You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为Django应用的python manage.py shell添加超级用户密码验证?

Add Password Protection to Django's manage.py shell

Absolutely, you can lock down access to Django's interactive shell by requiring superuser authentication before entry. The cleanest way to do this is to build a custom management command that wraps the default shell functionality with a credential check. Here's how to implement it step by step:

Step 1: Create the Command Structure

First, in one of your Django apps (preferably a core or utility app), create the following directory structure if it doesn't exist:

your_app/
├── management/
│   ├── __init__.py
│   └── commands/
│       ├── __init__.py
│       └── secure_shell.py

The empty __init__.py files tell Django this is a valid Python package containing management commands.

Step 2: Write the Secure Shell Command

Paste this code into secure_shell.py:

from django.core.management.base import CommandError
from django.contrib.auth import authenticate
from django.core.management.commands.shell import Command as ShellCommand
import getpass


class Command(ShellCommand):
    help = "Starts an interactive Django shell after validating superuser credentials"

    def handle(self, *args, **options):
        # Prompt for superuser credentials
        username = input("Enter superuser username: ")
        password = getpass.getpass("Enter superuser password: ")

        # Authenticate the user
        user = authenticate(username=username, password=password)

        # Validate superuser status
        if not user or not user.is_superuser:
            raise CommandError("Invalid superuser credentials. Access denied.")

        # If validation passes, launch the default shell
        self.stdout.write(self.style.SUCCESS(f"Welcome, {username}! Access granted."))
        super().handle(*args, **options)

What this code does:

  • Inherits from the default ShellCommand: This means you keep all the default shell features (like IPython/IPDB support, Django environment loading) without reinventing the wheel.
  • Uses getpass: Ensures the password isn't displayed as plain text when typed.
  • Django's built-in authenticate: Safely checks if the credentials are valid, and verifies the user is a superuser.
  • Throws a clear error: If credentials are invalid, the command exits immediately with a message.

Step 3: Use the Secure Shell

Run the command like you would the regular shell:

python manage.py secure_shell

You'll be prompted for your superuser username and password. If they're correct, you'll drop into the familiar Django shell environment.

Optional: Replace the Default shell Command

If you want the regular python manage.py shell to require authentication (instead of using secure_shell), just rename your command file from secure_shell.py to shell.py. Django will prioritize your custom command over the built-in one.

⚠️ Note: Be cautious with this approach—if you ever need to bypass authentication (e.g., during debugging or deployments), you'll need to temporarily rename or remove your custom command.

内容的提问来源于stack exchange,提问作者Julie Kramer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 08:40:47