Django删除按钮异常:无法正确获取Post ID及权限控制错误
Django删除按钮问题修复方案
问题1:删除按钮无法正确获取对应帖子ID
原因
所有帖子的删除按钮都绑定了同一个ID为myModal的弹窗,弹窗内的删除链接固定使用了循环中某一个post.id,导致无论点击哪个按钮,都会触发同一个弹窗并删除同一篇帖子。同时模板中包含重复的完整HTML结构,会破坏页面布局逻辑。
修复步骤
- 为每个帖子生成唯一弹窗ID:
给每个帖子的弹窗添加与帖子ID绑定的唯一标识,确保删除按钮只触发对应帖子的弹窗,弹窗内的删除链接也对应正确的帖子ID。 - 移除冗余的HTML结构:
删除模板中重复的<html>、<head>、<body>标签,保持模板为继承自base.html的片段结构。
修改后的post.html核心代码(假设你在循环渲染帖子):
{% for post in posts %} <!-- 帖子内容区域 --> <div class="post-item"> <h3>{{ post.title }}</h3> <p>{{ post.body }}</p> <!-- 删除按钮(仅作者可见,后续问题2会详细说明) --> {% if user.is_authenticated and user == post.author %} <a href="#myModal-{{ post.id }}" class="btn btn-danger btn-small" data-toggle="modal" data-target="#myModal-{{ post.id }}"> Delete <svg xmlns="http://www.w3.org/2000/svg" width="16" height="16" fill="currentColor" class="bi bi-trash" viewBox="0 0 16 16"> <path d="M5.5 5.5A.5.5 0 0 1 6 6v6a.5.5 0 0 1-1 0V6a.5.5 0 0 1 .5-.5Zm2.5 0a.5.5 0 0 1 .5.5v6a.5.5 0 0 1-1 0V6a.5.5 0 0 1 .5-.5Zm3 .5a.5.5 0 0 0-1 0v6a.5.5 0 0 0 1 0V6Z"/> <path d="M14.5 3a1 1 0 0 1-1 1H13v9a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V4h-.5a1 1 0 0 1-1-1V2a1 1 0 0 1 1-1H6a1 1 0 0 1 1-1h2a1 1 0 0 1 1 1h3.5a1 1 0 0 1 1 1v1ZM4.118 4 4 4.059V13a1 1 0 0 0 1 1h6a1 1 0 0 0 1-1V4.059L11.882 4H4.118ZM2.5 3h11V2h-11v1Z"/> </svg> </a> {% endif %} </div> <!-- 对应帖子的唯一弹窗 --> <div id="myModal-{{ post.id }}" class="modal fade"> <div class="modal-dialog modal-confirm"> <div class="modal-content"> <div class="modal-header"> <div class="icon-box"></div> <h4 class="modal-title">Are you sure?</h4> <button type="button" class="close" data-dismiss="modal" aria-hidden="true">×</button> </div> <div class="modal-body"> <p class="text-muted">Do you really want to delete {{ post.title }}? This process cannot be undone.</p> </div> <div class="modal-footer"> <button type="button" class="btn btn-secondary" data-dismiss="modal">Cancel</button> <a type="button" class="btn btn-danger" href="{% url 'delete' post.id %}">Delete</a> </div> </div> </div> </div> {% endfor %}
问题2:非作者用户可见删除按钮
修复方法
在模板中添加双重判断:用户已登录且当前用户是帖子的作者,才显示删除按钮,替换原来仅判断user.is_authenticated的条件:
{% if user.is_authenticated and user == post.author %} <!-- 删除按钮代码 --> {% endif %}
后端安全加固
为防止恶意用户直接构造URL删除他人帖子,在delete视图中添加权限验证:
@login_required() def delete(request, id): poost = get_object_or_404(post, pk=id) # 验证当前用户是帖子作者 if poost.author != request.user: messages.error(request, "You are not authorized to delete this post.") return redirect("/") poost.delete() messages.error(request, f'Post deleted!') return redirect("/")
内容的提问来源于stack exchange,提问作者Rin Hyakuya
相关产品推荐
相关产品推荐

