使用django-two-factor-auth无法访问Admin站点,如何设置管理员2FA?
Got it, I’ve run into this exact headache with django-two-factor-auth before—nothing’s more frustrating than getting locked out of your own admin because you forgot to set up 2FA for the admin user first! Here are the most reliable fixes depending on your situation:
1. Manually Create a 2FA Device via Django Shell (Permanent Fix)
This is the cleanest approach, no code changes needed, and it sets up 2FA properly for your admin user right away:
- Open your terminal, navigate to your project root, and launch the Django shell:
python manage.py shell - Import the required models and utilities:
from django.contrib.auth.models import User from two_factor.models import TOTPDevice import pyotp - Fetch your admin user (replace
adminwith your actual username):admin_user = User.objects.get(username="admin") - Generate a valid TOTP device and mark it as confirmed (so you don’t have to go through the setup flow):
# Generate a random secure key totp_key = pyotp.random_base32() # Create and save the device to the database TOTPDevice.objects.create( user=admin_user, name="Admin Device", key=totp_key, confirmed=True ) - Now open your 2FA app (like Google Authenticator, Authy) and add a new account using the
totp_keyyou just generated. Next time you log into admin, enter your regular credentials plus the 6-digit code from your app—it should work perfectly.
2. Temporarily Disable 2FA Admin Protection (Emergency Unlock)
If you need quick access to fix this through the admin UI itself, you can temporarily turn off the 2FA requirement for admin:
- Open your project’s main
urls.pyfile (the one where you configured the admin site). Look for lines that look like this:from two_factor.admin import AdminSiteOTPRequired admin.site.__class__ = AdminSiteOTPRequired - Comment out those lines to revert to the default admin site:
# from two_factor.admin import AdminSiteOTPRequired # admin.site.__class__ = AdminSiteOTPRequired - Restart your Django server. You can now log into the admin with just your regular credentials.
- Head to the admin user’s profile (or the 2FA settings page provided by django-two-factor-auth) and complete the 2FA setup normally.
- Important: Don’t forget to uncomment those lines once you’re done to re-enable 2FA protection for the admin.
3. Database Direct Edit (Last Resort for Production)
If you can’t access the shell or code (e.g., locked-out production server), you can manually insert a TOTP device record into your database:
- Connect to your project’s database (using pgAdmin, MySQL Workbench, etc.)
- Locate the
two_factor_totpdevicetable - Insert a new row with:
user_id: The ID of your admin user (find this in theauth_usertable)name: Any label (e.g., "Emergency Setup")key: A valid base32 string (you can generate one usingpyotp.random_base32()locally or a trusted online tool)confirmed: Set to1(true)created_at: Current timestamp
- Save the row, then use the
keyin your 2FA app to log in.
内容的提问来源于stack exchange,提问作者Ryan Skene
相关产品推荐
相关产品推荐

