You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Django删除按钮异常:无法正确获取Post ID及权限控制错误

Django删除按钮问题修复方案

问题1:删除按钮无法正确获取对应帖子ID

原因

所有帖子的删除按钮都绑定了同一个ID为myModal的弹窗,弹窗内的删除链接固定使用了循环中某一个post.id,导致无论点击哪个按钮,都会触发同一个弹窗并删除同一篇帖子。同时模板中包含重复的完整HTML结构,会破坏页面布局逻辑。

修复步骤

  1. 为每个帖子生成唯一弹窗ID:
    给每个帖子的弹窗添加与帖子ID绑定的唯一标识,确保删除按钮只触发对应帖子的弹窗,弹窗内的删除链接也对应正确的帖子ID。
  2. 移除冗余的HTML结构:
    删除模板中重复的<html>、<head>、<body>标签,保持模板为继承自base.html的片段结构。

修改后的post.html核心代码(假设你在循环渲染帖子):

{% for post in posts %}
  <!-- 帖子内容区域 -->
  <div class="post-item">
    <h3>{{ post.title }}</h3>
    <p>{{ post.body }}</p>
    
    <!-- 删除按钮(仅作者可见,后续问题2会详细说明) -->
    {% if user.is_authenticated and user == post.author %}
      <a href="#myModal-{{ post.id }}" class="btn btn-danger btn-small" data-toggle="modal" data-target="#myModal-{{ post.id }}">
        Delete <svg xmlns="http://www.w3.org/2000/svg" width="16" height="16" fill="currentColor" class="bi bi-trash" viewBox="0 0 16 16">
          <path d="M5.5 5.5A.5.5 0 0 1 6 6v6a.5.5 0 0 1-1 0V6a.5.5 0 0 1 .5-.5Zm2.5 0a.5.5 0 0 1 .5.5v6a.5.5 0 0 1-1 0V6a.5.5 0 0 1 .5-.5Zm3 .5a.5.5 0 0 0-1 0v6a.5.5 0 0 0 1 0V6Z"/>
          <path d="M14.5 3a1 1 0 0 1-1 1H13v9a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V4h-.5a1 1 0 0 1-1-1V2a1 1 0 0 1 1-1H6a1 1 0 0 1 1-1h2a1 1 0 0 1 1 1h3.5a1 1 0 0 1 1 1v1ZM4.118 4 4 4.059V13a1 1 0 0 0 1 1h6a1 1 0 0 0 1-1V4.059L11.882 4H4.118ZM2.5 3h11V2h-11v1Z"/>
        </svg>
      </a>
    {% endif %}
  </div>

  <!-- 对应帖子的唯一弹窗 -->
  <div id="myModal-{{ post.id }}" class="modal fade">
    <div class="modal-dialog modal-confirm">
      <div class="modal-content">
        <div class="modal-header">
          <div class="icon-box"></div>                
          <h4 class="modal-title">Are you sure?</h4>    
          <button type="button" class="close" data-dismiss="modal" aria-hidden="true">&times;</button>
        </div>
        <div class="modal-body">
          <p class="text-muted">Do you really want to delete {{ post.title }}? This process cannot be undone.</p>
        </div>
        <div class="modal-footer">
          <button type="button" class="btn btn-secondary" data-dismiss="modal">Cancel</button>
          <a type="button" class="btn btn-danger" href="{% url 'delete' post.id %}">Delete</a>
        </div>
      </div>
    </div>     
  </div>
{% endfor %}

问题2:非作者用户可见删除按钮

修复方法

在模板中添加双重判断:用户已登录且当前用户是帖子的作者,才显示删除按钮,替换原来仅判断user.is_authenticated的条件:

{% if user.is_authenticated and user == post.author %}
  <!-- 删除按钮代码 -->
{% endif %}

后端安全加固

为防止恶意用户直接构造URL删除他人帖子,在delete视图中添加权限验证:

@login_required()
def delete(request, id):
    poost = get_object_or_404(post, pk=id)
    # 验证当前用户是帖子作者
    if poost.author != request.user:
        messages.error(request, "You are not authorized to delete this post.")
        return redirect("/")
    poost.delete()
    messages.error(request, f'Post deleted!')
    return redirect("/")

内容的提问来源于stack exchange,提问作者Rin Hyakuya

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 21:35:06