Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
No auth view failing permission should raise 403
A view with no `authentication_classes` set and that fails a
permission check should raise a 403 with the message from the
failing permission.
  • Loading branch information
johnraz committed Apr 7, 2016
commit 4def1935a12bf0f11c6a3ec9e7bbe0af329199d0
2 changes: 1 addition & 1 deletion rest_framework/views.py
Original file line number Diff line number Diff line change
Expand Up @@ -162,7 +162,7 @@ def permission_denied(self, request, message=None):
"""
If request is not permitted, determine what kind of exception to raise.
"""
if not request.successful_authenticator:
if request.authenticators and not request.successful_authenticator:
raise exceptions.NotAuthenticated()
raise exceptions.PermissionDenied(detail=message)

Expand Down
25 changes: 25 additions & 0 deletions tests/test_authentication.py
Original file line number Diff line number Diff line change
Expand Up @@ -321,3 +321,28 @@ def test_failing_auth_accessed_in_renderer(self):
response = self.view(request)
content = response.render().content
self.assertEqual(content, b'not authenticated')


class NoAuthenticationClassesTests(TestCase):
def test_permission_message_with_no_authentication_classes(self):
"""
An unauthenticated request made against a view that containes no
`authentication_classes` but do contain `permissions_classes` the error
code returned should be 403 with the exception's message.
"""

class DummyPermission(permissions.BasePermission):
message = 'Dummy permission message'

def has_permission(self, request, view):
return False

request = factory.get('/')
view = MockView.as_view(
authentication_classes=(),
permission_classes=(DummyPermission,),
)
response = view(request)
self.assertEqual(response.status_code,
status.HTTP_403_FORBIDDEN)
self.assertEqual(response.data, {'detail': 'Dummy permission message'})