django-two-factor-auth 1.2.0

Complete Two-Factor Authentication for Django

Complete Two-Factor Authentication for Django. Built on top of the one-time password framework django-otp and Django's built-in authentication framework django.contrib.auth for providing the easiest integration into most Django projects. Inspired by the user experience of Google's Two-Step Authentication, allowing users to authenticate through call, text messages (SMS), by using a token generator app like Google Authenticator or a YubiKey hardware token generator (optional).

I would love to hear your feedback on this package. If you run into problems, please file an issue on GitHub, or contribute to the project by forking the repository and sending some pull requests. The package is currently translated into English, Dutch, Hebrew and Arabic. Please contribute your own language using Transifex.

Test drive this app through the online example app, hosted by Heroku. It demos most features except the Twilio integration. The example also includes django-user-sessions for providing Django sessions with a foreign key to the user. Although the package is optional, it improves account security control over django.contrib.sessions.

Compatible with all supported Django (LTS) versions. At the moment of writing that's including 1.4, 1.7 and 1.8 on Python 2.6, 2.7, 3.2, 3.3 and 3.4. Documentation is available at readthedocs.org.

Installation

Installation with pip:

$ pip install django-two-factor-auth

On Django 1.8, also install django-formtools:

$ pip install django-formtools

Add the following apps to the INSTALLED_APPS:

INSTALLED_APPS = (
    ...
    'django_otp',
    'django_otp.plugins.otp_static',
    'django_otp.plugins.otp_totp',
    'two_factor',
)

Add django_otp.middleware.OTPMiddleware to MIDDLEWARE_CLASSES. It must be installed after AuthenticationMiddleware:

MIDDLEWARE_CLASSES = [
    'django.middleware.common.CommonMiddleware',
    'django.contrib.sessions.middleware.SessionMiddleware',
    'django.middleware.csrf.CsrfViewMiddleware',
    'django.contrib.auth.middleware.AuthenticationMiddleware',
    'django_otp.middleware.OTPMiddleware',
    'django.contrib.messages.middleware.MessageMiddleware',
]

Configure a few urls:

from django.core.urlresolvers import reverse_lazy
LOGIN_URL = reverse_lazy('two_factor:login')

Add the url routes:

urlpatterns = patterns('',
    ...
    url(r'', include('two_factor.urls', 'two_factor')),
)

Be sure to remove any other login routes, otherwise the two-factor authentication might be circumvented. The admin interface should be automatically patched to use the new login method.

Support for YubiKey is disabled by default, but enabling is easy. Please refer to the documentation for instructions.

Contribute

  • Submit issues to the issue tracker on Github
  • Fork the source code at Github
  • Run the tests.
  • Send a pull request with your changes.
  • Provide a translation using Transifex.

Running tests

This project aims for full code-coverage, this means that your code should be well-tested. Also test branches for hardened code. You can run the full test suite with:

make test

Or run a specific test with:

make test TARGET=tests.tests.TwilioGatewayTest

For Python compatibility, tox is used. You can run the full test suite with:

tox

Releasing

The following actions are required to push a new version:

python example/manage.py makemigrations two_factor git commit -am "Added migrations"

bumpversion [major|minor|patch] git commit -am "Released [version]" git tag [version] python setup.py sdist bdist_wheel upload

See Also

Have a look at django-user-sessions for Django sessions with a foreign key to the user. This package is also included in the online example app.

License

The project is licensed under the MIT license.

MIT

Author

Bouke Haarsma

Pip

django-two-factor-auth==1.2.0

Classifiers

  • Development Status :: 5 - Production/Stable
  • Environment :: Web Environment
  • Framework :: Django
  • Intended Audience :: Developers
  • License :: OSI Approved :: MIT License
  • Operating System :: OS Independent
  • Programming Language :: Python
  • Programming Language :: Python :: 2
  • Programming Language :: Python :: 2.6
  • Programming Language :: Python :: 2.7
  • Programming Language :: Python :: 3
  • Programming Language :: Python :: 3.2
  • Programming Language :: Python :: 3.3
  • Programming Language :: Python :: 3.4
  • Topic :: Security
  • Topic :: System :: Systems Administration :: Authentication/Directory
File Type Python Version Uploaded On Downloads
django_two_factor_auth-1.2.0-py2.py3-none-any.whl Wheel 2.7 May 2, 2015 5,651
django-two-factor-auth-1.2.0.tar.gz Source May 2, 2015 1,209
Version Release Date
1.2.0 May 2, 2015
1.1.1 Jan. 10, 2015
1.1.0 Jan. 7, 2015
1.0.0 Sept. 19, 2014
1.0.0-beta3 June 15, 2014
1.0.0-beta2 June 4, 2014
1.0.0-beta1 June 1, 2014
0.5.0 March 23, 2014
0.4.0 Jan. 30, 2014
0.3.1 Jan. 19, 2014
0.3.0 Jan. 15, 2014
0.2.3 Jan. 3, 2014
0.2.2 Nov. 27, 2013
0.2.1 Nov. 25, 2013
0.2.0 Nov. 20, 2013
0.1.2 Jan. 13, 2013
0.1.1 Sept. 12, 2012
0.1.0 Sept. 12, 2012
Date Package Version Action
Aug. 26, 2015, 12:30 a.m. django-two-factor-auth 0.5.0 Release Created
Aug. 26, 2015, 12:30 a.m. django-two-factor-auth 1.0.0-beta3 Release Created
Aug. 26, 2015, 12:30 a.m. django-two-factor-auth 0.1.2 Release Created
Aug. 26, 2015, 12:30 a.m. django-two-factor-auth 0.4.0 Release Created
Aug. 26, 2015, 12:30 a.m. django-two-factor-auth 0.1.0 Release Created
Aug. 26, 2015, 12:30 a.m. django-two-factor-auth 0.2.0 Release Created
Aug. 26, 2015, 12:30 a.m. django-two-factor-auth 1.2.0 Release Created
Aug. 26, 2015, 12:30 a.m. django-two-factor-auth 0.2.2 Release Created
Aug. 26, 2015, 12:30 a.m. django-two-factor-auth 0.2.3 Release Created
Aug. 26, 2015, 12:30 a.m. django-two-factor-auth 0.3.1 Release Created
Aug. 26, 2015, 12:30 a.m. django-two-factor-auth 0.3.0 Release Created
Aug. 26, 2015, 12:30 a.m. django-two-factor-auth 0.1.1 Release Created
Aug. 26, 2015, 12:30 a.m. django-two-factor-auth 1.0.0-beta2 Release Created
Aug. 26, 2015, 12:30 a.m. django-two-factor-auth 0.2.1 Release Created
Aug. 26, 2015, 12:30 a.m. django-two-factor-auth 1.0.0 Release Created
Aug. 26, 2015, 12:30 a.m. django-two-factor-auth 1.0.0-beta1 Release Created
Aug. 26, 2015, 12:30 a.m. django-two-factor-auth 1.1.0 Release Created
Aug. 26, 2015, 12:30 a.m. django-two-factor-auth 1.1.1 Release Created
Aug. 26, 2015, 12:30 a.m. django-two-factor-auth Package Created