小编diw*_*arb的帖子

如何在注册时使django-rest-framework-jwt返回令牌?

我有一个基本的django休息服务,其中

  1. 注册一个人和
  2. 更新他的密码.

我想在它上面添加jwt身份验证.如果我按照教程操作,我需要在项目的urls.py中添加一个名为"api-token-auth"的新URL.但是,我不想添加这个新的url,并希望我的注册调用发送一个令牌作为响应.

这是我的代码:

serializers.py

class UserSerializer(serializers.HyperlinkedModelSerializer):
    def create(self, validated_data):
        user = User(
            username=validated_data['username']
        )
        user.set_password(validated_data['password'])
        user.save()
        return user

    def update(self, instance, validated_data):
        instance.set_password(validated_data['password'])
        instance.save()
        return instance

    class Meta:
        model = User
        fields = ('url', 'username', 'password')
        lookup_field = 'username'
        write_only_fields = ('password',)
Run Code Online (Sandbox Code Playgroud)

views.py

class UserViewSet(viewsets.ModelViewSet):
    """
    API endpoint that allows users to be viewed or edited.
    """
    queryset = User.objects.exclude(is_superuser=1)
    serializer_class = UserSerializer
    lookup_field = 'username'
Run Code Online (Sandbox Code Playgroud)
  1. 要做到这一点应该怎么做?我应该在序列化程序的create方法中调用api-auth-token吗?
  2. django-rest-framework-jwt如何处理多个身份验证令牌并正确识别哪个令牌属于哪个用户?特别是当它不在db中存储令牌时.
  3. 如何使用此身份验证机制限制用户仅查看/更新/删除其用户?
  4. 我如何使用此身份验证机制来执行任何操作.例如,如果用户想要将他的名字写入/tmp/abcd.txt.如何确保只有经过身份验证的用户才能这样做?
  5. 这种方法是否存在潜在的漏洞.如果我的应用程序要存储大量分类数据,我应该使用相同的代码吗?

python authentication django django-registration django-rest-auth

10
推荐指数
2
解决办法
9343
查看次数

如何调试在spring mvc rest中找不到的404资源?

我有一个示例spring rest mvc应用程序,它具有以下java代码:

SampleController.java

import org.apache.logging.log4j.Logger;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.util.StringUtils;
import org.springframework.web.bind.annotation.PathVariable;
import org.springframework.web.bind.annotation.RequestBody;
import org.springframework.web.bind.annotation.RequestMapping;
import org.springframework.web.bind.annotation.RequestMethod;
import org.springframework.web.bind.annotation.RequestParam;
import org.springframework.web.bind.annotation.ResponseBody;
import org.springframework.web.bind.annotation.RestController;

@RestController
@RequestMapping("sample")
public class SampleController {
        @RequestMapping(method = RequestMethod.GET, produces = "application/json")
        @ResponseBody
        public String getBatches()//@RequestParam(name = "name", required = true) String name)
        {
                return "Hello ";
        }
}
Run Code Online (Sandbox Code Playgroud)

的pom.xml

<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
    xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/maven-v4_0_0.xsd">
    <modelVersion>4.0.0</modelVersion>
    <groupId>ved</groupId>
    <artifactId>platform</artifactId>
    <packaging>war</packaging>
    <version>0.0.1-SNAPSHOT</version>
    <name>platform Maven Webapp</name>
    <url>http://maven.apache.org</url>
    <properties>
        <spring.version>4.2.1.RELEASE</spring.version>
        <jackson.version>2.6.2</jackson.version>
        <spring-boot.version>1.2.6.RELEASE</spring-boot.version>
        <filter.name>DEV</filter.name>
        <jersey.version>1.9</jersey.version>
        <base.directory>${basedir}</base.directory>
    </properties>
    <profiles>
        <profile>
            <id>local</id>
            <activation> …
Run Code Online (Sandbox Code Playgroud)

java maven spring-restcontroller spring-rest

9
推荐指数
2
解决办法
9125
查看次数

在 spring-boot 中禁用特定 url 的 Keycloak 身份验证

我的 spring-boot 服务的前端在第 3 方仪表板中呈现。该仪表板还有一个我们想要使用的通用搜索栏。现在,一旦我们实现了 Keycloak 身份验证,我们就开始面临这个搜索栏中的问题。所有其他 API 都工作正常,因为它们仅从我的前端调用,但搜索 API 由第 3 方仪表板调用。

奇怪的是,第 3 方使用 Http OPTION 方法调用我的方法,但我的端点注册为 GET。

对于临时修复,我们尝试仅禁用搜索 API 上的身份验证,但似乎根本不起作用。我的配置器是:

@KeycloakConfiguration
@Profile("!local") // in local profile InsecureLocalConfigurer must be included instead
public class KeycloakSecurityConfigurer extends KeycloakWebSecurityConfigurerAdapter {


    /**
     * Enable Keycloak configuration over Spring Boot config instead of {@code keycloak.json} file.
     *
     * @see <a href="https://www.keycloak.org/docs/latest/securing_apps/index.html#spring-boot-integration">
     * Spring Boot Integration</a>
     */
    @Bean
    @Nonnull
    public KeycloakConfigResolver keycloakConfigResolver() {
        return new KeycloakSpringBootConfigResolver();
    }

    /**
     * Registers the KeycloakAuthenticationProvider with …
Run Code Online (Sandbox Code Playgroud)

authentication spring-security spring-boot keycloak spring-rest

8
推荐指数
1
解决办法
6453
查看次数

在哪里覆盖 JWT_EXPIRATION_DELTA 以设置自定义令牌到期时间?

我正在使用 django-rest-framework-jwt 对我的 RESTful Web 服务上的用户进行身份验证。问题是每次我们发出令牌时,它都会在 5 分钟后过期。我已经浏览了以下文档 http://getblimp.github.io/django-rest-framework-jwt/#additional-settings

它说我们可以通过覆盖 JWT_EXPIRATION_DELTA 变量来覆盖这个行为,但没有告诉我们如何?我试过在项目的 settings.py 和 views.py 中覆盖它,但它不起作用。对于我们的 django-rest 应用程序,我们应该如何以及在哪里覆盖这些变量?

python django jwt django-rest-framework

3
推荐指数
2
解决办法
5754
查看次数