Django为什么我不能对用户进行身份验证?

时间:2016-01-16 17:17:28

标签: python django

我尝试使用Django +1.8创建用户身份验证表单但是我遇到了一个问题,当我按下表单提交按钮时,没有任何反应,页面只是重新加载而不是登录,为什么?

以下是代码:

views.py

from django.shortcuts import render
from django.contrib.auth import authenticate
from django.contrib.auth import login as auth_login
from django.contrib.auth import logout as auth_logout

# Create your views here.
def user(request):
    context = {}
    return render(request, 'user.html', context)

def login(request):
    context = {}
    if request.method == "POST":
        username = request.POST['username']
        password = request.POST['password']
        user = authenticate(username=username, password=password)
        if user is not None:
            if user is not None:
                auth_login(request, user)
            else:
                context['error'] = 'Non active user'
        else:
            context['error'] = 'Mauvais nom d\'utilisateur ou mot de passe'
    else:
        context['error'] = ''
    return render(request, 'user.html', context)

def logout(request):
    context = {}
    if request.method == "POST":
        auth_logout(request)
    else:
        context['error'] = 'une erreur s\'est produite.'
    return render(request, 'user.html', context)

urls.py

    from django.conf.urls import url
    from utilisateur import views

    urlpatterns = [
        url(r'^$', views.user, name="user"),
        url(r'^login$', views.login, name='login'),
        url(r'^logout$', views.logout, name='logout'),
    ]

user.html

{% block content %}
{% if user.authenticated %}
<p>{{ user.username }}</p>
<a href="logout?">Logout</a>
{% else %}
<form method="post" action="login">
    {% csrf_token %}
    <p>username:<input type="text" name="username"></p>
    <p>password:<input type="password" name="password"></p>
    <input value="Se connecter" type="submit">
</form>
{% endif %}
{% endblock %}

我还认为中间件可以用来解决这个问题。

MIDDLEWARE_CLASSES = [
    'django.middleware.security.SecurityMiddleware',
    'django.contrib.sessions.middleware.SessionMiddleware',
    'django.middleware.common.CommonMiddleware',
    'django.middleware.csrf.CsrfViewMiddleware',
    'django.contrib.auth.middleware.AuthenticationMiddleware',
    'django.contrib.auth.middleware.SessionAuthenticationMiddleware',
    'django.contrib.messages.middleware.MessageMiddleware',
    'django.middleware.clickjacking.XFrameOptionsMiddleware',
]

'context_processors': [
     'django.template.context_processors.debug',
     'django.template.context_processors.request',
     'django.contrib.auth.context_processors.auth',
     'django.contrib.messages.context_processors.messages',
],

我认为问题来自context_instance=RequestContext(request),我该如何解决?

2 个答案:

答案 0 :(得分:1)

问题是,如果用户在身份验证后有效,您只是忘记添加一行来将用户重定向到另一个页面。你应该替换这些行

`if user is not None:
    if user is not None:
       auth_login(request, user)
    else:
       context['error'] = 'Non active user'
 else:
    context['error'] = 'Mauvais nom d\'utilisateur ou mot de passe'`

与这些

if user is not None:
    auth_login(request, user)
    redirect('login')
 else:
    context['error'] = 'Mauvais nom d\'utilisateur ou mot de passe'

然后你继续,如果用户已经使用你的模板进行了身份验证

{% if user.is_authenticated %}

{% if not user.is_anonymous %}

如果问题仍然存在,请随时告诉我

答案 1 :(得分:1)

实际上身份验证工作正常。您需要对 user.authemticated 进行一些更正,以 user.is_authenticated ,并更改模板上的注销功能和网址

user.html:

{% block content %}
{% if user.is_authenticated %}
<p>{{ user.username }}</p>

<a href="/logout">Logout</a>
{% else %}
<form method="post" action="login">
    {% csrf_token %}
    <p>username:<input type="text" name="username"></p>
    <p>password:<input type="password" name="password"></p>
    <input value="Se connecter" type="submit">
</form>
{% endif %}
{% endblock %}

views.py

from django.shortcuts import render
from django.contrib.auth import authenticate
from django.contrib.auth import login as auth_login
from django.contrib.auth import logout as auth_logout

# Create your views here.
def user(request):
    context = {}
    return render(request, 'user.html', context)

def login(request):
    context = {}
    if request.method == "POST":
        username = request.POST['username']
        password = request.POST['password']
        user = authenticate(username=username, password=password)
        if user is not None:
            if user.is_active:
                auth_login(request, user)
            else:
                context['error'] = 'Non active user'
        else:
            context['error'] = 'Mauvais nom d\'utilisateur ou mot de passe'
    else:
        context['error'] = ''
    return render(request, 'user.html', context)

def logout(request):
    context = {}
    auth_logout(request)
    return render(request, 'user.html', context)