DRF. Don't look at solutions.md before submitting.
Exercise 1 — The matrix before the code
- Build the complete matrix (actions × roles): event list/detail, create/edit event, view availability, create reservation, view/cancel someone else's reservation, start payment, view sales, refund, change a user's role.
- Mark the cells with a condition (not just yes/no): e.g. "edit event: the ORGANIZER of that event and state=DRAFT".
- Highlight 2 cells your implementation today does NOT satisfy. Those are your tasks for exercises 3-4.
Exercise 2 — IDOR: provoke it and close it
- Create 2 users with 1 reservation each. With A's token, call
GET /api/reservations/{B's uuid}/. What does your API answer today? (if it is 200: you have the hole live). - Close it with
get_queryset()filtered by user (404 for others' resources) and verify. What does 404 gain over 403 here? - Second layer: ownership
has_object_permission. In what order are they evaluated and why both?
Exercise 3 — IsOrganizer and object
- Create
IsOrganizer(endpoint: only the ORGANIZER role creates events) andIsOrganizerOfEvent(object: the event's owner or staff edits). - Demonstrate: B (organizer) tries to edit A's event → 403/404; B edits their own → 200.
- Bug to hunt: does your Event serializer accept
organizerfrom the request? (escalation: assigning others' events to yourself). Fix it (read_only or force request.user).
Exercise 4 — The ABAC rule
- Implement: "an event is only editable if
state=DRAFTor (state=PUBLISHEDand more than 24h until starts_at)". Where does it live? (the service, with the appropriate domain exception). - Demonstrate the 3 cases: draft editable, published 48h ahead editable, published 2h ahead → 422 with type
event-locked. - Who may cancel an already-published event and what happens to active reservations? (design: policy + effect on states; don't implement all of it: the ADR is enough).
Exercise 5 — Role escalation
- Try (as BUYER)
PATCH /api/users/me/ {"role": "STAFF"}. If your serializer accepts it: celebrate having caught it. Close it (role never from input; role changes only through a staff endpoint + audit log of who changed whom). - Write the test that guarantees it forever (escalation regression test).
Submit
Paste the matrix, the tests and the corrected endpoints. Next: Lesson 22 — OWASP Top 10.