3 ms·
Yeah you're right, that's definitely not the the most secure. Do you know of a more secure alternative I could try instead?
by nfoert 2y ago
Yeah you're right, that's definitely not the the most secure. Do you know of a more secure alternative I could try instead?
- deleted 2y ago[deleted]
- aperezalbela 2y agoI'd suggest using forms.Form for a LoginForm containing e.g. username = forms.CharField(max_length=150) password = forms.CharField(widget=forms.PasswordInput) and then a view to instantiate form with request.POST (if request.POST) like: form = LoginForm(request.POST) and then if form.is_valid() you can clean data using username = form.cleaned_data['username'] and the same for password. Then: user = authenticate(request, username=username, password=password) and then check if user is not None then login(request, user) Note that login and authenticate come from django.contrib.auth import authenticate, login Hope that helps.
- singpolyma3 2y ago...how is that more secure?
- nfoert 2y agoThank you, Django Forms do look promising. I’ll definitely look into more secure alternatives to the current implementation.