Django REST Framework has an excellent piece of documentation about permissions. I've been able to use pre-made permission classes and also built my own.
However, there are some API methods in which a "Permission denied" generic message is not very informative for the user. For example, if the user is authenticated but the account has expired, it would be nice to let the user know that his account is expired and not just a permission denied error.
When building custom permission classes, you either return True
or False
- according to the documentation. But I would like, as said above, to show a more informative message to the user. How to accomplish this?