Friday, October 31, 2014

Django Mobile Backend Login

Disclaimer: There are many things in this entry which are incomplete in some cases, for example when I say mobile applications don't have the "session"s, it is a general statement, of course you can use libraries or custom methods to build sessions.


We all know how pain in the ass authentication may become if you are inexperienced in mobile backend development.

It is different from website development, there are no sessions. You can't send a login request once and forget about it for the following requests. You have to keep user logged in, he may leave and come back 1 month later, who would want to be welcomed back by a login screen in a mobile application anyway?

My solution is specific to Django Framework but the main idea is the same.

There are 2 options:
1) At every request include email and password to the request. This way your backend will know no sessions, every request is a new request and at each request you should login your user again. Don't ever worry about few extra bytes this wastes. Nothing would change because of 50 bytes.

2) Make a login request which on successful requests returns a random "token" like 15dsf87yfa8sfas8a7shdas8ah and save it to the database as well under the user, this is basically the same as previous one and you are inventing the "sessions". But don't worry it is a very easy process so don't think it like reinventing the wheel. At every request include this token and login the user with it.

You will need a login request which does nothing! You can ask why would you need a login screen and request when each request already includes login request. Think deeply you open an application and give your credentials. At that exact moment you don't need to change anything at the backend (in Option 1) but you still have to warn user if the credentials are right or wrong. This way user won't be interrupted after his first job-doing request, that's not convenient. This is why you still need a login request which does nothing but just returns {'success':True} or {'success':False}

Here is the Django specific part, I wrote a custom middleware, which is very basic but it does the job:



Here you see at every request I look at GET parameters and login the user as custom Citizen class, because I don't use the regular user class. 

In the view which needs login you can do this:


I am checking isinstance of Citizen because Django adds custom user class and that's not what I care about, the request may have a regular user but that doesn't mean my custom login has ran (in fact it means it was unsuccessful)


You can put your custom middleware class anywhere you want, I put it in Citizen app because logically that's where it belonged:


Then what you need to do is open settings.py and add your middleware path to is like this:




Of course the best way to develop mobile backend with Django is using Django Rest Framework and probably there is a better way to handle this authentication with AuthenticationMiddleware shipped with Django but everyday I am developing with a new framework so this solution works as is, I couldn't find a clear solution to this utilizing them under 30 minutes so I implemented one.

One note: I did use GET for test purposes, at production use POST and don't ever forget using SSL except when it's just a hobby project.

Happy Djangoing

Saturday, September 20, 2014

MaksatFirsat Privacy Policy

We use technologies like cookies (small files stored on your browser), web beacons, or unique device identifiers to identify your computer or device so we can deliver a better experience. Our systems also log information like your browser, operating system and IP address.

We also may collect personally identifiable information that you provide to us, such as your name, address, phone number or email address. With your permission, we may also access other personal information on your device, such as your phone book, calendar or messages, in order to provide services to you. If authorized by you, we may also access profile and other information from services like Facebook.

Our systems may associate this personal information with your activities in the course of providing service to you (such as pages you view or things you click on or search for).

We do not knowingly contact or collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us so we can promptly obtain parental consent or remove the information.

Our service does not currently recognize the "Do Not Track" signal that may be available in some web browsers.

We do not use or collect your precise geographic location.

You can sign into your account to see any personally identifiable information we have stored, such as your name, email, address or phone number. You can also contact us by email to request to see this information.

We may keep data indefinitely.

We generally do not share personally identifiable information (such as name, address, email or phone) with other companies.

We do not allow advertising companies to collect data through our service for ad targeting.

If you have any questions or concerns about our privacy policies, please contact us:

In order to serve you, we may share your personal and anonymous information with other companies, including vendors and contractors. Their use of information is limited to these purposes, and subject to agreements that require them to keep the information confidential. Our vendors provide assurance that they take reasonable steps to safeguard the data they hold on our behalf, although data security cannot be guaranteed.

Analytics companies may access anonymous data (such as your IP address or device ID) to help us understand how our services are used. They use this data solely on our behalf. They do not share it except in aggregate form; no data is shared as to any individual user. Click to see company privacy policies that govern their use of data.

We take reasonable steps to secure your personally identifiable information against unauthorized access or disclosure. We encrypt transmission of data on pages where you provide payment information. However, no security or encryption method can be guaranteed to protect information from hackers or human error.

Information we collect may be stored or processed on computers located in any country where we do business.

To operate the service, we also may make identifiable and anonymous information available to third parties in these limited circumstances: (1) with your express consent, (2) when we have a good faith belief it is required by law, (3) when we have a good faith belief it is necessary to protect our rights or property, or (4) to any successor or purchaser in a merger, acquisition, liquidation, dissolution or sale of assets. Your consent will not be required for disclosure in these cases, but we will attempt to notify you, to the extent permitted by law to do so.