{"title":"Uwierzytelnienie przy użyciu REMOTE_USER","version":"6.1","locale":"pl","docname":"howto/auth-remote-user","url":"/pl/6.1/howto/auth-remote-user/","canonical":"https://djangodocs.dev/pl/6.1/howto/auth-remote-user/","summary":"This document describes how to make use of external authentication sources in your Django applications. This type of authentication solution is typically seen on…","html":"<h1>Uwierzytelnienie przy użyciu <code class=\"docutils literal notranslate\"><span class=\"pre\">REMOTE_USER</span></code><a class=\"heading-anchor\" href=\"#how-to-authenticate-using-remote-user\"><span class=\"visually-hidden\">Link to this heading</span><span aria-hidden=\"true\">#</span></a></h1>\n<p>This document describes how to make use of external authentication sources in\nyour Django applications. This type of authentication solution is typically\nseen on intranet sites, with single sign-on solutions such as IIS and\nIntegrated Windows Authentication or Apache and <a class=\"reference external\" href=\"https://httpd.apache.org/docs/current/mod/mod_authnz_ldap.html\">mod_authnz_ldap</a>, <a class=\"reference external\" href=\"https://www.apereo.org/projects/cas\">CAS</a>,\n<a class=\"reference external\" href=\"https://uit.stanford.edu/service/authentication\">WebAuth</a>, <a class=\"reference external\" href=\"https://sourceforge.net/projects/mod-auth-sspi\">mod_auth_sspi</a>, etc.</p>\n<p>When the web server takes care of authentication it typically provides the\nauthenticated user as <code class=\"docutils literal notranslate\"><span class=\"pre\">REMOTE_USER</span></code>. In Django, this value is made available\nin <a class=\"reference internal\" href=\"/pl/6.1/ref/request-response/#django.http.HttpRequest.META\" title=\"django.http.HttpRequest.META\"><code class=\"xref py py-attr docutils literal notranslate\"><span class=\"pre\">request.META</span></code></a> (as <code class=\"docutils literal notranslate\"><span class=\"pre\">REMOTE_USER</span></code> when\nsupplied as an environment variable, as in WSGI, or <code class=\"docutils literal notranslate\"><span class=\"pre\">HTTP_REMOTE_USER</span></code> when\nsupplied via an HTTP header, as in ASGI). Django can be configured to make use\nof the <code class=\"docutils literal notranslate\"><span class=\"pre\">REMOTE_USER</span></code> value using the <code class=\"docutils literal notranslate\"><span class=\"pre\">RemoteUserMiddleware</span></code> or\n<code class=\"docutils literal notranslate\"><span class=\"pre\">PersistentRemoteUserMiddleware</span></code>, and\n<a class=\"reference internal\" href=\"/pl/6.1/ref/contrib/auth/#django.contrib.auth.backends.RemoteUserBackend\" title=\"django.contrib.auth.backends.RemoteUserBackend\"><code class=\"xref py py-class docutils literal notranslate\"><span class=\"pre\">RemoteUserBackend</span></code></a> classes found in\n<a class=\"reference internal\" href=\"/pl/6.1/topics/auth/#module-django.contrib.auth\" title=\"django.contrib.auth: Django's authentication framework.\"><code class=\"xref py py-mod docutils literal notranslate\"><span class=\"pre\">django.contrib.auth</span></code></a>.</p>\n<section id=\"configuration\">\n<h2>Konfiguracja<a class=\"heading-anchor\" href=\"#configuration\"><span class=\"visually-hidden\">Link to this heading</span><span aria-hidden=\"true\">#</span></a></h2>\n<p>Najpierw musisz dodać <a class=\"reference internal\" href=\"/pl/6.1/ref/middleware/#django.contrib.auth.middleware.RemoteUserMiddleware\" title=\"django.contrib.auth.middleware.RemoteUserMiddleware\"><code class=\"xref py py-class docutils literal notranslate\"><span class=\"pre\">django.contrib.auth.middleware.RemoteUserMiddleware</span></code></a> do ustawienia <a class=\"reference internal\" href=\"/pl/6.1/ref/settings/#std-setting-MIDDLEWARE\"><code class=\"xref std std-setting docutils literal notranslate\"><span class=\"pre\">MIDDLEWARE</span></code></a> <strong>po</strong> <a class=\"reference internal\" href=\"/pl/6.1/ref/middleware/#django.contrib.auth.middleware.AuthenticationMiddleware\" title=\"django.contrib.auth.middleware.AuthenticationMiddleware\"><code class=\"xref py py-class docutils literal notranslate\"><span class=\"pre\">django.contrib.auth.middleware.AuthenticationMiddleware</span></code></a>:</p>\n<div class=\"code-block\" data-language=\"default\"><div class=\"code-block-toolbar\"><span class=\"code-block-language\">Code</span><button type=\"button\" class=\"copy-button\" data-copy hidden><span class=\"copy-button-label\">Copy</span></button></div><pre role=\"group\" tabindex=\"0\" aria-label=\"Code code\"><code><span class=\"n\">MIDDLEWARE</span> <span class=\"o\">=</span> <span class=\"p\">[</span>\n    <span class=\"s2\">&quot;...&quot;</span><span class=\"p\">,</span>\n    <span class=\"s2\">&quot;django.contrib.auth.middleware.AuthenticationMiddleware&quot;</span><span class=\"p\">,</span>\n    <span class=\"s2\">&quot;django.contrib.auth.middleware.RemoteUserMiddleware&quot;</span><span class=\"p\">,</span>\n    <span class=\"s2\">&quot;...&quot;</span><span class=\"p\">,</span>\n<span class=\"p\">]</span>\n</code></pre></div>\n<p>Następnie musisz zamienić <a class=\"reference internal\" href=\"/pl/6.1/ref/contrib/auth/#django.contrib.auth.backends.ModelBackend\" title=\"django.contrib.auth.backends.ModelBackend\"><code class=\"xref py py-class docutils literal notranslate\"><span class=\"pre\">ModelBackend</span></code></a> na <a class=\"reference internal\" href=\"/pl/6.1/ref/contrib/auth/#django.contrib.auth.backends.RemoteUserBackend\" title=\"django.contrib.auth.backends.RemoteUserBackend\"><code class=\"xref py py-class docutils literal notranslate\"><span class=\"pre\">RemoteUserBackend</span></code></a> w ustawieniu <a class=\"reference internal\" href=\"/pl/6.1/ref/settings/#std-setting-AUTHENTICATION_BACKENDS\"><code class=\"xref std std-setting docutils literal notranslate\"><span class=\"pre\">AUTHENTICATION_BACKENDS</span></code></a>:</p>\n<div class=\"code-block\" data-language=\"default\"><div class=\"code-block-toolbar\"><span class=\"code-block-language\">Code</span><button type=\"button\" class=\"copy-button\" data-copy hidden><span class=\"copy-button-label\">Copy</span></button></div><pre role=\"group\" tabindex=\"0\" aria-label=\"Code code\"><code><span class=\"n\">AUTHENTICATION_BACKENDS</span> <span class=\"o\">=</span> <span class=\"p\">[</span>\n    <span class=\"s2\">&quot;django.contrib.auth.backends.RemoteUserBackend&quot;</span><span class=\"p\">,</span>\n<span class=\"p\">]</span>\n</code></pre></div>\n<p>With this setup, <code class=\"docutils literal notranslate\"><span class=\"pre\">RemoteUserMiddleware</span></code> will detect the username in\n<code class=\"docutils literal notranslate\"><span class=\"pre\">request.META['REMOTE_USER']</span></code> (or <code class=\"docutils literal notranslate\"><span class=\"pre\">request.META['HTTP_REMOTE_USER']</span></code> under\nASGI) and will authenticate and auto-login that user\nusing the <a class=\"reference internal\" href=\"/pl/6.1/ref/contrib/auth/#django.contrib.auth.backends.RemoteUserBackend\" title=\"django.contrib.auth.backends.RemoteUserBackend\"><code class=\"xref py py-class docutils literal notranslate\"><span class=\"pre\">RemoteUserBackend</span></code></a>.</p>\n<p>Miej świadomość, że ta konkretna konfiguracja wyłącza autentykację z domyślnym <code class=\"docutils literal notranslate\"><span class=\"pre\">ModelBackend</span></code>. To oznacza, że jeśli wartość <code class=\"docutils literal notranslate\"><span class=\"pre\">REMOTE_USER</span></code> nie jest ustawiona, wtedy użytkownik nie jest w stanie się zalogować, nawet używając interfejsu panelu administracyjnego Django. Dodanie <code class=\"docutils literal notranslate\"><span class=\"pre\">'django.contrib.auth.backends.ModelBackend'</span></code> do listy <code class=\"docutils literal notranslate\"><span class=\"pre\">AUTHENTICATION_BACKENDS</span></code> będzie używać <code class=\"docutils literal notranslate\"><span class=\"pre\">ModelBackend</span></code> jako fallbacku, jeśli nie ma <code class=\"docutils literal notranslate\"><span class=\"pre\">REMOTE_USER</span></code>, co rozwiąże te problemy.</p>\n<p>Zarządzanie użytkownikami Django, tak jak widok w  <code class=\"docutils literal notranslate\"><span class=\"pre\">contrib.admin</span></code> i polecenie <a class=\"reference internal\" href=\"/pl/6.1/ref/django-admin/#django-admin-createsuperuser\"><code class=\"xref std std-djadmin docutils literal notranslate\"><span class=\"pre\">createsuperuser</span></code></a>  nie jest zintegrowane ze zdalnymi użytkownikami. Te interfejsy pracują z użytkownikami przechowywanymi w bazie bez względu na <code class=\"docutils literal notranslate\"><span class=\"pre\">AUTHENTICATION_BACKENDS</span></code>.</p>\n<aside class=\"admonition admonition-note\" role=\"note\">\n<p class=\"admonition-title\">Informacja</p>\n<p>Dopóki <code class=\"docutils literal notranslate\"><span class=\"pre\">RemoteUserBackend</span></code> dziedziczy z  <code class=\"docutils literal notranslate\"><span class=\"pre\">ModelBackend</span> <span class=\"pre\">``,</span> <span class=\"pre\">będziesz</span> <span class=\"pre\">miał</span> <span class=\"pre\">te</span> <span class=\"pre\">same</span> <span class=\"pre\">uprawnienia</span> <span class=\"pre\">zaimplementowane</span> <span class=\"pre\">w</span> <span class=\"pre\">``ModelBackend</span></code>.</p>\n<p>Użytkownicy z <a class=\"reference internal\" href=\"/pl/6.1/ref/contrib/auth/#django.contrib.auth.models.User.is_active\" title=\"django.contrib.auth.models.User.is_active\"><code class=\"xref py py-attr docutils literal notranslate\"><span class=\"pre\">is_active=False</span></code></a>  nie będą mieli przyzwolenia na uwierzetelnienie. Użyj <a class=\"reference internal\" href=\"/pl/6.1/ref/contrib/auth/#django.contrib.auth.backends.AllowAllUsersRemoteUserBackend\" title=\"django.contrib.auth.backends.AllowAllUsersRemoteUserBackend\"><code class=\"xref py py-class docutils literal notranslate\"><span class=\"pre\">AllowAllUsersRemoteUserBackend</span></code></a> jeśli chcesz na to pozwolić.</p>\n</aside>\n<p>If your authentication mechanism uses a custom HTTP header and not\n<code class=\"docutils literal notranslate\"><span class=\"pre\">REMOTE_USER</span></code>, you can subclass <code class=\"docutils literal notranslate\"><span class=\"pre\">RemoteUserMiddleware</span></code> and set the\n<code class=\"docutils literal notranslate\"><span class=\"pre\">header</span></code> attribute to the desired <code class=\"docutils literal notranslate\"><span class=\"pre\">request.META</span></code> key. For example:</p>\n<figure class=\"code-block code-block-captioned\" data-language=\"python\"><figcaption class=\"code-block-caption\"><code class=\"docutils literal notranslate\"><span class=\"pre\">mysite/middleware.py</span></code></figcaption>\n<div class=\"code-block-toolbar\"><span class=\"code-block-language\">Python</span><button type=\"button\" class=\"copy-button\" data-copy hidden><span class=\"copy-button-label\">Copy</span></button></div><pre role=\"group\" tabindex=\"0\" aria-label=\"Python code\"><code> <span class=\"kn\">from</span><span class=\"w\"> </span><span class=\"nn\">django.contrib.auth.middleware</span><span class=\"w\"> </span><span class=\"kn\">import</span> <span class=\"n\">RemoteUserMiddleware</span>\n\n\n <span class=\"k\">class</span><span class=\"w\"> </span><span class=\"nc\">CustomHeaderRemoteUserMiddleware</span><span class=\"p\">(</span><span class=\"n\">RemoteUserMiddleware</span><span class=\"p\">):</span>\n     <span class=\"n\">header</span> <span class=\"o\">=</span> <span class=\"s2\">&quot;HTTP_AUTHUSER&quot;</span>\n</code></pre></figure>\n<p>This custom middleware is then used in the <a class=\"reference internal\" href=\"/pl/6.1/ref/settings/#std-setting-MIDDLEWARE\"><code class=\"xref std std-setting docutils literal notranslate\"><span class=\"pre\">MIDDLEWARE</span></code></a> setting\ninstead of <a class=\"reference internal\" href=\"/pl/6.1/ref/middleware/#django.contrib.auth.middleware.RemoteUserMiddleware\" title=\"django.contrib.auth.middleware.RemoteUserMiddleware\"><code class=\"xref py py-class docutils literal notranslate\"><span class=\"pre\">django.contrib.auth.middleware.RemoteUserMiddleware</span></code></a>:</p>\n<div class=\"code-block\" data-language=\"default\"><div class=\"code-block-toolbar\"><span class=\"code-block-language\">Code</span><button type=\"button\" class=\"copy-button\" data-copy hidden><span class=\"copy-button-label\">Copy</span></button></div><pre role=\"group\" tabindex=\"0\" aria-label=\"Code code\"><code><span class=\"n\">MIDDLEWARE</span> <span class=\"o\">=</span> <span class=\"p\">[</span>\n    <span class=\"s2\">&quot;...&quot;</span><span class=\"p\">,</span>\n    <span class=\"s2\">&quot;django.contrib.auth.middleware.AuthenticationMiddleware&quot;</span><span class=\"p\">,</span>\n    <span class=\"s2\">&quot;mysite.middleware.CustomHeaderRemoteUserMiddleware&quot;</span><span class=\"p\">,</span>\n    <span class=\"s2\">&quot;...&quot;</span><span class=\"p\">,</span>\n<span class=\"p\">]</span>\n</code></pre></div>\n<aside class=\"admonition admonition-warning\" role=\"note\">\n<p class=\"admonition-title\">Ostrzeżenie</p>\n<p><code class=\"docutils literal notranslate\"><span class=\"pre\">RemoteUserMiddleware</span></code> must not be deployed in configurations where a\nclient can supply the header. You must be sure that your web server or\nreverse proxy always sets or strips that header based on the appropriate\nauthentication checks, never permitting an end user to submit a fake (or\n„spoofed”) header value.</p>\n<p>Since the HTTP headers <code class=\"docutils literal notranslate\"><span class=\"pre\">X-Auth-User</span></code> and <code class=\"docutils literal notranslate\"><span class=\"pre\">X-Auth_User</span></code> (for example)\nboth normalize to the <code class=\"docutils literal notranslate\"><span class=\"pre\">HTTP_X_AUTH_USER</span></code> key in <code class=\"docutils literal notranslate\"><span class=\"pre\">request.META</span></code>, you\nmust also check that your web server doesn’t allow a spoofed header using\nunderscores in place of dashes.</p>\n<p>Under WSGI, this warning doesn’t apply to <code class=\"docutils literal notranslate\"><span class=\"pre\">RemoteUserMiddleware</span></code> in its\ndefault configuration with <code class=\"docutils literal notranslate\"><span class=\"pre\">header</span> <span class=\"pre\">=</span> <span class=\"pre\">&quot;REMOTE_USER&quot;</span></code>, since a key that\ndoesn’t start with <code class=\"docutils literal notranslate\"><span class=\"pre\">HTTP_</span></code> in <code class=\"docutils literal notranslate\"><span class=\"pre\">request.META</span></code> can only be set by your\nWSGI server, not directly from an HTTP request header.</p>\n<p>This warning applies under ASGI in all configurations, because there is\nno equivalent for a WSGI server’s ability to place a trusted value in the\nenviron. ASGI deployments <em>must</em> use a reverse proxy as described above\nwhen using this middleware.</p>\n</aside>\n<p>Jeśli potrzebujesz więcej kontroli, możesz stworzyć swój własny backendowy system uwierzetelniania dziedziczący z <a class=\"reference internal\" href=\"/pl/6.1/ref/contrib/auth/#django.contrib.auth.backends.RemoteUserBackend\" title=\"django.contrib.auth.backends.RemoteUserBackend\"><code class=\"xref py py-class docutils literal notranslate\"><span class=\"pre\">RemoteUserBackend</span></code></a> i przeładowujący jeden lub więcej jego atrybutów i metod.</p>\n</section>\n<section id=\"using-remote-user-on-login-pages-only\">\n<span id=\"persistent-remote-user-middleware-howto\"></span><h2>Używaj <code class=\"docutils literal notranslate\"><span class=\"pre\">REMOTE_USER</span></code> tylko na stronach logowania<a class=\"heading-anchor\" href=\"#using-remote-user-on-login-pages-only\"><span class=\"visually-hidden\">Link to this heading</span><span aria-hidden=\"true\">#</span></a></h2>\n<p>Middleware uwierzytelniający <code class=\"docutils literal notranslate\"><span class=\"pre\">RemoteUserMiddleware</span></code> zakłada, że nagłówek <code class=\"docutils literal notranslate\"><span class=\"pre\">REMOTE_USER</span></code> żądania HTTP jest obecny we wszystkich uwierzytelnionych żądaniach. To może być oczekiwane i praktyczne, kiedy użyty jest mechanizm Basic HTTP Auth z <code class=\"docutils literal notranslate\"><span class=\"pre\">htpasswd</span></code> lub jemu podobne, ale z metodą uwierzytelnienia Negotiate (GSSAPI/Kerberos) lub innymi metodami niewrażliwymi na zasoby, uwierzytelnianie we front-endowym serwerze HTTP jest zazwyczaj tylko przygotowaniem dla jednego lub kilku URLi logowania i po udanym uwierzytelnieniu aplikacja ma za zadanie samodzielnie utrzymać uwierzytelnioną sesję.</p>\n<p><a class=\"reference internal\" href=\"/pl/6.1/ref/middleware/#django.contrib.auth.middleware.PersistentRemoteUserMiddleware\" title=\"django.contrib.auth.middleware.PersistentRemoteUserMiddleware\"><code class=\"xref py py-class docutils literal notranslate\"><span class=\"pre\">PersistentRemoteUserMiddleware</span></code></a> dostarcza wsparcia dla tego przypadku użycia. Będzie utrzymywać uwierzetelnioną sesję dopóki użytkownik wprost się nie wyloguje. Klasa może być użytka jako zamiennik <a class=\"reference internal\" href=\"/pl/6.1/ref/middleware/#django.contrib.auth.middleware.RemoteUserMiddleware\" title=\"django.contrib.auth.middleware.RemoteUserMiddleware\"><code class=\"xref py py-class docutils literal notranslate\"><span class=\"pre\">RemoteUserMiddleware</span></code></a> w powyższej dokumentacji.</p>\n</section>","rootId":"how-to-authenticate-using-remote-user","toc":[{"title":"Konfiguracja","anchor":"configuration","children":[]},{"title":"Używaj REMOTE_USER tylko na stronach logowania","anchor":"using-remote-user-on-login-pages-only","children":[]}],"breadcrumbs":[{"docname":"howto/index","title":"How-to guides","url":"/pl/6.1/howto/"}],"prev":{"docname":"howto/static-files/deployment","title":"How to deploy static files","url":"/pl/6.1/howto/static-files/deployment/"},"next":{"docname":"howto/csp","title":"How to use Django’s Content Security Policy","url":"/pl/6.1/howto/csp/"},"formats":{"html":"/pl/6.1/howto/auth-remote-user/","markdown":"/pl/6.1/howto/auth-remote-user.md","json":"/pl/6.1/howto/auth-remote-user.json"},"source":"https://github.com/django/django/blob/stable/6.1.x/docs/howto/auth-remote-user.txt","official":"https://docs.djangoproject.com/pl/6.1/howto/auth-remote-user/","inVersions":["6.1","6.0","5.2","5.1","5.0","4.2","4.1","4.0","3.2","3.1","3.0","2.2","2.1","2.0","1.11","1.10"],"inLocales":["en","sv","zh-hans","ga","fr","ja","id","it","pt-br","ko","es","el","pl"]}