DRF Authentication की मूल बातें
In this page:
from rest_framework.permissions import IsAuthenticated
from rest_framework.views import APIView
class ViewName(APIView):
permission_classes = [IsAuthenticated]
def get(self, request):
return Response(data)
Authentication बनाम Permissions
Authentication जवाब देता है 'यह कौन है?' (जैसे एक session cookie या token जांचना)। Permissions जवाब देते हैं 'यह user क्या कर सकता है?' (जैसे सिर्फ authenticated users एक book create कर सकते हैं)। DRF इन दोनों को अलग रखता है ताकि इन्हें mix और match किया जा सके।
उदाहरण: Authentication vs Permissions
Authentication answers 'who is this?' (e.g. checking a session cookie or token). Permissions answer 'what can this user do?' (e.g. only authenticated users may create a book). DRF separates the two so they can be mixed and matched.
# Authentication: identifies the user (or None for anonymous)
# Permissions: decides whether that user may perform this action
#
# request.user -> set by authentication
# IsAuthenticated, AllowAny, IsAdminUser -> examples of permissions
{# Django-only code -- models.py/views.py/urls.py/settings.py
snippets, or template markup using Django template tags/variables
-- can't run standalone via Judge0 or the browser preview, since
it needs a real Django project. Only this course's pure-Python
examples (example_lang == 'python', no Django imports) are
actually runnable, so those still get the button below. #}
एक View पर Authentication Require करना
एक APIView पर permission_classes access restrict करता है; IsAuthenticated किसी भी request को reject करता है जो logged in नहीं है, एक 401/403 response के साथ।
उदाहरण: Requiring Authentication on a View
permission_classes on an APIView restricts access; IsAuthenticated rejects any request that isn't logged in with a 401/403 response.
from rest_framework.views import APIView
from rest_framework.permissions import IsAuthenticated
from rest_framework.response import Response
class BookListView(APIView):
permission_classes = [IsAuthenticated]
def get(self, request):
return Response({'message': f'Hello {request.user.username}'})
{# Django-only code -- models.py/views.py/urls.py/settings.py
snippets, or template markup using Django template tags/variables
-- can't run standalone via Judge0 or the browser preview, since
it needs a real Django project. Only this course's pure-Python
examples (example_lang == 'python', no Django imports) are
actually runnable, so those still get the button below. #}
Project-Wide Defaults
हर view पर permission_classes repeat करने के बजाय, settings.py में एक बार defaults set करें ताकि सारे API views authentication require करें जब तक कोई view explicitly इसे override न करे।
उदाहरण: Project-Wide Defaults
Instead of repeating permission_classes on every view, set defaults once in settings.py so all API views require authentication unless a view explicitly overrides it.
REST_FRAMEWORK = {
'DEFAULT_AUTHENTICATION_CLASSES': [
'rest_framework.authentication.SessionAuthentication',
],
'DEFAULT_PERMISSION_CLASSES': [
'rest_framework.permissions.IsAuthenticated',
],
}
{# Django-only code -- models.py/views.py/urls.py/settings.py
snippets, or template markup using Django template tags/variables
-- can't run standalone via Judge0 or the browser preview, since
it needs a real Django project. Only this course's pure-Python
examples (example_lang == 'python', no Django imports) are
actually runnable, so those still get the button below. #}
- किसी authentication class को configure किए बिना
IsAuthenticatedजैसी एक permission class enable करना, इसलिए हर request reject हो जाती है क्योंकि DRF के पास user identify करने का कोई तरीका नहीं। - यह मान लेना कि Django का session login अपने आप API endpoints protect करता है, जब DRF views को अपने खुद के
authentication_classes/permission_classesconfigure करने होते हैं। - हर view में permissions hardcode करना
settings.pyमें sensible project-wide defaults set करने के बजाय, जो endpoints के बीच inconsistent access rules की ओर ले जाता है।
- Authentication identify करता है कि request कौन कर रहा है; permissions decide करती हैं कि वह identified user क्या करने की अनुमति रखता है।
- DRF कई authentication schemes support करता है, SessionAuthentication (Django के login को reuse करता है) और TokenAuthentication (API tokens) सहित।
settings.pyमेंDEFAULT_AUTHENTICATION_CLASSESऔरDEFAULT_PERMISSION_CLASSESहर API view के लिए project-wide defaults set करते हैं।
Chapter Quiz — Complete all 6 topics to unlock
0/6 topics done
Complete these topics first: