User authentication in Django

In this tutorial we’ll create a typical Django app and then we’ll utilize built-in authentication of Django in our own custom views and templates. For this tutorial you need to have Python 3 installed along with venv package. Command line instructions given here will work on any Linux, macOS or WSL in Windows. So, let’s get going…

First create a new folder:

mkdir myapp

Go inside this newly created folder:

cd myapp

(Note: From now on wards all the commands entered in this tutorial are from root position of this myapp folder.)

Create virtual environment:

python3 -m venv .env

Mount virtual environment:

source .env/bin/activate

Install Django

pip install django

The above command will install Django. Now create a project by entering following command (don’t forget the full-stop at the end):

django-admin startproject project .

Then create an app named ‘base’:

python manage.py startapp base

Amend project/settings.py as follows in order to add base app into project:

INSTALLED_APPS = [
    "base",
    # ...
]

Change project/urls.py as follows:

from django.contrib import admin
from django.urls import path, include

urlpatterns = [
    path("admin/", admin.site.urls),
    path("", include('base.urls')),
]

Then create base/urls.py by executing:

touch base/urls.py

And then insert following in base/urls.py:

from django.urls import path,include
from . import views
urlpatterns = [
    path('home', views.home, name="home"),
    path('login', views.login, name='login'),
    path('register', views.register, name='register'), 
    path('logout', views.logout_view, name='logout'),
]

Now amend base/views.py as follows:

from django.shortcuts import render, redirect
from django.contrib import messages
from django.contrib.auth import authenticate, login as auth_login, logout
from django.contrib.auth.decorators import login_required
from django.contrib.auth.models import User

@login_required
def home(request):
    return render(request, 'base/home.html')
 
def login(request):
    if request.method == "POST":
        username = request.POST.get('username')
        password = request.POST.get('password')
         
        if not User.objects.filter(username=username).exists():
            messages.error(request, 'Invalid Username')
            return redirect('/login')
         
        user = authenticate(username=username, password=password)
         
        if user is None:
            messages.error(request, "Invalid Password")
            return redirect('/login')
        else:
            auth_login(request, user)
            return redirect('/home')
     
    return render(request, 'base/login.html')
 
def register(request):
    if request.method == 'POST':
        first_name = request.POST.get('first_name')
        last_name = request.POST.get('last_name')
        username = request.POST.get('username')
        password = request.POST.get('password')
         
        user = User.objects.filter(username=username)
         
        if user.exists():
            messages.info(request, "Username already taken!")
            return redirect('/register')
         
        user = User.objects.create_user(
            first_name=first_name,
            last_name=last_name,
            username=username
        )
         
        user.set_password(password)
        user.save()
         
        messages.info(request, "Account created Successfully!")
        return redirect('/login')
     
    return render(request, 'base/register.html')

def logout_view(request):
    logout(request)
    return redirect('/login')

Populate database with migrations:

python manage.py migrate

Then create a folder for templates inside base app by executing:

mkdir base/templates/base -p

Create a file base.html inside this base/templates/base/ folder and then insert following code into the base.html:

<!DOCTYPE html>
<html lang="en">
<head>
    <meta charset="utf-8">
    <title>{% block title %}MyApp{% endblock %}</title>
    <meta name="viewport" content="width=device-width, initial-scale=1">
    <link href="https://cdn.jsdelivr.net/npm/bootstrap@5.2.3/dist/css/bootstrap.min.css" rel="stylesheet" integrity="sha384-rbsA2VBKQhggwzxH7pPCaAqO46MgnOM80zW1RWuH61DGLwZJEdK2Kadq2F9CUG65" crossorigin="anonymous">
    {% block extra_head %}{% endblock %}
</head>
<body>
    <nav class="navbar navbar-expand-lg navbar-light bg-light mb-4">
        <div class="container-fluid">
            <a class="navbar-brand" href="{% url 'home' %}">MyApp</a>
            <button class="navbar-toggler" type="button" data-bs-toggle="collapse" data-bs-target="#navbarNav"
                aria-controls="navbarNav" aria-expanded="false" aria-label="Toggle navigation">
                <span class="navbar-toggler-icon"></span>
            </button>
            <div class="collapse navbar-collapse" id="navbarNav">
                <ul class="navbar-nav">
                    <li class="nav-item">
                        <a class="nav-link" href="{% url 'register' %}">Register</a>
                    </li>
                    <li class="nav-item">
                        <a class="nav-link" href="{% url 'login' %}">Login</a>
                    </li>
                    <li class="nav-item">
                        <a class="nav-link" href="{% url 'logout' %}">Logout</a>
                    </li>
                    {% block menu_items %}{% endblock %}
                </ul>
            </div>
        </div>
    </nav>
    <div class="container">
        {% block content %}
        {% endblock %}
    </div>
    <script src="https://cdn.jsdelivr.net/npm/bootstrap@5.2.3/dist/js/bootstrap.bundle.min.js" integrity="sha384-kenU1KFdBIe4zVF0s0G1M5b4hcpxyD9F7jL+jjXkk+Q2h455rYXK/7HAuoJl+0I4" crossorigin="anonymous"></script>
    {% block extra_js %}{% endblock %}
</body>
</html>

Now create register.html inside base/templates/base/ folder and then insert following code into this register.html:

{% extends 'base/base.html' %}
{% block content %}
    <div class="container mt-5">
        <form class="col-6 mx-auto card p-3 shadow" method="post" enctype="multipart/form-data">
            {% csrf_token %} 
 
            <h1 style="text-align: center;"><span style="color: green;">Register</span></h1>
            <hr>
 
            {% if messages %}
            <div class="alert alert-primary" role="alert">
                {% for message in messages %}
                {{ message }}
                {% endfor %}
            </div>
            {% endif %}
 
            <div class="form-group">
                <label for="firstName">First name</label>
                <input type="text" class="form-control" id="firstName"
                    placeholder="Enter First name" name="first_name" required>
            </div>
 
            <div class="form-group">
                <label for="lastName">Last name</label>
                <input type="text" name="last_name" class="form-control" id="lastName"
                    placeholder="Enter Last name" required>
            </div>
 
            <div class="form-group">
                <label for="userName">Username</label>
                <input type="text" class="form-control" name="username" id="userName"
                    placeholder="Enter username" required>
            </div>
 
            <div class="form-group">
                <label for="password">Password</label>
                <input type="password" class="form-control" name="password" id="password"
                    placeholder="Password" required>
            </div>
 
            <p>Already have an account <a href="/login">Login</a> </p>
 
            <button type="submit" class="btn btn-primary">Submit</button>
        </form>
    </div>
{% endblock content %}

Similarly create login.html inside base/templates/base/ folder and then insert following code into the login.html:

{% extends 'base/base.html' %}
{% block content %}

    <div class="container mt-5">
        <form class="col-6 mx-auto card p-3 shadow" method="post" enctype="multipart/form-data">
            <h1 style="text-align: center;"><span style="color: green;">Login</span></h1>
 
            {% csrf_token %}
             <hr>
 
            {% if messages %}
            <div class="alert alert-primary" role="alert">
                {% for message in messages %}
                {{ message }}
                {% endfor %}
            </div>
            {% endif %}
 
            <div class="form-group">
                <label for="userName">Username</label>
                <input type="text" class="form-control" name="username" id="userName" 
                    placeholder="Enter username" required>
            </div>
 
            <div class="form-group">
                <label for="password">Password</label>
                <input type="password" name="password" class="form-control" id="password" placeholder="Password" required>
            </div>
 
            <p>Don't have an account? <a href="/register">Register</a> </p>
 
            <button type="submit" class="btn btn-primary">Submit</button>
        </form>
    </div>
{% endblock content %}

And then, create home.html inside base/templates/base/ folder and then insert following code into the home.html:

{% extends 'base/base.html' %}
{% block content %}

<h3>Dashboard</h3>
<p>Do you want to logout? <a href="/logout">Logout</a> </p>

{% endblock content %}

Finally insert some default redirecting instructions by inserting following lines in project/settings.py:

# ...
LOGIN_URL = 'login'
LOGIN_REDIRECT_URL = 'home'
LOGOUT_REDIRECT_URL = 'login'

Run dev server:

python manage.py runserver

Head to:

localhost:8000/register

Leave a Comment