ExamHoot

Implementing Custom Authentication Backend for Company Access Control

from django.contrib.auth.backends import ModelBackend
from django.contrib.auth import get_user_model

User = get_user_model()

class CompanyBackend(ModelBackend):
    def authenticate(self, request, username=None, password=None, company_id=None):
        try:
            user = User.objects.get(username=username, profile__company_id=company_id)
        except User.DoesNotExist:
            return None
        
        if user.check_password(password):
            return user
        return None
  1. The backend will authenticate any user with the correct password regardless of company_id

  2. The backend filters users by both username and company_id, returning the user only if both match and password is correct

  3. The backend requires company_id to be stored in the User model directly, not in a related profile

  4. The backend cannot be used with Django's default authenticate() function

Show answer & explanation

Correct answer

The backend filters users by both username and company_id, returning the user only if both match and password is correct

Explanation

This custom backend extends ModelBackend and adds company_id validation during authentication. It ensures users can only authenticate if they belong to the specified company.

Written by ExamHoot EditorialPublished · Updated

All 30 Django Authentication and Permissions questions

  1. 1.What is the primary purpose of Django's authentication system?
  2. 2.Which Django decorator is used to restrict access to a view to authenticated users only?
  3. 3.What is the difference between authentication and authorization in Django?
  4. 4.Which model in Django stores user information and authentication credentials?
  5. 5.What does the `is_authenticated` attribute of a User object return for an anonymous user?
  6. 6.Which method is used to authenticate a user with username and password in Django?
  7. 7.What is the purpose of the `login()` function in Django?
  8. 8.In Django, what is a Permission object used for?
  9. 9.What is the purpose of a Group in Django's permission system?
  10. 10.Which method checks if a user has a specific permission?
  11. 11.Scenario:
  12. 12.What will be the output of the following code?
  13. 13.Which decorator would you use to ensure a user has the 'can_publish_article' permission before accessing a view?
  14. 14.Scenario:
  15. 15.What is the output of the following code when user 'hari' has the 'blog.change_post' permission?
  16. 16.How would you programmatically assign a permission to a user in Django?
  17. 17.Scenario:
  18. 18.What will be the output of the following code?
  19. 19.Coding Question:
  20. 20.Scenario:
  21. 21.Understanding Django's Authentication Backend Architecture
  22. 22.Implementing Custom Authentication Backend for Company Access Control
  23. 23.Permission Inheritance in Django Group-Based Authorization
  24. 24.Scenario:
  25. 25.Using Django's @permission_required Decorator for View Protection
  26. 26.Implementing Object-Level Permissions for Hari's Document Sharing Platform
  27. 27.Token-Based Authentication Implementation for API Security
  28. 28.Debugging Permission Issues:
  29. 29.Implementing Session-Based Authentication with CSRF Protection
  30. 30.Advanced: