def has_object_permission()

in tweeter/permissions.py [0:0]


    def has_object_permission(self, request, view, obj):
        # A User can edit and view their own data
        is_self = obj == request.user
        is_admin = request.user.is_superuser
        return is_self or is_admin