如何限制django-microsoft-auth的AuthenticateCallbackView仅对已注册账号开放?
实现django-microsoft-auth仅允许已注册用户登录
步骤1:禁用自动创建用户
首先在项目的settings.py中添加配置,关闭django-microsoft-auth自动创建新用户的功能:
MICROSOFT_AUTH_AUTO_CREATE = False
这个配置会让authenticate函数在遇到未关联的微软账号时返回None,而非自动创建新用户。
步骤2:重写AuthenticateCallbackView的_authenticate方法
创建自定义视图类,继承原有的AuthenticateCallbackView,并重写_authenticate方法,添加用户存在性检查与自定义错误提示:
from django.contrib.auth.models import User from django.contrib.auth import authenticate, login from microsoft_auth.views import AuthenticateCallbackView from microsoft_auth.utils import get_oauth2_session from django.conf import settings class RestrictedMicrosoftAuthCallbackView(AuthenticateCallbackView): def _authenticate(self, code): if "error" not in self.context["message"]: if code is None: self.context["message"] = {"error": "missing_code"} else: user = authenticate(self.request, code=code) if user is None: try: # 获取微软账号的用户信息 oauth_session = get_oauth2_session(self.request) token = oauth_session.fetch_token( "https://login.microsoftonline.com/common/oauth2/v2.0/token", code=code, client_secret=settings.MICROSOFT_AUTH_CLIENT_SECRET, ) user_data = oauth_session.get("https://graph.microsoft.com/v1.0/me").json() # 检查系统中是否存在该邮箱对应的注册用户 if not User.objects.filter(email=user_data.get("mail")).exists(): self.context["message"] = {"error": "请先注册您的账号"} else: # 邮箱存在但认证失败(比如未关联微软账号) self.context["message"] = {"error": "login_failed"} except Exception: # 网络或其他异常情况 self.context["message"] = {"error": "login_failed"} else: login(self.request, user)
步骤3:替换原有的URL配置
在项目的urls.py中,将原有的microsoft-auth回调URL替换为自定义视图:
from django.urls import path, include from .views import RestrictedMicrosoftAuthCallbackView urlpatterns = [ # 替换原有的回调路由 path('microsoft/auth/callback/', RestrictedMicrosoftAuthCallbackView.as_view(), name='microsoft_auth:callback'), # 保留微软登录的发起路由 path('microsoft/auth/', include('microsoft_auth.urls', namespace='microsoft_auth')), ]
步骤4:前端优化(可选)
为提升用户体验,在登录页面模板中仅对已登录(已注册)用户显示微软登录按钮:
{% if user.is_authenticated %} <a href="{% url 'microsoft_auth:login' %}">使用微软登录</a> {% else %} <p>请先<a href="{% url 'register' %}">注册</a>您的账号</p> {% endif %}
这样,未注册用户尝试通过微软登录时,后端会返回「请先注册您的账号」的错误提示;前端也会隐藏按钮,避免用户误操作。
内容的提问来源于stack exchange,提问作者Adrian
相关产品推荐
相关产品推荐

