免责声明 - 妈妈的回答应该有效。写到一半时我意识到我错了,但我仍然想向您展示我想要建议的内容。它展示了 JWT TokenAuth 变异的作用以及完全利用它的方法。
- 按照妈妈的回答建议更改内置 Django 身份验证
- 重写
graphql_jwt.decorators.token_auth 以查看两个字段,而不仅仅是一个字段
- 为 TokenMutation 编写你自己的类,在它的 mutate 函数上使用这个装饰器
类似的东西(未经测试):
def two_field_token_auth(f):
@wraps(f)
@setup_jwt_cookie
@csrf_rotation
@refresh_expiration
def wrapper(cls, root, info, password, **kwargs):
context = info.context
context._jwt_token_auth = True
username = kwargs.get('username')
email = kwargs.get('email')
user = your_auth_method(
request=context,
username=username,
email=email,
password=password,
)
if user is None:
raise exceptions.JSONWebTokenError(
_('Please enter valid credentials'),
)
if hasattr(context, 'user'):
context.user = user
result = f(cls, root, info, **kwargs)
signals.token_issued.send(sender=cls, request=context, user=user)
return maybe_thenable((context, user, result), on_token_auth_resolve)
return wrapper
class TwoFieldJWTMutation(JSONWebTokenMutation):
@classmethod
@two_field_token_auth
def mutate(cls, root, info, **kwargs):
return cls.resolve(root, info, **kwargs)
您可以找到所有必要的导入 here 和 here