← Back to Django Course | Chapter 10: Authentication & Authorization | Lesson 10 of 12

Session Authentication की मूल बातें

एक session दरवाज़े पर stamped एक wristband जैसा है — एक बार आप stamped हो जाएं, Django याद रखता है कि आपको allowed है बिना हर page पर आपका password पूछे।
Syntax
markup
def view_name(request):
    request.session['key'] = value
    stored = request.session.get('key', default)
    return HttpResponse('content')

Sessions कैसे काम करते हैं

जब एक user log in करता है, Django एक session record बनाता है और browser को एक sessionid cookie भेजता है। हर बाद की request उस cookie का उपयोग session ढूंढने और logged-in user पाने के लिए करती है।

उदाहरण: How Sessions Work

request.session.session_key is the same value stored in the visitor's sessionid cookie, linking the browser to server-side session data.

markup
def whoami(request):
    print(request.session.session_key)
    print(request.user)
    return render(request, 'home.html')
{# Django-only code -- models.py/views.py/urls.py/settings.py snippets, or template markup using Django template tags/variables -- can't run standalone via Judge0 or the browser preview, since it needs a real Django project. Only this course's pure-Python examples (example_lang == 'python', no Django imports) are actually runnable, so those still get the button below. #}

एक Session में Custom Data Store करना

Login state से आगे, request.session एक dictionary जैसा behave करता है जिसे आप per-visitor data के छोटे टुकड़े याद रखने के लिए उपयोग कर सकते हैं।

Warning: Session में directly बड़ा या sensitive data store न करें — इसे छोटा रखें।

उदाहरण: Storing Custom Data in a Session

Anything assigned to request.session is automatically saved and available again on the visitor's next request.

markup
def set_theme(request):
    request.session['theme'] = 'dark'
    return redirect('home')
{# Django-only code -- models.py/views.py/urls.py/settings.py snippets, or template markup using Django template tags/variables -- can't run standalone via Judge0 or the browser preview, since it needs a real Django project. Only this course's pure-Python examples (example_lang == 'python', no Django imports) are actually runnable, so those still get the button below. #}

Session Expiry Settings

SESSION_COOKIE_AGE control करता है कि एक session cookie expire होने से पहले कितने seconds तक चलता है।

उदाहरण: Session Expiry Settings

Without this setting, Django's default session cookie expires as soon as the browser is closed.

markup
SESSION_COOKIE_AGE = 1209600  # 2 weeks, in seconds
{# Django-only code -- models.py/views.py/urls.py/settings.py snippets, or template markup using Django template tags/variables -- can't run standalone via Judge0 or the browser preview, since it needs a real Django project. Only this course's pure-Python examples (example_lang == 'python', no Django imports) are actually runnable, so those still get the button below. #}
Related Topics
{# common_mistakes/chapter_summary/browser_support: on Hindi pages the view already swaps in the hi_ translation fields (or blanks these out if untranslated), so this renders correctly for both languages without a lang_code check here. #}
आम गलतियां
  1. यह मान लेना कि sessions हमेशा के लिए persist करते हैं — default रूप से Django का session cookie browser बंद होने पर expire हो जाता है जब तक SESSION_COOKIE_AGE configure न किया जाए।
  2. Login state check करने के लिए manually cookies पढ़ना बजाय request.user पर भरोसा करने के, जिसे Django पहले से session से resolve करता है।
  3. यह भूल जाना कि एक device पर log out करना दूसरे devices पर sessions को अपने आप खत्म नहीं करता जब तक sessions explicitly clear न की जाएं।
चैप्टर सारांश
  • Django का session framework एक cookie में per-visitor session ID store करता है।
  • असली session data server-side (default रूप से database में) रहता है, उस session ID से keyed।
  • login() authenticated user की ID session में लिखता है; हर बाद की request इसे AuthenticationMiddleware के through वापस पढ़ती है।
  • Sessions ही हैं जो request.user को कई page loads में populated रहने देते हैं।

Login to run this code

C/C++/Java/PHP execution requires a free account. Your code is saved — you'll land right back in the editor after logging in.