2014-02-19 53 views
0

我使用的是django 1.6和django-registration 1.0。为什么django 1.6在contrib.auth.views.password_reset_confirm视图中将“form”设置为“none”?

我不得不修补Django上注册的网址,因为他们并没有公布其更新为2月19日的2014年

所有密码重置网址/看法都只是password_reset_confirm工作。

在我的主urls.py文件,我有这样的:

url(r'^accounts/', include('registration.backends.simple.urls')), 

在注册/后端/简单/ urls.py我有这样的:

from django.conf.urls import include 
from django.conf.urls import patterns 
from django.conf.urls import url 
from django.views.generic.base import TemplateView 

from registration.backends.simple.views import RegistrationView 


urlpatterns = patterns('', 
         url(r'^register/$', 
          RegistrationView.as_view(), 
          name='registration_register'), 
         url(r'^register/closed/$', 
          TemplateView.as_view(template_name='registration/registration_closed.html'), 
          name='registration_disallowed'), 
         (r'', include('registration.auth_urls')), 
         ) 

from django.contrib.auth import views as auth_views 

# THIS IS A PATCH added by me !!! 
urlpatterns = patterns('', 

     # override the default urls 
     url(r'^password/change/$', 
        auth_views.password_change, 
        name='password_change'), 
     url(r'^password/change/done/$', 
        auth_views.password_change_done, 
        name='password_change_done'), 
     url(r'^password/reset/$', 
        auth_views.password_reset, 
        name='password_reset'), 
     url(r'^password/reset/done/$', 
        auth_views.password_reset_done, 
        name='password_reset_done'), 
     url(r'^password/reset/complete/$', 
        auth_views.password_reset_complete, 
        name='password_reset_complete'), 
     url(r'^password/reset/confirm/(?P<uidb64>[0-9A-Za-z]+)-(?P<token>.+)/$', 
        auth_views.password_reset_confirm, 
        name='password_reset_confirm'), 

     # and now add the registration urls 
     url(r'', include('registration.backends.default.urls')), 
) 

Django1.6 Django的/的contrib/AUTH/views.py具有用于password_reset_confirm功能:

# Doesn't need csrf_protect since no-one can guess the URL 
@sensitive_post_parameters() 
@never_cache 
def password_reset_confirm(request, uidb64=None, token=None, 
          template_name='registration/password_reset_confirm.html', 
          token_generator=default_token_generator, 
          set_password_form=SetPasswordForm, 
          post_reset_redirect=None, 
          current_app=None, extra_context=None): 
    """ 
    View that checks the hash in a password reset link and presents a 
    form for entering a new password. 
    """ 
    UserModel = get_user_model() 
    assert uidb64 is not None and token is not None # checked by URLconf 
    if post_reset_redirect is None: 
     post_reset_redirect = reverse('password_reset_complete') 
    else: 
     post_reset_redirect = resolve_url(post_reset_redirect) 
    try: 
     uid = urlsafe_base64_decode(uidb64) 
     user = UserModel._default_manager.get(pk=uid) 
    except (TypeError, ValueError, OverflowError, UserModel.DoesNotExist): 
     user = None 

    if user is not None and token_generator.check_token(user, token): 
     validlink = True 
     if request.method == 'POST': 
      form = set_password_form(user, request.POST) 
      if form.is_valid(): 
       form.save() 
       return HttpResponseRedirect(post_reset_redirect) 
     else: 
      form = set_password_form(None) 
    else: 
     validlink = False 
     form = None 
    context = { 
     'form': form, 
     'validlink': validlink, 
    } 
    if extra_context is not None: 
     context.update(extra_context) 
    return TemplateResponse(request, template_name, context, 
          current_app=current_app) 

因此,要么token_generator.check_token(用户令牌)的返回False或用户==无。

最大的痛苦是,这只发生在我看来是随机的。所以调试是一个痛苦。有时候它会起作用({{ form }}呈现输入)并且经常失败({{ form }}呈现“无”来代替输入标记)

任何帮助将不胜感激。

+0

请问您可以复制粘贴您的确切视图代码?你的格式稍微偏离.. – karthikr

+0

@karthikr我刚刚用我自己的urls.py文件,django-registration的urls.py文件和django 1.6的contrib.auth.views.py文件中的代码更新了这个问题。 – teewuane

+0

确保'urlsafe_base64_decode(uidb64)'返回一个有效的uid。接下来,在“if user is not None”之前,如果它显示有效值,则执行“打印用户”。 – karthikr

回答

0

出于某种原因token_generator.check_token(user, token)确定时间戳/ uid已被篡改。这意味着需要生成一个新的令牌。

从模板我要检测{{ form }}是“无”。如果是这样的话,我会建立一个链接,重新启动整个过程。

{% if form != None %} 
    <div class="modal-body"> 
     <p>Type in a new password. Try not to forget this one!</p> 
     {{ form }} 
    </div> 
    <div class="modal-footer"> 
     <button type="submit" class="btn btn-primary"><span>Continue</span></button> 
    </div> 
{% else %} 
    <div class="modal-body"> 
     <p>This link has expired. You'll need to click "Reset Password" again.</p> 
     <p><a class="btn btn-primary" href="{% url 'auth_password_reset' %}">Reset Password</a></p> 
    </div> 
{% endif %} 

这很重要,因为如果你没有这个地方,django-bootstrap-form将会窒息并抛出500错误。

相关问题