How to get unique users across multiple Django sites powered by the “sites” framework?

前端 未结 3 559
庸人自扰
庸人自扰 2020-12-04 14:57

I am building a Django site framework which will power several independent sites, all using the same apps but with their own templates. I plan to accomplish this by using mu

相关标签:
3条回答
  • 2020-12-04 15:14

    You have to know, that many people complain for Django default authorization system and privileges - it has simply rules for objects, for instances of the objects - what it means, that without writing any code it woudn't be possible.

    However, there are some authorization hooks which can helps you to achieve this goal, for example:

    Take a look there: http://code.djangoproject.com/browser/django/trunk/django/contrib/auth/models.py and for class Permission.

    You can add your own permission and define rules for them (there is a ForeignKey for User and for ContentType).

    However2, without monkeypatching/change some methods it could be difficult.

    0 讨论(0)
  • 2020-12-04 15:20

    You can plug your own authorization and authentication backends that take the site id into consideration.

    See other authentication sources on the django documentation and the authentication backends references

    Besides that, if your django source is too old, you can always modify the authenticate() or login() code yourself. After all... Isn't that one of the wonders of open source. Be aware that by doing so you may affect your compatibility with other modules.

    Hope this helps.

    0 讨论(0)
  • 2020-12-04 15:36

    The most compatible way to do this would be to create a user Profile model that includes a foreign key to the Site model, then write a custom auth backend that checks the current site against the value of that FK. Some sample code:

    Define your profile model, let's say in app/models.py:

    from django.db import models
    from django.contrib.sites.models import Site
    from django.contrib.auth.models import User
    
    class UserProfile(models.Model):
        user = models.OneToOneField(User)
        site = models.ForeignKey(Site)
    

    Write your custom auth backend, inheriting from the default one, let's say in app/auth_backend.py:

    from django.contrib.auth.backends import ModelBackend
    from django.contrib.sites.models import Site
    
    class SiteBackend(ModelBackend):
        def authenticate(self, **credentials):
            user_or_none = super(SiteBackend, self).authenticate(**credentials)
            if user_or_none and user_or_none.userprofile.site != Site.objects.get_current():
                user_or_none = None
            return user_or_none
    
        def get_user(self, user_id):
            try:
                return User.objects.get(
                    pk=user_id, userprofile__site=Site.objects.get_current())
            except User.DoesNotExist:
                return None
    

    This auth backend assumes all users have a profile; you'd need to make sure that your user creation/registration process always creates one.

    The overridden authenticate method ensures that a user can only login on the correct site. The get_user method is called on every request to fetch the user from the database based on the stored authentication information in the user's session; our override ensures that a user can't login on site A and then use that same session cookie to gain unauthorized access to site B. (Thanks to Jan Wrobel for pointing out the need to handle the latter case.)

    0 讨论(0)
提交回复
热议问题