77 lines
2.1 KiB
Python

from ninja import Router, Form
from django.contrib.auth import get_user_model
from rest_framework_simplejwt.tokens import RefreshToken
from django.contrib.auth import authenticate
from django.http import HttpRequest
from django.db.models import Q
from django.contrib.auth.hashers import check_password
User = get_user_model()
router = Router(tags=["用户注册 + JWT"])
@router.post("/register")
def register(
request,
username: str = Form(...),
password: str = Form(...),
email: str = Form(...),
role: str = Form("user") # 也可写死 "user"
):
if User.objects.filter(username=username).exists():
return {"success": False, "message": "用户名已存在"}
if role != "user":
return {"success": False, "message": "不能注册管理员或分管理账号"}
user = User(username=username, email=email, role=role)
user.set_password(password)
user.save()
# 生成 JWT token
refresh = RefreshToken.for_user(user)
return {
"success": True,
"message": "注册成功",
"user": {
"id": user.id,
"username": user.username,
"role": user.role,
},
"token": {
"access": str(refresh.access_token),
"refresh": str(refresh),
}
}
@router.post("/login")
def login(
request: HttpRequest,
username: str = Form(...), # 可以是用户名或邮箱
password: str = Form(...),
):
user = User.objects.filter(Q(username=username) | Q(email=username)).first()
if not user or not user.check_password(password):
return {"success": False, "message": "用户名或密码错误"}
if not user.is_active:
return {"success": False, "message": "账号未激活"}
refresh = RefreshToken.for_user(user)
return {
"success": True,
"message": "登录成功",
"user": {
"id": user.id,
"username": user.username,
"role": user.role,
},
"token": {
"access": str(refresh.access_token),
"refresh": str(refresh),
}
}