A Django permit service must carry a reviewer's identity into an exact case permission check, read only a bounded queue, commit browser commands once, and keep synchronous database transactions outside the async event loop. These lessons use one set of permit cases so query shape, retry behavior, and deployment choices can be evaluated against the same business rule.
Topics in this track
- Django Middleware, Sessions, and Object Permissions — Separate request-wide identity setup from the permission decision for one database row.
- Django QuerySet Shape, Prefetch, and Page Cost — Bound query count, transferred columns, page width, and relation loading for a case list.
- Django Forms, CSRF, Atomic Approval, and On-Commit Work — Validate a browser command, commit one state change, and dispatch side effects after commit.
- Django ASGI, Async Views, and the Sync ORM Boundary — Use asynchronous views where waiting overlaps, while keeping transactional database work synchronous.
Prerequisite paths
Backend and API Systems; Authorization and Tenant Boundaries; Data Persistence.
Practice and check
Build Project: Django permit review service and review Web Development: Django request and persistence quiz.
