import logging from oauth2_provider.contrib.rest_framework import TokenMatchesOASRequirements, OAuth2Authentication from rest_framework.permissions import ( IsAuthenticated ) loger = logging.getLogger("oauth2_provider") class IsAuthenticatedOrTokenMatchesOASRequirements(TokenMatchesOASRequirements): def has_permission(self, request, view): is_authenticated = IsAuthenticated().has_permission(request, view) oauth2authenticated = False if is_authenticated: oauth2authenticated = isinstance(request.successful_authenticator, OAuth2Authentication) token_has_scope = TokenMatchesOASRequirements() return (is_authenticated and not oauth2authenticated) or token_has_scope.has_permission(request, view)