What are the risks of middleware that mutates request.user?
PICTURE THIS: BROWSER VS ATTACKER
Simple meaning
AuthenticationMiddleware already sets request.user lazily via SimpleLazyObject.
WHY — Middleware instead of guessing?
Why interviewers care about Middleware:
who only read docs from people who shipped.
and tied to Python work.
Name the idea, why it exists, then one short example.
End with when you use it and one common pitfall.
STEPS — What happens step by step?
Before you speak the answer, walk the interviewer through these steps:
- 1AuthenticationMiddleware already sets request.user
lazily via SimpleLazyObject.
- 2Replacing it late can
desync the session, CSRF, and downstream permission checks.
- 3Impersonation middleware must be
explicit, audited, and never enabled based on an untrusted header.
- 4Give an example
One tiny concrete case you can say aloud.
- 5Common mistake
What juniors usually get wrong.
- 6Close
When you pick this over the alternative.
EXAMPLE — See it in action
Here's a short line you can speak, broken into clear beats:
Note: Adapt this scaffold to your own project — keep it under 60–90 seconds.
Key takeaway
AuthenticationMiddleware already sets request.user lazily via SimpleLazyObject. Replacing it late can desync the session, CSRF, and downstream permission checks.