read about security with DRF https://www.django-rest-framework.org/topics/ajax-csrf-cors/