【发布时间】:2019-04-07 03:45:06
【问题描述】:
我的 Django 应用无法识别管理面板中某些模型的凭据。我可以登录,查看部分模型,但对于其他一些模型,我看到以下错误消息:
{"detail":"Authentication credentials were not provided."}
有趣:我可以看到一些模型,但是当我单击“添加”添加条目时,我看到了错误消息。
除其他外,我正在使用以下库:
Django==2.0.9
django-cors-headers==2.4.0
django-extensions==2.1.3
django-storages==1.7.1
djangorestframework==3.8.2
djangorestframework-jwt==1.11.0
在我的 settings.py 中,我有以下内容:
INSTALLED_APPS = [
'django.contrib.admin',
'django.contrib.auth',
'django.contrib.contenttypes',
'django.contrib.sessions',
'django.contrib.messages',
'django.contrib.staticfiles',
'corsheaders',
'django_extensions',
'storages',
'rest_framework',
'authentication.apps.AuthenticationConfig',
'directory.apps.DirectoryConfig',
'metacontent.apps.MetacontentConfig',
]
MIDDLEWARE = [
'django.middleware.security.SecurityMiddleware',
'django.contrib.sessions.middleware.SessionMiddleware',
'django.middleware.common.CommonMiddleware',
'django.middleware.csrf.CsrfViewMiddleware',
'django.contrib.auth.middleware.AuthenticationMiddleware',
'django.contrib.messages.middleware.MessageMiddleware',
'django.middleware.clickjacking.XFrameOptionsMiddleware',
'corsheaders.middleware.CorsMiddleware',
'django.middleware.common.CommonMiddleware',
]
还有:
REST_FRAMEWORK = {
'DEFAULT_PERMISSION_CLASSES': (
#'rest_framework.permissions.IsAuthenticated', #removed for open docs access
),
'DEFAULT_AUTHENTICATION_CLASSES': (
'rest_framework_jwt.authentication.JSONWebTokenAuthentication',
'rest_framework.authentication.SessionAuthentication',
'rest_framework.authentication.BasicAuthentication',
),
'DEFAULT_RENDERER_CLASSES': (
'rest_framework.renderers.JSONRenderer',
),
'DEFAULT_PAGINATION_CLASS': 'rest_framework.pagination.LimitOffsetPagination',
'PAGE_SIZE': 100,
'DEFAULT_THROTTLE_CLASSES': (
'rest_framework.throttling.AnonRateThrottle',
),
'DEFAULT_THROTTLE_RATES': {
'anon': '1000/hour',
'user': '6000/hour',
},
}
当请求不工作时,响应的标头如下:
HTTP/1.1 401 Unauthorized
Date: Fri, 02 Nov 2018 21:50:27 GMT
Server: Apache/2.4.34 (Amazon) mod_wsgi/3.5 Python/3.6.5
Allow: GET, HEAD, OPTIONS
Vary: Origin
X-Frame-Options: SAMEORIGIN
WWW-Authenticate: JWT realm="api"
Content-Length: 58
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: application/json
当它工作时:
HTTP/1.1 200 OK
Date: Fri, 02 Nov 2018 21:50:28 GMT
Server: Apache/2.4.34 (Amazon) mod_wsgi/3.5 Python/3.6.5
Expires: Fri, 02 Nov 2018 21:50:29 GMT
Cache-Control: max-age=0, no-cache, no-store, must-revalidate
Vary: Cookie,Origin
X-Frame-Options: SAMEORIGIN
Set-Cookie: csrftoken=8Aw8toVirE5qLSt79Nhh5tDem59qLChCrZ3i7zKkLo2NzS1UZ37SVDpjl; expires=Fri, 01-Nov-2019 21:50:29 GMT; Max-Age=31449600; Path=/
Content-Length: 3876
Keep-Alive: timeout=5, max=99
Connection: Keep-Alive
Content-Type: text/html; charset=utf-8
我考虑过“WSGIPassAuthorization On”,但如果这是问题所在,它永远不会起作用。此外,我在本地主机(mac)和服务器(具有 WSGIPassAuthorization On 的 Apache)上都有问题。 我错过了什么?非常感谢您的帮助。
【问题讨论】:
-
您是否会尝试在您的
installed_apps中评论authentication.app.AuthenticationConfig并查看它的作用。 -
不能这样做,因为这是我管理用户模型的地方:-/ 我在其他项目中使用了相同的应用程序名称,它在 Python 2.7 和 Django 1.11 上运行良好,但现在使用的是 Python 3.4和 Django 2.0.9
标签: django django-rest-framework jwt