简体   繁体   English

带有 JWT 用户身份验证的 Django Rest 框架(获取匿名用户)

[英]Django Rest Framework With JWT user authentication (getting anonymous user )

I am using JWT with Django to Authenticate requests from Ajax jquery .我正在使用 JWT 和 Django 来验证来自 Ajax jquery 的请求。 My Jquery is我的 Jquery 是

$.ajax({
        url: "/customerapi/get-customer-detail/",
        type: 'GET',
        // headers: {"Token": localStorage.getItem('token')},
        beforeSend: function (xhr) {
        /* Authorization header */
        xhr.setRequestHeader("Authorization", "Token " + localStorage.getItem('token'));
        xhr.setRequestHeader("X-Mobile", "false");
         },

        success: function (res) {

        }
    });

And when I get this request on server I authenticate like this当我在服务器上收到此请求时,我会像这样进行身份验证

from rest_framework.permissions import IsAuthenticated

class GetCustomerData(APIView):
    authentication_classes = (JSONWebTokenAuthentication,  )
    permission_classes = (IsAuthenticated ,)
    def get(self, request):
        try:
        Customer.objects.get(id=request.user)

here my Request.user is always anonymous.这里我的 Request.user 总是匿名的。 Why this this is happening?为什么会这样?

and my middleware classes are我的中间件类是

MIDDLEWARE = [
    'django.middleware.security.SecurityMiddleware',
    'django.contrib.sessions.middleware.SessionMiddleware',
    'django.middleware.common.CommonMiddleware',
    'django.middleware.csrf.CsrfViewMiddleware',
    'django.contrib.auth.middleware.AuthenticationMiddleware',
    'django.contrib.messages.middleware.MessageMiddleware',
    'django.middleware.clickjacking.XFrameOptionsMiddleware',

]

它应该是JWT而不是Token里面的标头值:

xhr.setRequestHeader("Authorization", "JWT " + localStorage.getItem('token'));

声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.

 
粤ICP备18138465号  © 2020-2024 STACKOOM.COM