i want to modify authentication behaviour so that the whole process can be done on the client side through xhr. so for example when i sumbit the login form login_handler would return a some json data on success and error instead of loading up new html pages or having a redirect of any sort. what should i look into to do this?
login through XHR
1.3k views Asked by rhyek At
3
There are 3 answers
0
On
You should be able to write your own login controller by getting the identifier and calling the remember method.
First retrieve your user from the database, validate the password and then if everything is correct you can set the authentication cookie:
response.headers = request.environ['repoze.who.plugins']['main_identifier'].remember(request.environ, {'repoze.who.userid':user_name})
Also return a json dict from the controller at the end confirming success or not for UI purpose
2
On
I was trying to do the exact same thing with TG2. This is an extending the answer from amol. I am using it and it works fine for me.
@expose("json")
def login(self, login, password):
identity = {"login": login,
"password": password}
# Authenticate the credentials
username = request.environ['repoze.who.plugins']['sqlauth'].authenticate(request.environ, identity)
if username:
print("Logged into " + username)
# Remember this user
response.headers = request.environ['repoze.who.plugins']['main_identifier'].remember(request.environ, {'repoze.who.userid':username})
return {"status": True, "username": username}
else:
print("Could not authenticate")
return {"status": False, "username": None}
If you extract the username and password and send them to a login script as parameters, you could then validate the user and return results accordingly.
Where the script would look something like this:
I would suggest against this, though, since the process itself is riddled with security issues and vulnerabilities. If you can get away with posting credentials securely to a server and allowing the web server to handle the session, setting the cookie, and properly authenticating, then try to do so.