from django.contrib.auth.backends import ModelBackend
from django.contrib.auth import get_user_model
User = get_user_model()
class CompanyBackend(ModelBackend):
def authenticate(self, request, username=None, password=None, company_id=None):
try:
user = User.objects.get(username=username, profile__company_id=company_id)
except User.DoesNotExist:
return None
if user.check_password(password):
return user
return NoneImplementing Custom Authentication Backend for Company Access Control
The backend will authenticate any user with the correct password regardless of company_id
The backend filters users by both username and company_id, returning the user only if both match and password is correct
The backend requires company_id to be stored in the User model directly, not in a related profile
The backend cannot be used with Django's default authenticate() function
Show answer & explanationAnswer
Correct answer
The backend filters users by both username and company_id, returning the user only if both match and password is correct
Explanation
This custom backend extends ModelBackend and adds company_id validation during authentication. It ensures users can only authenticate if they belong to the specified company.
Written by ExamHoot EditorialPublished · Updated
All 30 Django Authentication and Permissions questions
- 1.What is the primary purpose of Django's authentication system?
- 2.Which Django decorator is used to restrict access to a view to authenticated users only?
- 3.What is the difference between authentication and authorization in Django?
- 4.Which model in Django stores user information and authentication credentials?
- 5.What does the `is_authenticated` attribute of a User object return for an anonymous user?
- 6.Which method is used to authenticate a user with username and password in Django?
- 7.What is the purpose of the `login()` function in Django?
- 8.In Django, what is a Permission object used for?
- 9.What is the purpose of a Group in Django's permission system?
- 10.Which method checks if a user has a specific permission?
- 11.Scenario:
- 12.What will be the output of the following code?
- 13.Which decorator would you use to ensure a user has the 'can_publish_article' permission before accessing a view?
- 14.Scenario:
- 15.What is the output of the following code when user 'hari' has the 'blog.change_post' permission?
- 16.How would you programmatically assign a permission to a user in Django?
- 17.Scenario:
- 18.What will be the output of the following code?
- 19.Coding Question:
- 20.Scenario:
- 21.Understanding Django's Authentication Backend Architecture
- 22.Implementing Custom Authentication Backend for Company Access Control
- 23.Permission Inheritance in Django Group-Based Authorization
- 24.Scenario:
- 25.Using Django's @permission_required Decorator for View Protection
- 26.Implementing Object-Level Permissions for Hari's Document Sharing Platform
- 27.Token-Based Authentication Implementation for API Security
- 28.Debugging Permission Issues:
- 29.Implementing Session-Based Authentication with CSRF Protection
- 30.Advanced:
