Django Rest Framework is requiring both a session and token to make authenticated request

Viewed 51

I'm in the process of creating a REST API using Django Rest Framework for a web application made by a third party.

I'm trying to configure the REST API so that it is available using SessionAuthentication or TokenAuthentication and that the Swagger documentation (generated using drf-yasg) is available unauthenticated.

The problem I am running into at the moment is that when I send a request to my API it is requiring both a sessionid and token to be sent in the request. If I remove the token I get:

{"detail":"Invalid token."}

and if I remove the session, it redirects me to the login page of the main application. If I send it with both in the request then I get a valid response from my REST API.

My settings.py file looks like the following:

REST_FRAMEWORK = {
    'DEFAULT_PERMISSION_CLASSES': [
        'rest_framework.permissions.IsAuthenticated',
    ],
    'DEFAULT_AUTHENTICATION_CLASSES': [
        'rest_framework.authentication.TokenAuthentication',
        #'rest_framework.authentication.SessionAuthentication',
        
    ],
}

As can be seen above, even with SessionAuthentication disabled for the REST API, it still requires the session to be set. Does anyone know why it is doing this? My initial thoughts are that it's using django.contrib.auth and applying that to all views but i'm not sure, i'm a bit of a Django noob in all honesty.

The other issue I have is that I have exposed some documentation for my API using drf-yasg which I want to be available unauthenticated. My get_schema_view for this looks like:

schema_view = get_schema_view(
   openapi.Info(
      title="<redacted>",
      default_version='v1',
      description="<redacted>",
   ),
   public=True,
   permission_classes=[permissions.AllowAny],
   authentication_classes=[]
)

According to the drf-yasg documentation this should allow anyone to access the documentation but again when I try to access it I get redirected to the application login page.

0 Answers
Related