【问题标题】:Middleware handler for Mobile and Browser API calls移动和浏览器 API 调用的中间件处理程序
【发布时间】:2015-10-20 08:47:18
【问题描述】:

我想开发一个基于 Django 的 Web 服务,我的 Web 应用程序(平台:Angular JS)和移动应用程序(平台:iOS、android、Windows Phone)将与它通信。 我的 django Web 服务应用程序仅用于处理 API 调用。出于安全原因,我选择了用于移动应用程序的 Oauth 工具包,用于 Web 会话身份验证?

用于身份验证的Settings.py,

'DEFAULT_AUTHENTICATION_CLASSES': (
    'rest_framework.authentication.SessionAuthentication',
    'oauth2_provider.ext.rest_framework.OAuth2Authentication',
),

我的问题:

  1. 如果我收到来自浏览器端的调用,我想处理基于 CSRF 的身份验证。
  2. 如果我收到来自 Native Mobile 客户端的呼叫,请调用 Oauth 身份验证。 如何区分两者,以及如何处理这种身份验证技术。

需要你的帮助!!

【问题讨论】:

    标签: django web-services django-rest-framework django-authentication


    【解决方案1】:

    您可以使用django-mobile 库来检测来自移动浏览器的请求,然后调用不同的身份验证类。

    django-mobile 库在其中定义了MobileDetectionMiddleware 和SetFlavourMiddleware 中间件类。

    MobileDetectionMiddleware 检测请求是来自移动设备还是 Web 浏览器。

    SetFlavourMiddleware 类在请求中设置flavour 属性。 flavour 有 2 个可能的值:

    'mobile' # Mobile requests
    'full' # Web requests 
    

    在中间件以某种方式选择了正确的风格之后,它被分配给request.flavour 属性。

    第 1 步:在您的应用程序中配置 django-mobile

    按照https://github.com/gregmuellegger/django-mobile#installation 中给出的步骤在您的应用程序中安装和配置django-mobile。

    配置完成后,您可以使用request.flavour 来检查请求是来自移动浏览器还是网络浏览器。

    第 2 步:创建自定义 WebSessionAuthentication 类

    由于您想将 OAuth 的 OAuth2Authentication 用于移动应用程序,将 DRF 的 SessionAuthentication 用于 Web,我们可以创建一个自定义的 WebSessionAuthentication 类,该类将继承自 DRF 的 SessionAuthentication。

    这个WebSessionAuthentication 类将不对移动请求执行任何身份验证。如果是 Web 请求,它将使用 CSRF 检查执行正确的会话身份验证。

    from rest_framework.authentication import  SessionAuthentication
    
    class WebSessionAuthentication(SessionAuthentication):
        """
        Performs session authentication for web requests
        """
    
        def authenticate(self, request):
            """
            Returns a `User` if the request session currently has a logged in user 
            and request is a web request
            Otherwise returns `None`.
            """
            underlying_request = request._request # get the underlying HttpRequest object
            if underlying_request.flavour == 'mobile': # check if mobile request
                return None # No authentication performed for mobile requests
    
            # For web requests perform DRF's original session authentication    
            return super(WebSessionAuthentication, self).authenticate(request) 
    

    第 3 步:创建自定义 MobileOAuth2Authentication 类

    MobileOAuth2Authentication 类仅对 mobile 请求执行身份验证,即具有 .flavour 为 mobile。不对web 请求执行身份验证。

    from oauth2_provider.ext.rest_framework import OAuth2Authentication
    
    class MobileOAuth2Authentication(OAuth2Authentication):
        """
        Performs outh2 authentication for mobile requests
        """
    
        def authenticate(self, request):
            """
            Returns two-tuple of (user, token) if mobile authentication succeeds,
            or None otherwise.
            """
            underlying_request = request._request # get the underlying HttpRequest object
            if underlying_request.flavour == 'full': # check if web request
                return None # No authentication performed for web requests
    
            # For mobile requests perform OAuth2's original authentication    
            return super(MobileOAuth2Authentication, self).authenticate(request) 
    

    第 4 步:在设置中定义您的身份验证类

    创建自定义WebSessionAuthentication 和MobileOuth2Authentication 身份验证类后,在您的项目设置中定义这些身份验证类。

    'DEFAULT_AUTHENTICATION_CLASSES': (
        'my_app.authentication.WebSessionAuthentication', # custom session authentication class for web requests
        'my_app.authentication.MobileOAuth2Authentication', # custom oauth2 authentication class for mobile requests
    ),
    

    【讨论】:

    • 感谢您的回复@Rahul..我将开发具有功能的本机移动应用程序..我不会使用网络浏览器..
    • 那么,您对 Web 应用程序的意图是什么?您指的是移动浏览器吗?
    • no..Web 独立应用..移动原生应用..2 个独立平台
    • 您可以使用User-Agent 标头来区分两者。独立的 Web 应用和原生应用会有不同的用户代理,您可以在代码中检查以了解请求的来源。
    猜你喜欢
    • 1970-01-01
    • 2014-10-26
    • 2011-03-29
    • 1970-01-01
    • 2011-07-07
    • 1970-01-01
    • 2013-05-22
    • 1970-01-01
    • 2021-12-08
    相关资源
    最近更新 更多