian","object-level"]},MDXLayout=e=>(0,o.jsx)(n.B,Object.assign({meta:r},e));function _createMdxContent(e){let t=Object.assign({p:"p",code:"code"},(0,s.ah)(),e.components);return(0,o.jsxs)(o.Fragment,{children:[(0,o.jsx)(t.p,{children:"I'm currently in the middle of a architecture migration for one of my clients where are unifying how the sharing of different resources (essentially different models) are visible to different users. We have also built some UI to support this so some users have the ability to do the sharing themselves. For the models that are not yet migrated it's either a ForeignKey or ManyToManyField named differently on each model and operating slighltly differently in each view."}),"\n",(0,o.jsxs)(t.p,{children:["The basics of the new architecture is that we programitically create Django authorization Groups that are linked to differing levels of access, be it a single object, a group of users, or everyone. We then use django-guardian to assign the ",(0,o.jsx)(t.code,{children:"view_*"})," permission to the group that matches the object being permissioned (this is linked via the pk of the object being present in the name of the group)"]}),"\n",(0,o.jsx)(t.p,{children:"Finally we have used this logic to allow users to group arbitary objects in to collections of items. This isn't done explicity through relationships or Generic ForeignKeys, but it's a semi-layered approach to permissions as the collection has an auth group which gets view permission to the objects added to the collection."}),"\n",(0,o.jsx)(t.p,{children:"All this results in quite generic and reusable code for both the sharing an object with a user and also for views where we want to display a list of objects that a user has access to. The current challenge is adding the ability for a user to filter on these list views, I was pondering this today and tomorrow I will share the results of my findings."})]})}t.default=function(e={}){return(0,o.jsx)(MDXLayout,Object.assign({},e,{children:(0,o.jsx)(_createMdxContent,e)}))}}},function(e){e.O(0,[407,8819,4825,9774,2888,179],function(){return e(e.s=38509)}),_N_E=e.O()}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.