Conas fíordheimhniú ag baint úsáide as REMOTE_USERLink to this heading
This document describes how to make use of external authentication sources in your Django applications. This type of authentication solution is typically seen on intranet sites, with single sign-on solutions such as IIS and Integrated Windows Authentication or Apache and mod_authnz_ldap, CAS, WebAuth, mod_auth_sspi, etc.
When the web server takes care of authentication it typically provides the
authenticated user as REMOTE_USER. In Django, this value is made available
in request.META (as REMOTE_USER when
supplied as an environment variable, as in WSGI, or HTTP_REMOTE_USER when
supplied via an HTTP header, as in ASGI). Django can be configured to make use
of the REMOTE_USER value using the RemoteUserMiddleware or
PersistentRemoteUserMiddleware, and
RemoteUserBackend classes found in
django.contrib.auth.
CumraíochtLink to this heading
Ar dtús, ní mór duit an:class: django.contrib.auth.middleware.remoteUserMiddleware a chur leis an socrú:setting: MIDDLEWARE **tar éis ** an:class: django.contrib.auth.middleware.AuthenticationMiddleware:
MIDDLEWARE = [
"...",
"django.contrib.auth.middleware.AuthenticationMiddleware",
"django.contrib.auth.middleware.RemoteUserMiddleware",
"...",
]
Ansin, ní mór duit:class: ~django.contrib.auth.backends.modelBackend a chur in ionad la:class: ~django.contrib.auth.backends.remoteUserBackend sa socrú: AUTHENTICATION_BACKENDS:
AUTHENTICATION_BACKENDS = [
"django.contrib.auth.backends.RemoteUserBackend",
]
With this setup, RemoteUserMiddleware will detect the username in
request.META['REMOTE_USER'] (or request.META['HTTP_REMOTE_USER'] under
ASGI) and will authenticate and auto-login that user
using the RemoteUserBackend.
Bí ar an eolas go ndíchumasaíonn an socrú áirithe seo fíordheimhniú leis an réamhshocraithe ModelBackend. Ciallaíonn sé seo mura socraítear an luach REMOTE_USER` ansin níl an t-úsáideoir in ann logáil isteach, fiú ag baint úsáide as comhéadan riaracháin Django. Ag cur `Django.contrib.auth.backends.ModelBackend' leis an liosta AUTHENTICATION_BACKENDS, úsáidfear ModelBackend mar fhillback má tá REMOTE_USER as láthair, rud a réiteoidh na saincheisteanna seo.
Ní chomhtháthaíonn bainistíocht úsáideora Django, mar shampla na tuairimí i contrib.admin ``agus an t-ordú bainistíochta: djadmin: `createsuperuser, le húsáideoirí iargúlta. Oibríonn na comhéadain seo le húsáideoirí atá stóráilte sa bhunachar sonraí beag beann ar ``AUTHENTICATION_BACKENDS`.
If your authentication mechanism uses a custom HTTP header and not
REMOTE_USER, you can subclass RemoteUserMiddleware and set the
header attribute to the desired request.META key. For example:
mysite/middleware.py from django.contrib.auth.middleware import RemoteUserMiddleware
class CustomHeaderRemoteUserMiddleware(RemoteUserMiddleware):
header = "HTTP_AUTHUSER"
This custom middleware is then used in the MIDDLEWARE setting
instead of django.contrib.auth.middleware.RemoteUserMiddleware:
MIDDLEWARE = [
"...",
"django.contrib.auth.middleware.AuthenticationMiddleware",
"mysite.middleware.CustomHeaderRemoteUserMiddleware",
"...",
]
Má theastaíonn níos mó smachta uait, is féidir leat do chúltaca fíordheimhnithe féin a chruthú a fhaigheann oidhreacht ó:class: ~django.contrib.auth.backends.remoteUserBackend agus ceann amháin nó níos mó dá thréithe agus modhanna a shárú.
Ag baint úsáide as REMOTE_USER ar leathanaigh logála isteach amháinLink to this heading
Glacann an middleware fíordheimhnithe RemoteUserMiddleware go bhfuil an ceannteideal iarratais HTTP REMOTE_USER i láthair le gach iarratas fíordheimhnithe. D'fhéadfaí súil leis sin agus praiticiúil nuair a úsáidtear Basic HTTP Auth le htpasswd nó meicníochtaí den chineál céanna, ach le Negoate (GSSAPI/KerberOS) nó modhanna fíordheimhnithe dian-acmhainní eile, de ghnáth ní bhunaítear an fíordheimhniú sa bhfreastalaí HTTP tosaigh ach le haghaidh URL amháin nó cúpla URL, agus tar éis fíordheimhniú rathúil, ceaptar an feidhmchlár an seisiún fíordheimhnithe féin a choinneáil.
PersistentRemoteUserMiddleware
provides support for this use case. It will maintain the authenticated session
until explicit logout by the user. The class can be used as a drop-in
replacement of RemoteUserMiddleware
in the documentation above.