How to block/override djoser user/me endpoint?

Viewed 579

I would like to know if there is a chance to block the djoser's user/me endpoint for specific request methods. I don't see this in the docs.

Problem: Now when I have two users { email: 'a@exa.com' }, and { email: 'b@exa.com' }. I can use the first user to change his email to match the 2nd user's email, so both will have the same email, and the second one will be blocked cos of that.

Is there an elegant way to check if the email exists from the djoser's level?

1 Answers

Djoser maintainer here.

I would like to know if there is a chance to block the djoser's user/me endpoint for specific request methods. I don't see this in the docs.

You'd need to subclass UserViewSet and change me action or add custom permissions in get_permissions.

So if you wanted to disable/limit PUT

class MyCustomUserViewSet(UserViewSet):
    def get_permissions(self):
        if self.action == "me" and self.request.method == "PUT":
            # do something
        return super().get_permissions()

or

class MyCustomUserViewSet(UserViewSet):
    @action(["get", "patch", "delete"], detail=False)
    def me(self, request, *args, **kwargs):
        return super().me(request, *args, **kwargs)

Problem: Now when I have two users { email: 'a@exa.com' }, and { email: 'b@exa.com' }. I can use the first user to change his email to match the 2nd user's email, so both will have the same email, and the second one will be blocked cos of that.

You should always have unique or pk constraint on user email. It's not djoser's responsibility to guarantee unique email in your DB.

Is there an elegant way to check if the email exists from the djoser's level?

If you use unique then it won't be 2xx and you will know something went wrong. There's no way to "check" if email exists from the djoser level and there will never be as its purpose is to be a generic REST auth for Django.

Related