Django REST How to Hash Password Correctly

Viewed 350

I'm using dj_rest_auth to authenticate my users and there is a problem with registration. After I create a user with RegisterView that dj_rest_auth gives, django creates the user without a problem but password hashing is incorrect and thus I can not login with new created user. This is my Register View:

registerview.py

class UserRegisterAPIView(RegisterView):
    def create(self, request, *args, **kwargs):
        serializer = self.get_serializer(data=request.data)
        serializer.is_valid(raise_exception=True)
        # user.set_password(make_password(request.data.get('password'))) Didn't work
        user = self.perform_create(serializer)
        headers = self.get_success_headers(serializer.data)

        return Response(self.get_response_data(user),
                        status=status.HTTP_201_CREATED,
                        headers=headers)

    def perform_create(self, serializer):
        user = serializer.save(self.request)
        create_token(self.token_model, user, serializer)
        complete_signup(self.request._request, user,
                        allauth_settings.EMAIL_VERIFICATION,
                        None)
        return user

EDIT: These are the same password but hashed differently(First one is dj_rest_auth's register view, second one is created in admin panel) If I use the second password on other users, they successfully log in.

dj_rest_auth

django created

1 Answers

I think you have a typo in your create method.

Where you have the commented section:

user.set_password(make_password(request.data.get('password')))

It should actually be:

user.set_password(make_password(serializer.data.get('password')))

I'm not sure what the function make_password does there, but that should solve the problem.

Related