【问题标题】:Request object has no attribute 'oauth2_error' in DRF + DOT请求对象在 DRF + DOT 中没有属性“oauth2_error”
【发布时间】:2019-10-23 17:37:08
【问题描述】:

我正在为我的 API 使用 djangorestframework 和 django-oauth-toolkit。

我有一个相当简单的用户注销视图,它支持带令牌撤销的 DOT 注销和常规 Django 会话注销:

class UserLogoutView(APIView):
    permission_classes = (IsAuthenticated,)

    @staticmethod
    def post(request):
        logout(request)

        if request.auth is None:
            return Response('OK')

        app = request.auth.application
        client_id = app.client_id
        client_secret = app.client_secret
        token = request.auth.token

        r = requests.post(settings.OAUTH_URL.format('revoke-token'), data={
            'client_id': client_id,
            'client_secret': client_secret,
            'token': token,
        })

        if r.status_code != 200:
            raise AuthenticationFailed('Failed to revoke token')

        return Response('OK')

如果令牌撤销有问题,我希望得到一个 401 错误响应,但我在服务器端得到一个错误(这是引发 AuthenticationFailed 的结果,如回溯所述):

AttributeError: 'Request' object has no attribute 'oauth2_error'

我想DRF + DOT组合的异常处理有问题,但是如何解决呢?

UPD: 我的settings.py 中与 DRF、身份验证或 DOT 相关的所有内容:

INSTALLED_APPS = [
    ...
    'rest_framework',
    'oauth2_provider',
    ...
]

MIDDLEWARE = [
    'django.middleware.security.SecurityMiddleware',
    'django.contrib.sessions.middleware.SessionMiddleware',
    'corsheaders.middleware.CorsMiddleware',
    'django.middleware.common.CommonMiddleware',
    'django.middleware.csrf.CsrfViewMiddleware',
    'django.contrib.auth.middleware.AuthenticationMiddleware',
    'django.contrib.messages.middleware.MessageMiddleware',
    'django.middleware.clickjacking.XFrameOptionsMiddleware',
]

AUTHENTICATION_BACKENDS = [
    'oauth2_provider.backends.OAuth2Backend',
    'django.contrib.auth.backends.ModelBackend',
    'guardian.backends.ObjectPermissionBackend',
]

REST_FRAMEWORK = {
    'DEFAULT_AUTHENTICATION_CLASSES': (
        'oauth2_provider.contrib.rest_framework.OAuth2Authentication',
        'rest_framework.authentication.SessionAuthentication',
    ),
}

UPD 2:我尝试从DEFAULT_AUTHENTICATION_CLASSES 中删除SessionAuthentication 并根据模块文档设置我的应用程序顺序(在oauth2_provider 之后写rest_framework),一切都没有运气。

【问题讨论】:

  • 嗯,确实很奇怪。我唯一能想到的是,包顺序的导入/包含可能不正确。您能否检查一下(以防万一)您的 settings.py 是否符合 django-oauth-toolkit.readthedocs.io/en/latest/rest-framework/… 中的要求
  • @Scircia,查看我的更新答案,我已经添加了我的设置。
  • 根据您的 settings.py 看起来您安装的应用程序的顺序(与文档相比)不正确。确保在 oauth2_provider 之后包含 rest_framework。更多关于这里的信息:stackoverflow.com/a/31925587/6809132 同样在 DEFAULT_AUTHENTICATION_CLASSES 中,您正在使用两个身份验证。您使用 rest_framework SessionAuthentication 的原因是什么?尝试评论该部分,看看这是否也可能导致问题。希望这会有所帮助,祝你好运:)
  • @Scircia,我正在使用会话身份验证来与旧应用程序兼容。至于应用程序订单——我会试试的,谢谢!
  • @Scircia,刚刚尝试更改顺序,但没有成功。我也试过删除 SessionAuthentication,同样的结果。

标签: python django django-rest-framework django-oauth


【解决方案1】:

我遇到了同样的问题并找到了解决方案:django-oauth-tookit 1.2.0 中有一个错误(请参阅https://github.com/jazzband/django-oauth-toolkit/pull/716),该错误已在 master 分支中修复。不幸的是,没有新版本,所以我不得不继承 OAuth2Authentication 并提供缺失的属性:

 def authenticate_header(self, request):
     request.oauth2_error = {}
     return super().authenticate_header(request)

【讨论】:

    猜你喜欢
    • 2023-01-22
    • 2021-06-18
    • 1970-01-01
    • 1970-01-01
    • 2014-06-26
    • 2015-08-17
    • 2023-03-26
    • 2012-08-22
    • 2018-06-20
    相关资源
    最近更新 更多