问题 Let's say i have a form that does something in database and requires user authentication that has been sent by POST, is it possible inside request someone evil to change the user in order to exploit the system? The following example creates an item in database but requires a logged in user. Can someone send other user's data in request.user ? from django.shortcuts import render, redirect from django.contrib.auth.decorators import login_required from items_core.models import Item from items