You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

DRF:如何将未通过IsAuthenticated权限的用户重定向至登录页?

更简便的实现方式

你当前的实现是可行的,但确实有更简洁的方案,无需重写整个dispatch方法,下面提供两种常用的优化方式:

方案一:重写视图的permission_denied方法

APIView内置了permission_denied方法,专门处理权限校验失败的场景,只需在视图中重写该方法,针对NotAuthenticated异常返回重定向即可,代码量大幅减少:

from rest_framework.views import APIView
from rest_framework.permissions import IsAuthenticated
from rest_framework.exceptions import NotAuthenticated
from django.shortcuts import redirect

class IndexView(APIView):
    permission_classes = [IsAuthenticated]

    def get(self, request, format=None):
        # 你的业务逻辑代码
        ...

    def permission_denied(self, request, message=None, code=None):
        # 判断是否为未认证异常
        if isinstance(request.exception, NotAuthenticated):
            return redirect("/login")
        # 其他权限异常沿用默认处理逻辑
        super().permission_denied(request, message, code)

方案二:全局异常处理器(批量生效)

如果多个视图都需要这个重定向逻辑,可以配置DRF全局异常处理器,一次性处理所有NotAuthenticated异常:

  1. 在项目工具模块(如utils.py)中定义自定义异常处理器:
from rest_framework.views import exception_handler
from rest_framework.exceptions import NotAuthenticated
from django.shortcuts import redirect

def custom_exception_handler(exc, context):
    # 先调用DRF默认异常处理器获取基础响应
    response = exception_handler(exc, context)
    
    # 捕获未认证异常,返回重定向
    if isinstance(exc, NotAuthenticated):
        return redirect("/login")
    
    # 其他异常按默认逻辑处理
    return response
  1. 在settings.py中配置DRF使用该自定义处理器:
REST_FRAMEWORK = {
    'EXCEPTION_HANDLER': '你的项目名.utils.custom_exception_handler',
}

方案一适合单个/少数视图的个性化处理,方案二适合全局统一配置,可根据实际需求选择。

内容的提问来源于stack exchange,提问作者Vlad Marchenko

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 21:55:05