ExamHoot

Authentication and Permissions in DRF

from rest_framework.authentication import TokenAuthentication, SessionAuthentication
from rest_framework.permissions import IsAuthenticated, IsAdminUser
from rest_framework.views import APIView
from rest_framework.response import Response

class AdminOnlyView(APIView):
    authentication_classes = [TokenAuthentication, SessionAuthentication]
    permission_classes = [IsAuthenticated, IsAdminUser]
    
    def get(self, request):
        return Response({'message': 'Admin only content'})

class PublicView(APIView):
    permission_classes = []
    
    def get(self, request):
        return Response({'message': 'Public content'})
  1. AdminOnlyView requires both authentication AND admin status. PublicView is accessible to anyone. Both authentication methods in AdminOnlyView are tried sequentially.

  2. AdminOnlyView requires either TokenAuthentication OR SessionAuthentication, not both. The user needs only one to access the view.

  3. PublicView will still require authentication because permission_classes=[] inherits from the default settings.

  4. IsAdminUser permission is checked before IsAuthenticated, so unauthenticated users are rejected at the IsAdminUser step.

Show answer & explanation

Correct answer

AdminOnlyView requires both authentication AND admin status. PublicView is accessible to anyone. Both authentication methods in AdminOnlyView are tried sequentially.

Explanation

Multiple authentication methods allow flexibility (token or session), while permission_classes are evaluated as AND logic—all must pass. Empty permission_classes allows public access.

Written by ExamHoot EditorialPublished · Updated

All 29 Django REST API Development questions

  1. 1.What is the primary purpose of Django REST Framework (DRF)?
  2. 2.What is a Serializer in Django REST Framework?
  3. 3.Which decorator is used to convert a regular Django view into an API view in DRF?
  4. 4.What is the purpose of ViewSets in Django REST Framework?
  5. 5.Which class should be inherited to create a basic API view in DRF?
  6. 6.What is the default authentication method in Django REST Framework?
  7. 7.How do you register URLs for ViewSets in Django REST Framework?
  8. 8.What does the status module in DRF provide?
  9. 9.Which permission class allows only authenticated users to access an API endpoint?
  10. 10.What is the Response class used for in Django REST Framework?
  11. 11.Scenario:
  12. 12.What will be the output of the following code snippet?
  13. 13.Scenario:
  14. 14.What is the difference between ModelSerializer and Serializer in Django REST Framework?
  15. 15.Identify the bug in the following code snippet:
  16. 16.How do you implement pagination in a Django REST Framework API?
  17. 17.Scenario:
  18. 18.What is the purpose of the queryset attribute in a ViewSet?
  19. 19.Scenario:
  20. 20.What will be the output of this code snippet?
  21. 21.Understanding DRF Serializers and Nested Relationships
  22. 22.DRF Viewsets and Router Configuration Scenario
  23. 23.Authentication and Permissions in DRF
  24. 24.Pagination and Filtering in DRF Scenario
  25. 25.Custom Validation in DRF Serializers
  26. 26.Status Codes and Exception Handling in DRF
  27. 27.Throttling and Rate Limiting Scenario
  28. 28.Request and Response Cycle with Middleware
  29. 29.Advanced Serializer Optimization and Performance