How to authenticate against Django’s user database from ApacheLink to this heading
Since keeping multiple authentication databases in sync is a common problem when dealing with Apache, you can configure Apache to authenticate against Django’s authentication system directly. This requires Apache version >= 2.2 and mod_wsgi >= 2.0. For example, you could:
Serve static/media files directly from Apache only to authenticated users.
Authenticate access to a Subversion repository against Django users with a certain permission.
Allow certain users to connect to a WebDAV share created with mod_dav.
Autentykacja z mod_wsgiLink to this heading
Make sure that mod_wsgi is installed and activated and that you have followed the steps to set up Apache with mod_wsgi.
Next, edit your Apache configuration to add a location that you want only authenticated users to be able to view:
WSGIScriptAlias / /path/to/mysite.com/mysite/wsgi.py
WSGIPythonPath /path/to/mysite.com
WSGIProcessGroup %{GLOBAL}
WSGIApplicationGroup %{GLOBAL}
<Location "/secret">
AuthType Basic
AuthName "Top Secret"
Require valid-user
AuthBasicProvider wsgi
WSGIAuthUserScript /path/to/mysite.com/mysite/wsgi.py
</Location>
The WSGIAuthUserScript directive tells mod_wsgi to execute the
check_password function in specified wsgi script, passing the user name and
password that it receives from the prompt. In this example, the
WSGIAuthUserScript is the same as the WSGIScriptAlias that defines your
application that is created by django-admin startproject.
Finally, edit your WSGI script mysite.wsgi to tie Apache’s authentication
to your site’s authentication mechanisms by importing the check_password
function:
import os
os.environ["DJANGO_SETTINGS_MODULE"] = "mysite.settings"
from django.contrib.auth.handlers.modwsgi import check_password
from django.core.handlers.wsgi import WSGIHandler
application = WSGIHandler()
Requests beginning with /secret/ will now require a user to authenticate.
The mod_wsgi access control mechanisms documentation provides additional details and information about alternative methods of authentication.