Where should authentication checks live: middleware, mixin, or template?
PICTURE THIS: DJANGO MVT
Simple meaning
Enforce access in the view layer (LoginRequiredMixin, permission_required, DRF permissions) so APIs cannot be bypassed.
WHY — Django MVT instead of guessing?
Why interviewers care about Django MVT:
people who only read docs from people who shipped.
and tied to Python work.
Name the idea, why it exists, then one short example.
End with when you use it and one common pitfall.
STEPS — What happens step by step?
Before you speak the answer, walk the interviewer through these steps:
- 1Enforce access in the
view layer (LoginRequiredMixin, permission_required, DRF permissions) so APIs cannot be bypassed.
- 2Middleware is for site-wide
policies such as forcing login on all HTML except a few paths.
- 3Templates may hide buttons
but must never be the only guard.
- 4Give an example
One tiny concrete case you can say aloud.
- 5Common mistake
What juniors usually get wrong.
- 6Close
When you pick this over the alternative.
EXAMPLE — See it in action
Here's a short line you can speak, broken into clear beats:
Note: Adapt this scaffold to your own project — keep it under 60–90 seconds.
Key takeaway
Enforce access in the view layer (LoginRequiredMixin, permission_required, DRF permissions) so APIs cannot be bypassed. Middleware is for site-wide policies such as forcing login on all HTML except a few paths.