@zeeg@joeyeomanss I'm confused, are you saying DRF is doing it wrong, or that incorporating the permission checks in the API layer is the better approach? Or are you referring to the default permission classes in DRF settings and people relying naively on that?
📢Silver sponsor: @maykinmedia
Maykin is a Dutch software company that specializes in designing and building user-friendly digital solutions for governments and public organizations.
We're really grateful for the support!
🔗https://t.co/NCIy1F8dpL
#djangocon
this thing about open source projects making their tests private
you're either open source or not - part of that is enabling a successor to show up for net benefit of the world
making that intentionally difficult is fine but then it's something different