← Back to Django Course | Chapter 10: Authentication & Authorization | Lesson 3 of 12

Login View Setup करना

एक login view एक bouncer जैसा है जो आपका username और password check करता है party में let in करने से पहले।
Syntax
markup
from django.contrib.auth import authenticate, login

def login_view(request):
    if request.method == 'POST':
        user = authenticate(request, username=username, password=password)
        if user is not None:
            login(request, user)
            return redirect('url_name')
    return render(request, 'login.html')

Login View लिखना

एक login view submitted username/password पढ़ता है, इन्हें verify करने के लिए authenticate() call करता है, और session शुरू करने के लिए login() call करता है।

Note: authenticate() गलत credentials के लिए None return करता है — login() call करने से पहले हमेशा check करें।

उदाहरण: Writing the Login View

authenticate() safely checks the hashed password; login() then stores the user id in the session.

markup
from django.contrib.auth import authenticate, login
from django.shortcuts import render, redirect

def login_view(request):
    if request.method == 'POST':
        username = request.POST['username']
        password = request.POST['password']
        user = authenticate(request, username=username, password=password)
        if user is not None:
            login(request, user)
            return redirect('home')
    return render(request, 'login.html')
{# Django-only code -- models.py/views.py/urls.py/settings.py snippets, or template markup using Django template tags/variables -- can't run standalone via Judge0 or the browser preview, since it needs a real Django project. Only this course's pure-Python examples (example_lang == 'python', no Django imports) are actually runnable, so those still get the button below. #}

Login Template

Login form username और password fields उसी view पर post back करता है, protection के लिए एक CSRF token के साथ।

उदाहरण: The Login Template

Each input has a matching label and a name attribute so Django's request.POST can read username and password.

markup
<form method="post">
  {% csrf_token %}
  <label for="username">Username</label>
  <input type="text" id="username" name="username">
  <label for="password">Password</label>
  <input type="password" id="password" name="password">
  <button type="submit">Log In</button>
</form>
{# Django-only code -- models.py/views.py/urls.py/settings.py snippets, or template markup using Django template tags/variables -- can't run standalone via Judge0 or the browser preview, since it needs a real Django project. Only this course's pure-Python examples (example_lang == 'python', no Django imports) are actually runnable, so those still get the button below. #}

URL Wire करना

Login view को एक URL entry चाहिए ताकि browser /login/ तक पहुंच सके।

उदाहरण: Wiring the URL

Naming the URL login lets templates link to it with {% url login %} instead of a hardcoded path.

markup
from django.urls import path
from . import views

urlpatterns = [
    path('login/', views.login_view, name='login'),
]
{# Django-only code -- models.py/views.py/urls.py/settings.py snippets, or template markup using Django template tags/variables -- can't run standalone via Judge0 or the browser preview, since it needs a real Django project. Only this course's pure-Python examples (example_lang == 'python', no Django imports) are actually runnable, so those still get the button below. #}
Related Topics
{# common_mistakes/chapter_summary/browser_support: on Hindi pages the view already swaps in the hi_ translation fields (or blanks these out if untranslated), so this renders correctly for both languages without a lang_code check here. #}
आम गलतियां
  1. Login form template में {% csrf_token %} भूल जाना, जो Django को POST request reject करने देता है।
  2. Raw passwords को manually compare करना बजाय authenticate() call करने के, जो hashed password को correctly check करता है।
  3. Successful login के बाद redirect न करना, browser को login form resubmit करने देते हुए अगर user refresh करे।
चैप्टर सारांश
  • authenticate() एक username/password pair जांचता है और एक User या None return करता है।
  • login() उस user को current session से attach करता है ताकि वे requests में logged in रहें।
  • resubmission from refresh से बचने के लिए successful POST login के बाद हमेशा redirect करें।
  • Login templates में <form> tag के अंदर {% csrf_token %} ज़रूर शामिल होना चाहिए।

Login to run this code

C/C++/Java/PHP execution requires a free account. Your code is saved — you'll land right back in the editor after logging in.