Integrating django-axes with customized django rest framework and simpleJWT

Viewed 919

I am a beginner at Django and was building a login system. I wanted to use axes with django rest framework and simpleJWT. According to the documentation for Django-Axes:

Modern versions of Django REST Framework after 3.7.0 work normally with Axes out-of-the-box and require no customization in DRF.

Now I have built a Custom User for my project who gets authenticated using my own custom authentication backend. For creating the Access and the Refresh tokens I have localhost:8000/api/loginend point which creates both the tokens and stores them as HTTPOnly cookie. The login view is like this :

@api_view(['POST'])
@permission_classes([AllowAny])
@ensure_csrf_cookie
def login_view(request):

    # print("captcha token = ", request.POST.get('g-recaptcha-response'))

    Account = get_user_model()
    EmailId = request.data.get('EmailId')
    password = request.data.get('password')
    response = Response()
    if (EmailId is None) or (password is None):
        raise exceptions.AuthenticationFailed('username and password required')

    # get the user with the credentials provided
    user = Account.objects.filter(EmailId=EmailId).first()

    if not check_user_validity(user, password):
        # locking the user
        raise exceptions.AuthenticationFailed('The credentials are invalid')
    else:
        print('user is valid')

    # get the token values
    tokenvals = get_jwt_tokens(user)

    response.set_cookie(key='refreshtoken', value=tokenvals['refresh_token'], httponly=True)
    response.set_cookie(key="accesstoken", value=tokenvals['access_token'])
    response.data = {
        'access_token': tokenvals['access_token'],
        'id': user.id
    }

    return response

I can refresh the access token using localhost:8000/api/Refresh endpoint.

  • get_jwt_token(user) returns a dictionary with both access and refresh tokens created in a customized way. It doesn't make use of any JWT Serializers or Views.

For the Login View I want to use axes to block users upon multiple invalid logins. But I have no clue how I could proceed from here on.

I followed the documentation for axes and modified the settings file like it was mentioned.

AUTHENTICATION_BACKENDS = [
    # AxesBackend should be the first backend in the AUTHENTICATION_BACKENDS list.
    'axes.backends.AxesBackend',

    # Django ModelBackend is the default authentication backend.
    'django.contrib.auth.backends.ModelBackend',
]

MIDDLEWARE = [
    ..
    ..
    ..
# at the end 
'axes.middleware.AxesMiddleware',
]

INSTALLED_APPS = [
    ..
    ..
    ..
   "authentication",
   "axes",
]

REST_FRAMEWORK = {
    'DEFAULT_AUTHENTICATION_CLASSES': [
        # a custom authentication method
        'authentication.authentication.SafeJWTAuthentication',
    ],
    'DEFAULT_PERMISSION_CLASSES': (
        'rest_framework.permissions.IsAuthenticated',  # make all endpoints private
    )
}

How can I proceed from this point onwwards? I couldn't really figure out much since I have done plenty customization..

  • Also Should I include 'django.contrib.auth.backends.ModelBackend', in the Backend since I am using a custom authentication?

How can I proceed from this point onwwards?

0 Answers
Related