#Difference between authentication classes and permission classes
11 messages · Page 1 of 1 (latest)
well, the word "authentication" means "seeing if someone is who they say they are".
and the word "permission" means "seeing if someone is allowed to do something".
so you generally want to do both: first, figure out if someone is who they say they are (and if not, you tell them to drop dead); then once you're sure you know who they are, you see if they are allowed to do the thing they're trying to do.
But how "IsAuthenticated" class connects to "JWTAuthentication"? What is the code flow?
no idea. Never heard of those classes.
django has an is_authenticated method, fwiw
I assume you're talking about DRF's IsAuthenticated permission class? That just checks whether request.user.is_authenticated is True
attribute, if we're being picky about terms 😆
are we? 🤔