You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

已通过JWT验证的Django API仍执行用户数据库查询问题求助

解决JWT认证时不必要的用户数据库查询问题

问题原因

DRF的JWT认证组件(如djangorestframework-simplejwt)默认逻辑是:验证Token有效性后,会从数据库查询对应User实例并赋值给request.user。即使视图中没有用到用户信息,IsAuthenticated权限类会触发对request.user的访问,进而触发数据库查询——因为默认的User实例是关联数据库的惰性对象,访问时会拉取完整数据。

解决方案

方案1:自定义JWT认证后端,跳过数据库查询

重写JWT认证的get_user方法,直接从Token的payload中提取信息构建一个虚拟User实例,避免查询数据库:

from rest_framework_simplejwt.authentication import JWTAuthentication
from django.contrib.auth.models import User

class NoDBJWTAuthentication(JWTAuthentication):
    def get_user(self, validated_token):
        # 从Token payload中提取用户ID
        user_id = validated_token.get('user_id')
        # 创建不关联数据库的User实例,仅设置必要属性
        user = User()
        user.id = user_id
        user.is_authenticated = True
        # 若payload中包含其他字段(如username),可直接赋值
        if 'username' in validated_token:
            user.username = validated_token['username']
        return user

在项目settings.py中替换默认的JWT认证类:

REST_FRAMEWORK = {
    'DEFAULT_AUTHENTICATION_CLASSES': [
        'your_app.utils.authentication.NoDBJWTAuthentication',  # 替换为你的类路径
    ],
}

方案2:自定义权限类,仅验证Token有效性

如果不需要request.user实例,可直接自定义权限类,跳过用户实例的获取,只验证Token是否有效:

from rest_framework.permissions import BasePermission
from rest_framework_simplejwt.authentication import JWTAuthentication
from rest_framework.exceptions import AuthenticationFailed

class JWTAuthenticatedOnly(BasePermission):
    def has_permission(self, request, view):
        auth = JWTAuthentication()
        try:
            # 仅验证Token有效性,不获取用户实例
            auth.authenticate(request)
            return True
        except AuthenticationFailed:
            return False

在视图中使用这个权限类替代IsAuthenticated:

class TestView(ViewSet):
    permission_classes = (JWTAuthenticatedOnly,)
    def list(self, request):
        return Response({'Key': 'Test '})

注意事项

  • 若后续业务需要用户的其他字段,建议在生成JWT时将这些字段写入payload,直接从validated_token中提取,避免查询数据库。
  • 确保JWT的签名和有效期验证逻辑正常,保障认证安全性。

内容的提问来源于stack exchange,提问作者Anu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.06 13:25:23