身份验证后,它不会重定向到django

时间:2016-03-04 20:40:43

标签: python django authentication redirect

我无法在身份验证后重定向到Django中的下一页。我已经在views.py文件中定义了下一个并调用该值,但是在URL中它将URL重定向到Login页面,如下所示:

没有@login_required它正常工作

将用户名和密码重定向到

http://127.0.0.1:8000/?next=/home/

但我想:

http://127.0.0.1:8000/home(并显示主页)

请帮忙。

views.py

from django.shortcuts import render
from django.contrib.auth import authenticate, login, logout
from django.contrib.auth.decorators import login_required
from django.http import HttpResponseRedirect, HttpResponse
from django.contrib import auth
from django.conf import settings
from django.core.urlresolvers import reverse
def login(request):
    next = request.POST.get('next', 'home/')
    if request.method == "POST":
            username = request.POST['username']
            password = request.POST['password']
            user = authenticate(username=username, password=password)


            if user is not None:
                    if user.is_active:
                            auth.login(request, user)

                            return HttpResponseRedirect(settings.LOGIN_REDIRECT_URL)
                    else:
                            return HttpResponse("Inactive user.")
            else:
                    return HttpResponseRedirect(settings.LOGIN_URL)
    return render(request, "login.html")

def logout(request):
    auth.logout(request)
    return HttpResponseRedirect(settings.LOGIN_URL)

@login_required(redirect_field_name='next')
def home(request):
    return render (request, "home.html")

App-urls.py:

 from django.conf.urls import url

 from . import views

 urlpatterns = [
         url(r'^$', views.home, name='home'),
  ]

项目网址:

from django.conf.urls import url, include
from django.contrib import admin
from django.contrib.auth import views


urlpatterns = [
         url(r'^admin/', admin.site.urls),
         url(r'^home/', include('login.urls', namespace="login")),
         url(r'^$', views.login),
         url(r'^logout/$', views.logout),
 ]

Settings.py:

  import os

  # Build paths inside the project like this: os.path.join(BASE_DIR,  ...)
 BASE_DIR = os.path.dirname(os.path.dirname(os.path.abspath(__file__)))


# Quick-start development settings - unsuitable for production
# See     https://docs.djangoproject.com/en/1.9/howto/deployment/checklist/

# SECURITY WARNING: keep the secret key used in production secret!
SECRET_KEY = '(i34g@645+vc8$@y9qd)_fo1l#k%78up_cheab#!(b24xv$!uj'

# SECURITY WARNING: don't run with debug turned on in production!
DEBUG = True

ALLOWED_HOSTS = []


# Application definition

INSTALLED_APPS = [
      'login',
      'django.contrib.admin',
      'django.contrib.auth',
      'django.contrib.contenttypes',
      'django.contrib.sessions',
      'django.contrib.messages',
       'django.contrib.staticfiles',
  ]

 MIDDLEWARE_CLASSES = [
      'django.middleware.security.SecurityMiddleware',
      'django.contrib.sessions.middleware.SessionMiddleware',
      'django.middleware.common.CommonMiddleware',
      'django.middleware.csrf.CsrfViewMiddleware',
      'django.contrib.auth.middleware.AuthenticationMiddleware',
     'django.contrib.auth.middleware.SessionAuthenticationMiddleware',
     'django.contrib.messages.middleware.MessageMiddleware',
     'django.middleware.clickjacking.XFrameOptionsMiddleware',
    ]

 ROOT_URLCONF = 'myproject.urls'

 TEMPLATES = [
    {
    'BACKEND': 'django.template.backends.django.DjangoTemplates',
    'DIRS': [],
    'APP_DIRS': True,
    'OPTIONS': {
        'context_processors': [
            'django.template.context_processors.debug',
            'django.template.context_processors.request',
            'django.contrib.auth.context_processors.auth',
            'django.contrib.messages.context_processors.messages',
        ],
    },
},
 ]

 WSGI_APPLICATION = 'myproject.wsgi.application'


 # Database
 # https://docs.djangoproject.com/en/1.9/ref/settings/#databases

DATABASES = {
'default': {
    'ENGINE': 'django.db.backends.sqlite3',
    'NAME': os.path.join(BASE_DIR, 'db.sqlite3'),
}
}


 # Password validation
 # https://docs.djangoproject.com/en/1.9/ref/settings/#auth-password-     validators

 AUTH_PASSWORD_VALIDATORS = [
     {
    'NAME':   'django.contrib.auth.password_validation.UserAttributeSimilarityValidator',
},
{
    'NAME':  'django.contrib.auth.password_validation.MinimumLengthValidator',
},
{
    'NAME': 'django.contrib.auth.password_validation.CommonPasswordValidator',
},
{
    'NAME': 'django.contrib.auth.password_validation.NumericPasswordValidator',
},
 ]


 # Internationalization
# https://docs.djangoproject.com/en/1.9/topics/i18n/

 LANGUAGE_CODE = 'en-us'

 TIME_ZONE = 'UTC'

 USE_I18N = True

 USE_L10N = True

USE_TZ = True


# Static files (CSS, JavaScript, Images)
# https://docs.djangoproject.com/en/1.9/howto/static-files/

STATIC_URL = '/static/'


LOGIN_URL = 'login/'
APPEND_SLASH = False

的login.html:

<!DOCTYPE html>
<center>

<section class="loginform cf">
<h1 style="color:blue"> User Login </h1>
<form name="login" method="post" accept-charset="utf-8" action="{% url   'login:home' %}">
{% csrf_token %}
<label for="usermail" align="center">User-Id </label>
<input type="alphanumeric" name="userid" >
<br \>
<label for="password" align="center">Password </label>
<input type="alphanumeric" name="password" >
<br \>
<input type="submit" value="Login" style="color:blue">
<input type="hidden" name="next" value="{{ next }}"/>
</center>
</form>
</section>

1 个答案:

答案 0 :(得分:1)

你有一些不同的事情正在影响它。

您的urls.py文件需要进行一些清理。由于您已经定义了自己的登录/注销方法,因此您不需要使用django.contrib.auth.views中的方法。因此,您的基本urls.py文件应如下所示:

from django.conf.urls import url
from django.contrib import admin
import login.views

urlpatterns = [
    url(r'^admin/', admin.site.urls),
    url(r'^home/', include('login.urls')
    url(r'^$', login.views.login)
    url(r'^logout/$', login.views.logout)
]

您的login/urls.py文件可以保持不变。现在我们将登录/注销指向您的视图而不是django.contrib.auth.views

您已将settings.LOGIN_URL设置为login/,但您的urls.py文件会将/指向登录功能。对于此答案,我将settings.LOGIN_URL更改为/以匹配您的网址文件。

由于我们已更新login/views.py文件,因此您的urls.py文件只需进行一些更改。

我清理了一些不必要的导入语句,并从redirect_field_name='next'删除了@login_required,因为'next'是默认值。

我们需要同时检查POSTGET个对象以获取next参数。

最大的变化是我们对用户进行身份验证并验证他们是否已激活,而不是return HttpResponseRedirect(settings.LOGIN_REDIRECT_URL)我们只是return HttpResponseRedirect('/home')或将其发送到我们的next网址从POST / GET数据抓取。

from django.shortcuts import render
from django.contrib import auth
from django.contrib.auth.decorators import login_required
from django.http import HttpResponse, HttpResponseRedirect
from django.conf import settings

def login(request):
    next = request.POST.get('next', request.GET.get('next', ''))
    if request.method == "POST":
        username = request.POST.get('username')
        password = request.POST.get('password')
        user = auth.authenticate(username=username, password=password)
        if user is not None:
            if user.is_active:
                login(request, user)
                if next:
                    return HttpResponseRedirect(next)
                return HttpResponseRedirect('/home')
            else:
                return HttpResponse('Inactive user')
        else:
            return HttpResponseRedirect(settings.LOGIN_URL)
    return render(request, "login.html")

def logout(request):
    auth.logout(request)
    # Redirect back to login page
    return HttpResponseRedirect(settings.LOGIN_URL)


@login_required
def home(request):
    return render(request, "home.html")

一旦你有了这个,除非我缺少其他东西,@login_required如果用户没有登录,应该正确地重定向到你的登录页面。