I am trying to understand how things work when one writes the following in settings.py:
AUTHENTICATION_BACKENDS = (
"django.contrib.auth.backends.ModelBackend",
"allauth.account.auth_backends.AuthenticationBackend",
"master_password.auth.ModelBackend"
)
In particular, the documentation states:
If a backend raises a
PermissionDeniedexception, authentication will immediately fail. Django won’t check the backends that follow.
Given this, how can the second and the third backend in the above example get a chance when a user has entered an incorrect password and the first backend has denied him access? More specifically, the third backend pertains to django-master-password, which should let the user in if he used a master password even if it does not match the user's password. So, how will that backend ever get a chance?