← Back to Django Course | Chapter 10: Authentication & Authorization | Lesson 1 of 12

Django के Auth System का परिचय

Django एक built-in security guard के साथ आता है जो पहले से जानता है कि IDs कैसे check करनी, visitors को कैसे याद रखना, और doors कैसे lock करनी हैं, इसलिए आपको खुद एक बनाना नहीं पड़ता।

django.contrib.auth क्या Provide करता है

Django का auth app एक User model, login/logout views, password hashing, permissions, और groups out of the box प्रदान करता है। यह हर नए project में INSTALLED_APPS में listed है।

Note: आपको शायद ही कभी authentication logic खुद लिखनी पड़े — Django ने इसे पहले से solve कर रखा है।

उदाहरण: What django.contrib.auth Provides

These are the default apps Django adds to every new project; 'django.contrib.auth' is what powers users, permissions and login.

markup
INSTALLED_APPS = [
    'django.contrib.admin',
    'django.contrib.auth',
    'django.contrib.contenttypes',
    'django.contrib.sessions',
    'django.contrib.messages',
    'django.contrib.staticfiles',
]
{# Django-only code -- models.py/views.py/urls.py/settings.py snippets, or template markup using Django template tags/variables -- can't run standalone via Judge0 or the browser preview, since it needs a real Django project. Only this course's pure-Python examples (example_lang == 'python', no Django imports) are actually runnable, so those still get the button below. #}

हर View में request.user

AuthenticationMiddleware हर incoming request पर एक user object attach करता है। अगर कोई logged in नहीं है, request.user None के बजाय एक AnonymousUser है।

Warning: MIDDLEWARE से AuthenticationMiddleware हटाना हर जगह request.user तोड़ देता है।

उदाहरण: request.user in Every View

is_authenticated is False for AnonymousUser and True for a real logged-in User, so this check never crashes.

markup
from django.http import HttpResponse

def whoami(request):
    if request.user.is_authenticated:
        return HttpResponse(f'Hello, {request.user.username}')
    return HttpResponse('Hello, anonymous visitor')
{# Django-only code -- models.py/views.py/urls.py/settings.py snippets, or template markup using Django template tags/variables -- can't run standalone via Judge0 or the browser preview, since it needs a real Django project. Only this course's pure-Python examples (example_lang == 'python', no Django imports) are actually runnable, so those still get the button below. #}

MIDDLEWARE Setting

Logins काम करने के लिए SessionMiddleware और AuthenticationMiddleware दोनों मौजूद होनी चाहिए, उस order में: sessions login store करते हैं, और auth middleware session पढ़ती है।

Note: Order मायने रखता है — AuthenticationMiddleware पहले SessionMiddleware run होने पर depend करता है।

उदाहरण: The MIDDLEWARE Setting

SessionMiddleware must come before AuthenticationMiddleware because auth reads the logged-in user id out of the session.

markup
MIDDLEWARE = [
    'django.contrib.sessions.middleware.SessionMiddleware',
    'django.contrib.auth.middleware.AuthenticationMiddleware',
    'django.contrib.messages.middleware.MessageMiddleware',
]
{# Django-only code -- models.py/views.py/urls.py/settings.py snippets, or template markup using Django template tags/variables -- can't run standalone via Judge0 or the browser preview, since it needs a real Django project. Only this course's pure-Python examples (example_lang == 'python', no Django imports) are actually runnable, so those still get the button below. #}
Related Topics
{# common_mistakes/chapter_summary/browser_support: on Hindi pages the view already swaps in the hi_ translation fields (or blanks these out if untranslated), so this renders correctly for both languages without a lang_code check here. #}
आम गलतियां
  1. यह मान लेना कि django.contrib.auth अलग से install करना होगा — यह हर नए Django project के साथ default रूप से ship होता है।
  2. Custom login/password-checking code लिखना बजाय पहले से मौजूद battle-tested auth system उपयोग करने के।
  3. यह भूल जाना कि views में request.user available होने के लिए AuthenticationMiddleware को MIDDLEWARE में रहना चाहिए।
चैप्टर सारांश
  • django.contrib.auth Django का users, passwords, sessions, और permissions के लिए built-in app है।
  • यह settings.py में INSTALLED_APPS और AuthenticationMiddleware के through default रूप से enabled है।
  • हर request को एक request.user object मिलता है — या तो एक असली logged-in User या एक AnonymousUser।
  • System password hashing, login sessions, और permission checks handle करता है इसलिए आपको इन्हें scratch से नहीं बनाना पड़ता।

Login to run this code

C/C++/Java/PHP execution requires a free account. Your code is saved — you'll land right back in the editor after logging in.