Files
Django/gvsdsdk/auth/jwt_auth.py
2026-06-18 19:17:26 +08:00

55 lines
2.2 KiB
Python
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
"""自定义 JWT 认证 — 向后兼容旧 token 的 user_id claim"""
from rest_framework_simplejwt.authentication import JWTAuthentication
from rest_framework_simplejwt.exceptions import InvalidToken, AuthenticationFailed
from rest_framework_simplejwt.settings import api_settings
from django.utils.translation import gettext_lazy as _
class CompatibleJWTAuthentication(JWTAuthentication):
"""
兼容旧 token 的 JWT 认证类。
旧 tokenUSER_ID_CLAIM='user_id' 时生成payload 中使用 'user_id' claim
值为 user.idUUID 字符串)。
新 tokenUSER_ID_CLAIM='UserUID' 时生成payload 中使用 'UserUID' claim
值为 user.UserUID7位业务ID
此类先尝试新 claim找不到时回退到旧 claim并用对应字段查库。
"""
def get_user(self, validated_token):
# 1. 先尝试当前配置的 USER_ID_CLAIM
user_id = validated_token.get(api_settings.USER_ID_CLAIM)
lookup_field = api_settings.USER_ID_FIELD
if user_id is None:
# 2. 回退:尝试旧 token 中的 'user_id' claim
user_id = validated_token.get('user_id')
if user_id is None:
raise InvalidToken(
{'detail': _('令牌未包含用户标识符'), 'code': 'token_not_valid'}
)
# 旧 token 的 user_id 来自 user.id即 UserUUID
# 需要用 UserUUID 字段查库
lookup_field = 'UserUUID'
try:
user = self.user_model.objects.get(**{lookup_field: user_id})
except self.user_model.DoesNotExist:
raise AuthenticationFailed(_('用户不存在'), code='user_not_found')
if not user.is_active:
raise AuthenticationFailed(_('用户已被禁用'), code='user_inactive')
if api_settings.CHECK_REVOKE_TOKEN:
from rest_framework_simplejwt.utils import get_md5_hash_password
if validated_token.get(
api_settings.REVOKE_TOKEN_CLAIM
) != get_md5_hash_password(user.password):
raise AuthenticationFailed(
_('用户密码已更改'), code='password_changed'
)
return user