I'm trying to grant access to specific URLs and menu links in the base.html file based on AD groups authenticated users belong to. The AD instance is fairly large but it also includes deeply-nested AD groups, so, querying the AD server for every HTTP request is an expensive one.
A solution I'm thinking of at the moment is to write a custom middleware that queries the AD server the first time a user access the application, I query the AD server one time, get all the access levels they should have and store this information in a session, then, when they make another request, I check the session values first if I already set permissions for that specific user, this should avoid querying the AD server every time.
Given this criteria, is there any native django authorization classes/technique that is able to handle this sort of access privilege?