Module 4 · Authentication and security

Lesson 21 — Authorization

Roles, permissions and per-resource access control: who can touch what.

Published
In this lesson
  1. Exercise 1 — The matrix before the code
  2. Exercise 2 — IDOR: provoke it and close it
  3. Exercise 3 — IsOrganizer and object
  4. Exercise 4 — The ABAC rule
  5. Exercise 5 — Role escalation
  6. Submit

DRF. Don't look at solutions.md before submitting.

Exercise 1 — The matrix before the code

  1. Build the complete matrix (actions × roles): event list/detail, create/edit event, view availability, create reservation, view/cancel someone else's reservation, start payment, view sales, refund, change a user's role.
  2. Mark the cells with a condition (not just yes/no): e.g. "edit event: the ORGANIZER of that event and state=DRAFT".
  3. Highlight 2 cells your implementation today does NOT satisfy. Those are your tasks for exercises 3-4.

Exercise 2 — IDOR: provoke it and close it

  1. Create 2 users with 1 reservation each. With A's token, call GET /api/reservations/{B's uuid}/. What does your API answer today? (if it is 200: you have the hole live).
  2. Close it with get_queryset() filtered by user (404 for others' resources) and verify. What does 404 gain over 403 here?
  3. Second layer: ownership has_object_permission. In what order are they evaluated and why both?

Exercise 3 — IsOrganizer and object

  1. Create IsOrganizer (endpoint: only the ORGANIZER role creates events) and IsOrganizerOfEvent (object: the event's owner or staff edits).
  2. Demonstrate: B (organizer) tries to edit A's event → 403/404; B edits their own → 200.
  3. Bug to hunt: does your Event serializer accept organizer from the request? (escalation: assigning others' events to yourself). Fix it (read_only or force request.user).

Exercise 4 — The ABAC rule

  1. Implement: "an event is only editable if state=DRAFT or (state=PUBLISHED and more than 24h until starts_at)". Where does it live? (the service, with the appropriate domain exception).
  2. Demonstrate the 3 cases: draft editable, published 48h ahead editable, published 2h ahead → 422 with type event-locked.
  3. Who may cancel an already-published event and what happens to active reservations? (design: policy + effect on states; don't implement all of it: the ADR is enough).

Exercise 5 — Role escalation

  1. Try (as BUYER) PATCH /api/users/me/ {"role": "STAFF"}. If your serializer accepts it: celebrate having caught it. Close it (role never from input; role changes only through a staff endpoint + audit log of who changed whom).
  2. Write the test that guarantees it forever (escalation regression test).

Submit

Paste the matrix, the tests and the corrected endpoints. Next: Lesson 22 — OWASP Top 10.