I am a beginner at Django and was building a login system. I wanted to use axes with django rest framework and simpleJWT. According to the documentation for Django-Axes:
Modern versions of Django REST Framework after 3.7.0 work normally with Axes out-of-the-box and require no customization in DRF.
Now I have built a Custom User for my project who gets authenticated using my own custom authentication backend. For creating the Access and the Refresh tokens I have localhost:8000/api/loginend point which creates both the tokens and stores them as HTTPOnly cookie.
The login view is like this :
@api_view(['POST'])
@permission_classes([AllowAny])
@ensure_csrf_cookie
def login_view(request):
# print("captcha token = ", request.POST.get('g-recaptcha-response'))
Account = get_user_model()
EmailId = request.data.get('EmailId')
password = request.data.get('password')
response = Response()
if (EmailId is None) or (password is None):
raise exceptions.AuthenticationFailed('username and password required')
# get the user with the credentials provided
user = Account.objects.filter(EmailId=EmailId).first()
if not check_user_validity(user, password):
# locking the user
raise exceptions.AuthenticationFailed('The credentials are invalid')
else:
print('user is valid')
# get the token values
tokenvals = get_jwt_tokens(user)
response.set_cookie(key='refreshtoken', value=tokenvals['refresh_token'], httponly=True)
response.set_cookie(key="accesstoken", value=tokenvals['access_token'])
response.data = {
'access_token': tokenvals['access_token'],
'id': user.id
}
return response
I can refresh the access token using localhost:8000/api/Refresh endpoint.
get_jwt_token(user)returns a dictionary with both access and refresh tokens created in a customized way. It doesn't make use of any JWT Serializers or Views.
For the Login View I want to use axes to block users upon multiple invalid logins. But I have no clue how I could proceed from here on.
I followed the documentation for axes and modified the settings file like it was mentioned.
AUTHENTICATION_BACKENDS = [
# AxesBackend should be the first backend in the AUTHENTICATION_BACKENDS list.
'axes.backends.AxesBackend',
# Django ModelBackend is the default authentication backend.
'django.contrib.auth.backends.ModelBackend',
]
MIDDLEWARE = [
..
..
..
# at the end
'axes.middleware.AxesMiddleware',
]
INSTALLED_APPS = [
..
..
..
"authentication",
"axes",
]
REST_FRAMEWORK = {
'DEFAULT_AUTHENTICATION_CLASSES': [
# a custom authentication method
'authentication.authentication.SafeJWTAuthentication',
],
'DEFAULT_PERMISSION_CLASSES': (
'rest_framework.permissions.IsAuthenticated', # make all endpoints private
)
}
How can I proceed from this point onwwards? I couldn't really figure out much since I have done plenty customization..
- Also Should I include
'django.contrib.auth.backends.ModelBackend',in the Backend since I am using a custom authentication?
How can I proceed from this point onwwards?