Website/api/permissions.py

13 lines
356 B
Python

from rest_framework import permissions
class IsSuperUserOrReadOnly(permissions.BasePermission):
def has_permission(self, request, view):
if request.method in permissions.SAFE_METHODS:
return True
return request.user.is_superuser
class IsStaff(permissions.BasePermission):
def has_permission(self, request, view):
return request.user.is_staff