{"title":"Comment authentifier avec REMOTE_USER","version":"6.0","locale":"fr","docname":"howto/auth-remote-user","url":"/fr/6.0/howto/auth-remote-user/","canonical":"https://djangodocs.dev/fr/6.0/howto/auth-remote-user/","summary":"This document describes how to make use of external authentication sources in your Django applications. This type of authentication solution is typically seen on…","html":"<h1>Comment authentifier avec <code class=\"docutils literal notranslate\"><span class=\"pre\">REMOTE_USER</span></code><a class=\"heading-anchor\" href=\"#how-to-authenticate-using-remote-user\"><span class=\"visually-hidden\">Lien vers cette rubrique</span><span aria-hidden=\"true\">#</span></a></h1>\n<p>This document describes how to make use of external authentication sources in\nyour Django applications. This type of authentication solution is typically\nseen on intranet sites, with single sign-on solutions such as IIS and\nIntegrated Windows Authentication or Apache and <a class=\"reference external\" href=\"https://httpd.apache.org/docs/current/mod/mod_authnz_ldap.html\">mod_authnz_ldap</a>, <a class=\"reference external\" href=\"https://www.apereo.org/projects/cas\">CAS</a>,\n<a class=\"reference external\" href=\"https://uit.stanford.edu/service/authentication\">WebAuth</a>, <a class=\"reference external\" href=\"https://sourceforge.net/projects/mod-auth-sspi\">mod_auth_sspi</a>, etc.</p>\n<p>When the web server takes care of authentication it typically provides the\nauthenticated user as <code class=\"docutils literal notranslate\"><span class=\"pre\">REMOTE_USER</span></code>. In Django, this value is made available\nin <a class=\"reference internal\" href=\"/fr/6.0/ref/request-response/#django.http.HttpRequest.META\" title=\"django.http.HttpRequest.META\"><code class=\"xref py py-attr docutils literal notranslate\"><span class=\"pre\">request.META</span></code></a> (as <code class=\"docutils literal notranslate\"><span class=\"pre\">REMOTE_USER</span></code> when\nsupplied as an environment variable, as in WSGI, or <code class=\"docutils literal notranslate\"><span class=\"pre\">HTTP_REMOTE_USER</span></code> when\nsupplied via an HTTP header, as in ASGI). Django can be configured to make use\nof the <code class=\"docutils literal notranslate\"><span class=\"pre\">REMOTE_USER</span></code> value using the <code class=\"docutils literal notranslate\"><span class=\"pre\">RemoteUserMiddleware</span></code> or\n<code class=\"docutils literal notranslate\"><span class=\"pre\">PersistentRemoteUserMiddleware</span></code>, and\n<a class=\"reference internal\" href=\"/fr/6.0/ref/contrib/auth/#django.contrib.auth.backends.RemoteUserBackend\" title=\"django.contrib.auth.backends.RemoteUserBackend\"><code class=\"xref py py-class docutils literal notranslate\"><span class=\"pre\">RemoteUserBackend</span></code></a> classes found in\n<a class=\"reference internal\" href=\"/fr/6.0/topics/auth/#module-django.contrib.auth\" title=\"django.contrib.auth: Django's authentication framework.\"><code class=\"xref py py-mod docutils literal notranslate\"><span class=\"pre\">django.contrib.auth</span></code></a>.</p>\n<section id=\"configuration\">\n<h2>Configuration<a class=\"heading-anchor\" href=\"#configuration\"><span class=\"visually-hidden\">Lien vers cette rubrique</span><span aria-hidden=\"true\">#</span></a></h2>\n<p>Vous devez tout d’abord ajouter <a class=\"reference internal\" href=\"/fr/6.0/ref/middleware/#django.contrib.auth.middleware.RemoteUserMiddleware\" title=\"django.contrib.auth.middleware.RemoteUserMiddleware\"><code class=\"xref py py-class docutils literal notranslate\"><span class=\"pre\">django.contrib.auth.middleware.RemoteUserMiddleware</span></code></a> au réglage <a class=\"reference internal\" href=\"/fr/6.0/ref/settings/#std-setting-MIDDLEWARE\"><code class=\"xref std std-setting docutils literal notranslate\"><span class=\"pre\">MIDDLEWARE</span></code></a> <strong>après</strong> la valeur <a class=\"reference internal\" href=\"/fr/6.0/ref/middleware/#django.contrib.auth.middleware.AuthenticationMiddleware\" title=\"django.contrib.auth.middleware.AuthenticationMiddleware\"><code class=\"xref py py-class docutils literal notranslate\"><span class=\"pre\">django.contrib.auth.middleware.AuthenticationMiddleware</span></code></a> :</p>\n<div class=\"code-block\" data-language=\"default\"><div class=\"code-block-toolbar\"><span class=\"code-block-language\">Code</span><button type=\"button\" class=\"copy-button\" data-copy hidden><span class=\"copy-button-label\">Copy</span></button></div><pre role=\"group\" tabindex=\"0\" aria-label=\"Code code\"><code><span class=\"n\">MIDDLEWARE</span> <span class=\"o\">=</span> <span class=\"p\">[</span>\n    <span class=\"s2\">&quot;...&quot;</span><span class=\"p\">,</span>\n    <span class=\"s2\">&quot;django.contrib.auth.middleware.AuthenticationMiddleware&quot;</span><span class=\"p\">,</span>\n    <span class=\"s2\">&quot;django.contrib.auth.middleware.RemoteUserMiddleware&quot;</span><span class=\"p\">,</span>\n    <span class=\"s2\">&quot;...&quot;</span><span class=\"p\">,</span>\n<span class=\"p\">]</span>\n</code></pre></div>\n<p>Puis, vous devez remplacez <a class=\"reference internal\" href=\"/fr/6.0/ref/contrib/auth/#django.contrib.auth.backends.ModelBackend\" title=\"django.contrib.auth.backends.ModelBackend\"><code class=\"xref py py-class docutils literal notranslate\"><span class=\"pre\">ModelBackend</span></code></a> par <a class=\"reference internal\" href=\"/fr/6.0/ref/contrib/auth/#django.contrib.auth.backends.RemoteUserBackend\" title=\"django.contrib.auth.backends.RemoteUserBackend\"><code class=\"xref py py-class docutils literal notranslate\"><span class=\"pre\">RemoteUserBackend</span></code></a> dans le réglage <a class=\"reference internal\" href=\"/fr/6.0/ref/settings/#std-setting-AUTHENTICATION_BACKENDS\"><code class=\"xref std std-setting docutils literal notranslate\"><span class=\"pre\">AUTHENTICATION_BACKENDS</span></code></a> :</p>\n<div class=\"code-block\" data-language=\"default\"><div class=\"code-block-toolbar\"><span class=\"code-block-language\">Code</span><button type=\"button\" class=\"copy-button\" data-copy hidden><span class=\"copy-button-label\">Copy</span></button></div><pre role=\"group\" tabindex=\"0\" aria-label=\"Code code\"><code><span class=\"n\">AUTHENTICATION_BACKENDS</span> <span class=\"o\">=</span> <span class=\"p\">[</span>\n    <span class=\"s2\">&quot;django.contrib.auth.backends.RemoteUserBackend&quot;</span><span class=\"p\">,</span>\n<span class=\"p\">]</span>\n</code></pre></div>\n<p>With this setup, <code class=\"docutils literal notranslate\"><span class=\"pre\">RemoteUserMiddleware</span></code> will detect the username in\n<code class=\"docutils literal notranslate\"><span class=\"pre\">request.META['REMOTE_USER']</span></code> (or <code class=\"docutils literal notranslate\"><span class=\"pre\">request.META['HTTP_REMOTE_USER']</span></code> under\nASGI) and will authenticate and auto-login that user\nusing the <a class=\"reference internal\" href=\"/fr/6.0/ref/contrib/auth/#django.contrib.auth.backends.RemoteUserBackend\" title=\"django.contrib.auth.backends.RemoteUserBackend\"><code class=\"xref py py-class docutils literal notranslate\"><span class=\"pre\">RemoteUserBackend</span></code></a>.</p>\n<p>Soyez conscient que cette configuration particulière désactive l’authentification avec le <code class=\"docutils literal notranslate\"><span class=\"pre\">ModelBackend</span></code> par défaut. Cela signifie que si la valeur de <code class=\"docutils literal notranslate\"><span class=\"pre\">REMOTE_USER</span></code> n’est pas configurée, l’utilisateur ne parviendra pas à se connecter, même en utilisant l’interface d’administration de Django. Ajouter <code class=\"docutils literal notranslate\"><span class=\"pre\">'django.contrib.auth.backends.ModelBackend'</span></code> à la liste des <code class=\"docutils literal notranslate\"><span class=\"pre\">AUTHENTICATION_BACKENDS</span></code> utilisera <code class=\"docutils literal notranslate\"><span class=\"pre\">ModelBackend</span></code> comme solution de repli si <code class=\"docutils literal notranslate\"><span class=\"pre\">REMOTE_USER</span></code> est absent, ce qui permettra de résoudre ces problèmes.</p>\n<p>La gestion des utilisateurs de Django, tels que les vue de <code class=\"docutils literal notranslate\"><span class=\"pre\">contrib.admin</span></code> et la commande de gestion <a class=\"reference internal\" href=\"/fr/6.0/ref/django-admin/#django-admin-createsuperuser\"><code class=\"xref std std-djadmin docutils literal notranslate\"><span class=\"pre\">createsuperuser</span></code></a>, ne s’intègrent pas avec des utilisateurs distants. Ces interfaces travaillent avec les utilisateurs stockés dans la base de données indépendamment de `` AUTHENTICATION_BACKENDS``.</p>\n<aside class=\"admonition admonition-note\" role=\"note\">\n<p class=\"admonition-title\">Note</p>\n<p>Comme <code class=\"docutils literal notranslate\"><span class=\"pre\">RemoteUserBackend</span></code> hérite de <code class=\"docutils literal notranslate\"><span class=\"pre\">ModelBackend</span></code>, le contrôle des permissions implémenté dans <code class=\"docutils literal notranslate\"><span class=\"pre\">ModelBackend</span></code> est toujours disponible.</p>\n<p>Les utilisateurs avec <a class=\"reference internal\" href=\"/fr/6.0/ref/contrib/auth/#django.contrib.auth.models.User.is_active\" title=\"django.contrib.auth.models.User.is_active\"><code class=\"xref py py-attr docutils literal notranslate\"><span class=\"pre\">is_active=False</span></code></a> ne seront pas autorisés à s’authentifier. Utilisez <a class=\"reference internal\" href=\"/fr/6.0/ref/contrib/auth/#django.contrib.auth.backends.AllowAllUsersRemoteUserBackend\" title=\"django.contrib.auth.backends.AllowAllUsersRemoteUserBackend\"><code class=\"xref py py-class docutils literal notranslate\"><span class=\"pre\">AllowAllUsersRemoteUserBackend</span></code></a> si vous voulez les autoriser à se connecter.</p>\n</aside>\n<p>Si votre mécanisme d’authentification utilise un en-tête HTTP personnalisé à la place de <code class=\"docutils literal notranslate\"><span class=\"pre\">REMOTE_USER</span></code>, vous pouvez créer une sous-classe de <code class=\"docutils literal notranslate\"><span class=\"pre\">RemoteUserMiddleware</span></code> et définir l’attribut <code class=\"docutils literal notranslate\"><span class=\"pre\">header</span></code> à la clé de <code class=\"docutils literal notranslate\"><span class=\"pre\">request.META</span></code> désirée. Par exemple :</p>\n<figure class=\"code-block code-block-captioned\" data-language=\"python\"><figcaption class=\"code-block-caption\"><code class=\"docutils literal notranslate\"><span class=\"pre\">monsite/middleware.py</span></code></figcaption>\n<div class=\"code-block-toolbar\"><span class=\"code-block-language\">Python</span><button type=\"button\" class=\"copy-button\" data-copy hidden><span class=\"copy-button-label\">Copy</span></button></div><pre role=\"group\" tabindex=\"0\" aria-label=\"Python code\"><code> <span class=\"kn\">from</span><span class=\"w\"> </span><span class=\"nn\">django.contrib.auth.middleware</span><span class=\"w\"> </span><span class=\"kn\">import</span> <span class=\"n\">RemoteUserMiddleware</span>\n\n\n <span class=\"k\">class</span><span class=\"w\"> </span><span class=\"nc\">CustomHeaderRemoteUserMiddleware</span><span class=\"p\">(</span><span class=\"n\">RemoteUserMiddleware</span><span class=\"p\">):</span>\n     <span class=\"n\">header</span> <span class=\"o\">=</span> <span class=\"s2\">&quot;HTTP_AUTHUSER&quot;</span>\n</code></pre></figure>\n<p>Cet intergiciel personnalisé est alors utilisé dans le réglage <a class=\"reference internal\" href=\"/fr/6.0/ref/settings/#std-setting-MIDDLEWARE\"><code class=\"xref std std-setting docutils literal notranslate\"><span class=\"pre\">MIDDLEWARE</span></code></a> à la place de <a class=\"reference internal\" href=\"/fr/6.0/ref/middleware/#django.contrib.auth.middleware.RemoteUserMiddleware\" title=\"django.contrib.auth.middleware.RemoteUserMiddleware\"><code class=\"xref py py-class docutils literal notranslate\"><span class=\"pre\">django.contrib.auth.middleware.RemoteUserMiddleware</span></code></a>:</p>\n<div class=\"code-block\" data-language=\"default\"><div class=\"code-block-toolbar\"><span class=\"code-block-language\">Code</span><button type=\"button\" class=\"copy-button\" data-copy hidden><span class=\"copy-button-label\">Copy</span></button></div><pre role=\"group\" tabindex=\"0\" aria-label=\"Code code\"><code><span class=\"n\">MIDDLEWARE</span> <span class=\"o\">=</span> <span class=\"p\">[</span>\n    <span class=\"s2\">&quot;...&quot;</span><span class=\"p\">,</span>\n    <span class=\"s2\">&quot;django.contrib.auth.middleware.AuthenticationMiddleware&quot;</span><span class=\"p\">,</span>\n    <span class=\"s2\">&quot;mysite.middleware.CustomHeaderRemoteUserMiddleware&quot;</span><span class=\"p\">,</span>\n    <span class=\"s2\">&quot;...&quot;</span><span class=\"p\">,</span>\n<span class=\"p\">]</span>\n</code></pre></div>\n<aside class=\"admonition admonition-warning\" role=\"note\">\n<p class=\"admonition-title\">Avertissement</p>\n<p><code class=\"docutils literal notranslate\"><span class=\"pre\">RemoteUserMiddleware</span></code> must not be deployed in configurations where a\nclient can supply the header. You must be sure that your web server or\nreverse proxy always sets or strips that header based on the appropriate\nauthentication checks, never permitting an end user to submit a fake (or\n« spoofed ») header value.</p>\n<p>Comme les en-têtes HTTP <code class=\"docutils literal notranslate\"><span class=\"pre\">X-Auth-User</span></code> et <code class=\"docutils literal notranslate\"><span class=\"pre\">X-Auth_User</span></code> (par exemple) sont tous deux normalisés en <code class=\"docutils literal notranslate\"><span class=\"pre\">HTTP_X_AUTH_USER</span></code> dans <code class=\"docutils literal notranslate\"><span class=\"pre\">request.META</span></code>, vous devez aussi contrôler que votre serveur web n’autorise pas d’en-tête fabriqué qui utiliserait des soulignements à la place des tirets.</p>\n<p>Under WSGI, this warning doesn’t apply to <code class=\"docutils literal notranslate\"><span class=\"pre\">RemoteUserMiddleware</span></code> in its\ndefault configuration with <code class=\"docutils literal notranslate\"><span class=\"pre\">header</span> <span class=\"pre\">=</span> <span class=\"pre\">&quot;REMOTE_USER&quot;</span></code>, since a key that\ndoesn’t start with <code class=\"docutils literal notranslate\"><span class=\"pre\">HTTP_</span></code> in <code class=\"docutils literal notranslate\"><span class=\"pre\">request.META</span></code> can only be set by your\nWSGI server, not directly from an HTTP request header.</p>\n<p>This warning applies under ASGI in all configurations, because there is\nno equivalent for a WSGI server’s ability to place a trusted value in the\nenviron. ASGI deployments <em>must</em> use a reverse proxy as described above\nwhen using this middleware.</p>\n</aside>\n<p>Si vous avez besoin de plus de maîtrise, vous pouvez créer votre propre moteur d’authentification héritant de <a class=\"reference internal\" href=\"/fr/6.0/ref/contrib/auth/#django.contrib.auth.backends.RemoteUserBackend\" title=\"django.contrib.auth.backends.RemoteUserBackend\"><code class=\"xref py py-class docutils literal notranslate\"><span class=\"pre\">RemoteUserBackend</span></code></a> et surcharger un ou plusieurs de ses attributs et méthodes.</p>\n</section>\n<section id=\"using-remote-user-on-login-pages-only\">\n<span id=\"persistent-remote-user-middleware-howto\"></span><h2>Utilisation de <code class=\"docutils literal notranslate\"><span class=\"pre\">REMOTE_USER</span></code> uniquement pour les pages de connexion<a class=\"heading-anchor\" href=\"#using-remote-user-on-login-pages-only\"><span class=\"visually-hidden\">Lien vers cette rubrique</span><span aria-hidden=\"true\">#</span></a></h2>\n<p>L’intergiciel d’authentification <code class=\"docutils literal notranslate\"><span class=\"pre\">RemoteUserMiddleware</span></code> part du principe que l’en-tête de requête HTTP <code class=\"docutils literal notranslate\"><span class=\"pre\">REMOTE_USER</span></code> est présent pour toutes les requêtes authentifiées. C’est en général le cas lorsqu’un mécanisme du genre Basic HTTP Auth avec <code class=\"docutils literal notranslate\"><span class=\"pre\">htpasswd</span></code> est utilisé, mais avec des méthodes d’authentification comme Negotiate (GSSAPI/Kerberos) ou autres méthodes gourmandes en ressources, l’authentification au niveau du serveur HTTP frontal n’est habituellement configurée que pour une ou quelques URL de connexion ; après une authentification réussie, l’application est censé maintenir elle-même la session authentifiée.</p>\n<p><a class=\"reference internal\" href=\"/fr/6.0/ref/middleware/#django.contrib.auth.middleware.PersistentRemoteUserMiddleware\" title=\"django.contrib.auth.middleware.PersistentRemoteUserMiddleware\"><code class=\"xref py py-class docutils literal notranslate\"><span class=\"pre\">PersistentRemoteUserMiddleware</span></code></a> prend en charge ce cas d’utilisation. Il maintient la session authentifiée jusqu’à une déconnexion explicite par l’utilisateur. Cette classe peut être utilisée en remplacement de <a class=\"reference internal\" href=\"/fr/6.0/ref/middleware/#django.contrib.auth.middleware.RemoteUserMiddleware\" title=\"django.contrib.auth.middleware.RemoteUserMiddleware\"><code class=\"xref py py-class docutils literal notranslate\"><span class=\"pre\">RemoteUserMiddleware</span></code></a> dans la documentation ci-dessus sans autre modification.</p>\n</section>","rootId":"how-to-authenticate-using-remote-user","toc":[{"title":"Configuration","anchor":"configuration","children":[]},{"title":"Utilisation de REMOTE_USER uniquement pour les pages de connexion","anchor":"using-remote-user-on-login-pages-only","children":[]}],"breadcrumbs":[{"docname":"howto/index","title":"Guides pratiques","url":"/fr/6.0/howto/"}],"prev":{"docname":"howto/static-files/deployment","title":"Déploiement des fichiers statiques","url":"/fr/6.0/howto/static-files/deployment/"},"next":{"docname":"howto/csp","title":"Comment utiliser la politique de sécurité de contenu de Django","url":"/fr/6.0/howto/csp/"},"formats":{"html":"/fr/6.0/howto/auth-remote-user/","markdown":"/fr/6.0/howto/auth-remote-user.md","json":"/fr/6.0/howto/auth-remote-user.json"},"source":"https://github.com/django/django/blob/stable/6.0.x/docs/howto/auth-remote-user.txt","official":"https://docs.djangoproject.com/fr/6.0/howto/auth-remote-user/","inVersions":["6.1","6.0","5.2","5.1","5.0","4.2","4.1","4.0","3.2","3.1","3.0","2.2","2.1","2.0","1.11","1.10","1.9"],"inLocales":["en","sv","zh-hans","ga","fr","ja","id","it","pt-br","ko","es","el","pl"]}