from django.core.exceptions import ImproperlyConfigured
SESSION_KEY = '_auth_user_id'
BACKEND_SESSION_KEY = '_auth_user_backend'
LOGIN_URL = '/accounts/login/'
def load_backend(path):
i = path.rfind('.')
module, attr = path[:i], path[i+1:]
mod = __import__(module, '', '', [attr])
except ImportError, e:
raise ImproperlyConfigured, 'Error importing authentication backend %s: "%s"' % (module, e)
cls = getattr(mod, attr)
except AttributeError:
raise ImproperlyConfigured, 'Module "%s" does not define a "%s" authentication backend' % (module, attr)
return cls()
def get_backends():
from django.conf import settings
backends = []
for backend_path in settings.AUTHENTICATION_BACKENDS:
return backends
def authenticate(**credentials):
If the given credentials, return a user object.
for backend in get_backends():
user = backend.authenticate(**credentials)
except TypeError:
# this backend doesn't accept these credentials as arguments, try the next one.
if user is None:
# annotate the user object with the path of the backend
user.backend = str(backend.__class__)
return user
def login(request, user):
Persist a user id and a backend in the request. This way a user doesn't
have to reauthenticate on every request.
if user is None:
user = request.user
# TODO: It would be nice to support different login methods, like signed cookies.
request.session[SESSION_KEY] =
request.session[BACKEND_SESSION_KEY] = user.backend
def logout(request):
Remove the authenticated user's id from request.
del request.session[SESSION_KEY]
del request.session[BACKEND_SESSION_KEY]
def get_user(request):
from django.contrib.auth.models import AnonymousUser
user_id = request.session[SESSION_KEY]
backend_path = request.session[BACKEND_SESSION_KEY]
backend = load_backend(backend_path)
user = backend.get_user(user_id) or AnonymousUser()
except KeyError:
user = AnonymousUser()
return user

