Authenticating with tokens
In this exercise, we will be treating the API that we built earlier in this chapter as if it is now an API provided by a third party. Pretend for a moment that you did not build your API and we will practice authenticating by using a security token. Token security will be used in addition to the individual model permissions as we did in the previous exercise. This will be done whether you grant a user access to the Django admin site or not. That also means we will create a new user/seller for this exercise and then restrict that user’s access to the Django admin site for demonstration purposes.
We will follow the same steps as the previous two exercises next.
Project configuration
This exercise requires a little bit of configuration inside the project’s settings.py
file before we can get started with the same steps as before.
Follow these steps to configure your project:
- In your
settings.py
file, add the following app to...