自定义User django+jwt验证登录

首先,我的项目结构是这样的

1.安装djangorestframework-jwt
pip install djangorestframework-jwt

2.setting.py配置

#rest_framework配置
REST_FRAMEWORK = {
    'DEFAULT_PERMISSION_CLASSES': (
        'rest_framework.permissions.IsAuthenticated',
    ),
    'DEFAULT_AUTHENTICATION_CLASSES': (
        # 'rest_framework_simplejwt.authentication.JWTAuthentication',  # JWT认证,在前面的认证方案优先
        'rest_framework_jwt.authentication.JSONWebTokenAuthentication',
        'rest_framework.authentication.SessionAuthentication',
        'rest_framework.authentication.BasicAuthentication',
    ),
}
    JWT_AUTH = {
        'JWT_EXPIRATION_DELTA': datetime.timedelta(days=1),  # JWT_EXPIRATION_DELTA 指明token的有效期
        'JWT_AUTH_HEADER_PREFIX': 'JWT',  # 默认的
    }

# from apps import bjnews
AUTH_USER_MODEL = 'bjnews.UserModel' #自定义user类,一定要配置,否则就是drf默认的
AUTHENTICATION_BACKENDS=(
    "bjnews.views.CustomBackend", #自定义登录验证
)

3.User类的继承(迁移至数据库)
#之所以继承AbstractBaseUser是因为它的字段比其他的感觉少一些
#如果继承AbstractBaseUser不继承PermissionsMixin,登录能正常登录,但是再次使用token时回报失效,具体底层我也不是特别清楚,感觉是权限问题;只有继承PermissionsMixin才能使用django的用户权限模块

from django.contrib.auth.models import AbstractBaseUser,PermissionsMixin,AbstractUser
from .UserManage import UserManager


# Create your models here.
class UserModel(AbstractBaseUser,PermissionsMixin):
    """用户表"""
    # password = models.CharField(max_length=128,null=False,verbose_name="密码")
    objects = UserManager()
    phone_num = models.CharField(max_length=16,null=False,verbose_name="电话号")
    company = models.CharField(max_length=32,verbose_name="公司名")
    username = models.CharField(max_length=32,verbose_name="姓名",null=False)
    email = models.CharField(max_length=24,verbose_name="邮箱",null=False)
    userID = models.IntegerField(verbose_name="用户ID
  • 0
    点赞
  • 3
    收藏
    觉得还不错? 一键收藏
  • 1
    评论
好的,下面是基于Python DjangoJWT的Web用户管理系统的开发步骤: 1. 创建Django项目 在命令行中输入以下命令来创建Django项目: ``` django-admin startproject user_management_system ``` 2. 创建Django应用程序 在命令行中输入以下命令来创建Django应用程序: ``` python manage.py startapp users ``` 3. 配置Django应用程序 在settings.py文件中添加以下应用程序和数据库的配置: ```python INSTALLED_APPS = [ 'users', 'rest_framework', 'rest_framework.authtoken', ] DATABASES = { 'default': { 'ENGINE': 'django.db.backends.postgresql', 'NAME': 'user_management_system', 'USER': 'postgres', 'PASSWORD': 'password', 'HOST': 'localhost', 'PORT': '5432', } } ``` 4. 创建模型 在models.py文件中创建用户模型: ```python from django.db import models from django.contrib.auth.models import AbstractBaseUser, BaseUserManager, PermissionsMixin class UserManager(BaseUserManager): def create_user(self, email, password=None): if not email: raise ValueError('Users must have an email address') user = self.model( email=self.normalize_email(email), ) user.set_password(password) user.save(using=self._db) return user def create_superuser(self, email, password): user = self.create_user( email, password=password, ) user.is_admin = True user.save(using=self._db) return user class User(AbstractBaseUser, PermissionsMixin): email = models.EmailField( verbose_name='email address', max_length=255, unique=True, ) is_active = models.BooleanField(default=True) is_admin = models.BooleanField(default=False) objects = UserManager() USERNAME_FIELD = 'email' REQUIRED_FIELDS = [] def __str__(self): return self.email def has_perm(self, perm, obj=None): return True def has_module_perms(self, app_label): return True @property def is_staff(self): return self.is_admin ``` 5. 配置REST框架 在settings.py文件中添加以下REST框架的配置: ```python REST_FRAMEWORK = { 'DEFAULT_AUTHENTICATION_CLASSES': ( 'rest_framework.authentication.TokenAuthentication', 'rest_framework_simplejwt.authentication.JWTAuthentication', ), 'DEFAULT_PERMISSION_CLASSES': ( 'rest_framework.permissions.IsAuthenticated', ), } ``` 6. 配置JWT 在settings.py文件中添加以下JWT的配置: ```python from datetime import timedelta SIMPLE_JWT = { 'ACCESS_TOKEN_LIFETIME': timedelta(minutes=60), 'REFRESH_TOKEN_LIFETIME': timedelta(days=1), 'ROTATE_REFRESH_TOKENS': True, 'BLACKLIST_AFTER_ROTATION': True, 'ALGORITHM': 'HS256', 'SIGNING_KEY': 'secret_key', 'VERIFYING_KEY': None, 'AUDIENCE': None, 'ISSUER': None, 'AUTH_HEADER_TYPES': ('Bearer',), 'AUTH_HEADER_NAME': 'HTTP_AUTHORIZATION', 'USER_ID_FIELD': 'id', 'USER_ID_CLAIM': 'user_id', 'JTI_CLAIM': 'jti', 'SLIDING_TOKEN_REFRESH_EXP_CLAIM': 'refresh_exp', 'SLIDING_TOKEN_LIFETIME': timedelta(minutes=5), 'SLIDING_TOKEN_REFRESH_LIFETIME': timedelta(days=1), } ``` 7. 创建视图 在views.py文件中创建视图: ```python from rest_framework.views import APIView from rest_framework.response import Response from rest_framework import status from rest_framework.permissions import IsAuthenticated from rest_framework.decorators import api_view, permission_classes from rest_framework_simplejwt.views import TokenObtainPairView, TokenRefreshView from rest_framework_simplejwt.authentication import JWTAuthentication from rest_framework_simplejwt.exceptions import InvalidToken, TokenError from django.contrib.auth import authenticate from django.contrib.auth.models import update_last_login from .serializers import UserSerializer from .models import User class UserRegistrationView(APIView): def post(self, request): serializer = UserSerializer(data=request.data) if serializer.is_valid(): serializer.save() return Response(serializer.data, status=status.HTTP_201_CREATED) return Response(serializer.errors, status=status.HTTP_400_BAD_REQUEST) class UserLoginView(TokenObtainPairView): def post(self, request, *args, **kwargs): try: email = request.data['email'] password = request.data['password'] user = authenticate(email=email, password=password) if user is None: return Response({'error': 'Invalid email or password'}, status=status.HTTP_400_BAD_REQUEST) refresh = self.get_token(user) update_last_login(None, user) return Response({ 'access': str(refresh.access_token), 'refresh': str(refresh), }) except KeyError: return Response({'error': 'Email and password are required'}, status=status.HTTP_400_BAD_REQUEST) class UserRefreshTokenView(TokenRefreshView): pass class UserDetailView(APIView): permission_classes = (IsAuthenticated,) authentication_classes = (JWTAuthentication,) def get(self, request): serializer = UserSerializer(request.user) return Response(serializer.data) ``` 8. 创建序列化器 在serializers.py文件中创建用户序列化器: ```python from rest_framework import serializers from .models import User class UserSerializer(serializers.ModelSerializer): class Meta: model = User fields = ('id', 'email', 'password') extra_kwargs = {'password': {'write_only': True}} def create(self, validated_data): user = User.objects.create_user( email=validated_data['email'], password=validated_data['password'], ) return user ``` 9. 配置URL 在urls.py文件中配置URL: ```python from django.urls import path from .views import UserRegistrationView, UserLoginView, UserRefreshTokenView, UserDetailView urlpatterns = [ path('register/', UserRegistrationView.as_view(), name='register'), path('login/', UserLoginView.as_view(), name='login'), path('refresh_token/', UserRefreshTokenView.as_view(), name='refresh_token'), path('user_detail/', UserDetailView.as_view(), name='user_detail'), ] ``` 10. 运行服务器 在命令行中输入以下命令来运行服务器: ``` python manage.py runserver ``` 现在,您可以使用Postman或其他HTTP客户端来测试API。在请求头中传递JWT令牌以验证用户身份。 希望这个简单的Django JWT用户管理系统可以帮助到您!
评论 1
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值