DRF + not DRF joint authentication

Viewed 144

I'm new-ish to Django and Token based authentication and have both a multi page site from django (non-DRF) with standard allauth session-based authentication, and a react app using graphQL on DRF and JWT authentication. They are on different subdomains but use the same django/db instance.

I would like my users to be able to log in on either site and navigate to the other and still stay 'authenticated'. i.e. not have to log in again. I was thinking about trying to get my non-DRF site to use JWT, but there doesnt seem to be much online content on this that isnt DRF. Also is it even possible to provide a token cross subdomain?

Is this all a pipe dream? Can someone please point me in the best direction to solve this problem?

Thanks in advance for your time.

2 Answers

Simply use SessionAuthentication on Rest API Default Authentication classes

REST_FRAMEWORK = {
    'DEFAULT_AUTHENTICATION_CLASSES': [
.........
'rest_framework.authentication.BasicAuthentication',
'rest_framework.authentication.SessionAuthentication',
'rest_framework_simplejwt.authentication.JWTAuthentication',

..........
]
}

This will ensure you are using session Authentication which shares the session cookie along all sites for authentication with which you can use both JWT and Session authentication. But be careful because your api can also be accessed with Session Authentication.

This is not a backend issue, simply local storage or any type of Browser storage does not allow one site/domain to access the data of another. I would suggest using the DRF for all the functionality and dropping the non-DRF one, but you can append the user JWT token to the link when redirecting the user from the drf site to the non-drf site and then extract the token and set it as an auth header. please explain why you need two separate backend apps, ill recommend if their is a better way.

Related