本文へ移動
cccskills
無料GitHub で公開

django-allauth

Use when implementing Django authentication - local accounts, OAuth, email verification, MFA, OIDC, django-organizations

インストール方法を見る

含まれるファイル(2)

  • SKILL.md14.0 KB
  • references/examples.md1.4 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

django-allauth

Django authentication package.

Overview

django-allauth is a reusable Django app for local and social authentication. It handles signup, login, logout, email verification, and integrates with many OAuth providers.

Key Features:

  • Local account management (signup, login, password reset)
  • OAuth providers (Google, GitHub, Facebook, etc.)
  • Email verification
  • Multi-factor authentication (TOTP, WebAuthn)
  • Headless REST API support
  • Session management
  • Custom adapters

Installation

pip install django-allauth

# With optional dependencies
pip install django-allauth[socialaccount]
pip install django-allauth[mfa]

Quick Start

settings.py

INSTALLED_APPS = [
    # Required apps
    'django.contrib.auth',
    'django.contrib.messages',
    'django.contrib.sites',
    
    # allauth
    'allauth',
    'allauth.account',
    'allauth.socialaccount',
]

# Authentication backends
AUTHENTICATION_BACKENDS = [
    'allauth.account.auth_backends.AuthenticationBackend',
]

# Site ID
SITE_ID = 1

# allauth settings
ACCOUNT_AUTHENTICATION_METHOD = 'email'  # or 'username'
ACCOUNT_EMAIL_REQUIRED = True
ACCOUNT_USERNAME_REQUIRED = False
ACCOUNT_EMAIL_VERIFICATION = 'mandatory'  # or 'optional', 'none'

LOGIN_REDIRECT_URL = '/'
ACCOUNT_LOGOUT_REDIRECT_URL = '/'

urls.py

from django.urls import path, include

urlpatterns = [
    path('accounts/', include('allauth.urls')),
]

OIDC Provider (NEW in 65.x)

INSTALLED_APPS = [
    # ... existing apps
    "allauth.idp.oidc",  # OIDC provider
]

# For Django Ninja:
from allauth.idp.oidc.contrib.ninja.security import TokenAuth

# For DRF:
from allauth.idp.oidc.contrib.rest_framework.authentication import TokenAuthentication

Local Authentication

Signup

# views.py
from allauth.account.views import SignupView

# Uses built-in signup form
# POST /accounts/signup/

Login

# POST /accounts/login/
# Uses built-in login form

# With remember me
# POST /accounts/login/ with remember=true

Logout

# POST /accounts/logout/
# Clears session

Password Management

# Password change: POST /accounts/password/change/
# Password set: POST /accounts/password/set/
# Password reset: POST /accounts/password/reset/
# Password reset confirm: POST /accounts/password/reset/confirm/

Email Configuration

Settings

# Email backend
EMAIL_BACKEND = 'django.core.mail.backends.console.EmailBackend'

# allauth email settings
ACCOUNT_EMAIL_NOTIFICATIONS = True
EMAIL_CONFIRMATION_AUTHENTICATED_REDIRECT_URL = '/'
EMAIL_CONFIRMATION_ANONYMOUS_REDIRECT_URL = '/'

Custom Email Templates

templates/account/email/
├── email_confirmation_subject.txt
├── email_confirmation_message.txt
├── email_confirmation_signup_message.txt
├── password_reset_key_message.txt
└── ...

Sending Emails Manually

from allauth.account.models import EmailAddress

# Get user's verified emails
emails = EmailAddress.objects.filter(
    user=user,
    verified=True
)

# Send via allauth adapter
from allauth.account.adapter import get_adapter
adapter = get_adapter()
adapter.send_mail(
    'account/email/custom_subject.txt',
    user,
    {'context': 'variables'},
    [user.email]
)

OAuth Providers

Google Setup

# settings.py
INSTALLED_APPS += [
    'allauth.socialaccount.providers.google',
]

# Social app in admin:
# Add SocialApp with Google provider
# Client ID and Secret from Google Cloud Console

GitHub Setup

INSTALLED_APPS += [
    'allauth.socialaccount.providers.github',
]

Custom Provider

# myapp/providers.py
from allauth.socialaccount.providers.base import Provider
from allauth.socialaccount.providers.oauth2.provider import ProviderMixin

class MyCustomProvider(ProviderMixin, Provider):
    pass

# myapp/app_settings.py
from allauth.socialaccount import app_settings

provider_classes = [
    'myapp.providers.MyCustomProvider',
]

# settings.py
SOCIALACCOUNT_PROVIDERS = {
    'custom': {
        'APP': {
            'client_id': 'xxx',
            'secret': 'xxx',
            'key': ''
        }
    }
}

Provider Settings

SOCIALACCOUNT_PROVIDERS = {
    'google': {
        'APP': {
            'client_id': 'xxx',
            'secret': 'xxx',
        },
        'SCOPE': ['profile', 'email'],
        'AUTH_PARAMS': {'access_type': 'online'},
    },
    'github': {
        'APP': {
            'client_id': 'xxx',
            'secret': 'xxx',
        },
        'SCOPE': ['user:email'],
    },
}

Multi-Factor Authentication

Enable MFA

INSTALLED_APPS += [
    'allauth.mfa',
]

# Settings
MFA_ENABLED = True
MFA_SUPPORTED_AUTHENTICATORS = [
    'allauth.mfa.authenticators.Totp',
    'allauth.mfa.authenticators.WebAuthn',
    'allauth.mfa.authenticators.RecoveryCodes',
]

TOTP Setup

# Users can set up TOTP via
# GET /mfa/totp/create/
# POST /mfa/totp/activate/

WebAuthn

# WebAuthn/fido2 setup
# GET /mfa/webauthn/create/
# POST /mfa/webauthn/activate/

Recovery Codes

# Generate recovery codes
# GET /mfa/recovery_codes/generate/

REST API (Headless)

Setup

INSTALLED_APPS += [
    'allauth.headless',
]

# Settings
ALLAUTH_HEADLESS_ENABLED = True
ALLAUTH_HEADLESS_TOKEN_STRATEGY = 'allauth.headless.token.StrategyJWT'
ALLAUTH_HEADLESS_TOKEN_JWT_SECRET_KEY = 'your-secret'
ALLAUTH_HEADLESS_TOKEN_JWT_ALGORITHM = 'HS256'

Endpoints

# Signup
POST /headless/signup/
{"email": "user@example.com", "password": "password"}

# Login
POST /headless/authentication/login/
{"email": "user@example.com", "password": "password"}

# Logout
POST /headless/authentication/logout/

# Get current user
GET /headless/users/me/

# Manage emails
GET/POST/DELETE /headless/emails/

# Manage passwords
POST /headless/password/set/
POST /headless/password/change/
POST /headless/password/reset/

Token Strategies

# JWT
ALLAUTH_HEADLESS_TOKEN_STRATEGY = 'allauth.headless.token.StrategyJWT'

# Session-based
ALLAUTH_HEADLESS_TOKEN_STRATEGY = 'allauth.headless.token.StrategySession'

Signals

Only a handful of signals matter operationally. Full list: https://docs.allauth.org/en/latest/_modules/allauth/core/signals.html

SignalWhen it firesUse this when…
user_signed_upAfter user object created, before email sentSend welcome emails, create profile rows, call external services
user_logged_inAfter successful authenticationLog activity, refresh sessions, sync with external systems
email_confirmedAfter email verification completesGrant features, send confirmation receipts, update CRM
password_changedAfter password updateInvalidate other sessions, notify user, audit trail
social_account_addedAfter OAuth account linkedSync profile data, merge duplicate accounts
from allauth.account import signals
from django.dispatch import receiver

@receiver(signals.user_signed_up)
def on_user_signup(request, user, **kwargs):
    # Create profile, send welcome email
    pass

Templates

All allauth templates are overridable by shadowing them in your project's templates/ directory. See template overriding docs for the full list.

Common overrides:

  • account/login.html, account/signup.html — customize forms
  • account/email/email_confirmation_message.txt — branded emails
  • socialaccount/login.html — provider selection UI

Anti-Patterns

FailureCauseFix
user.email raises DoesNotExistAccessing email before checking EmailAddress tableUse EmailAddress.objects.get_primary(user) or check user.email_set.exists() first
Stale sessions after password resetNot invalidating other sessionsSet ACCOUNT_SESSION_COOKIE_AGE short; use signals.password_changed to revoke
Verification emails not sendingEMAIL_BACKEND set to console in productionConfigure real SMTP; test with EMAIL_BACKEND = 'django.core.mail.backends.console.EmailBackend' in dev
Social login creates duplicatesNot checking existing emails in pre_social_loginIn adapter: check EmailAddress for matching email, merge if found
MFA bypass in devMFA_ENABLED = False but prod uses MFAKeep MFA on in all envs; disable per-user for testing

When Not to Use allauth

API-only / headless projects — If you're building a SPA or mobile backend with no server-rendered pages, allauth's template system is dead weight. Consider:

  • Simple JWT signup/login with djangorestframework-simplejwt
  • Custom views using Django's User model directly
  • Only adopt allauth if you need social providers or complex email flows

Existing user model conflicts — If your project already has:

  • A custom AbstractUser with fields allauth doesn't expect
  • Existing auth logic that would need to be unwound
  • Third-party packages that hook into auth in incompatible ways

Check before adopting:

  1. python manage.py shell → from django.contrib.auth import get_user_model; print(get_user_model()._meta.fields) — does it match allauth's expectations?
  2. Search for AUTH_USER_MODEL — is it already set to something custom?
  3. Review existing login/signup views — can they be replaced, or would allauth fight them?

Flow Decision Guide

Email Verification

RequirementSettingCommon failure
Must verify before loginACCOUNT_EMAIL_VERIFICATION = 'mandatory'Users complain they can't login; forgot to configure SMTP
Optional, but prefer verifiedACCOUNT_EMAIL_VERIFICATION = 'optional' + middleware checkFeature access not gated; check EmailAddress.verified in views
No verification neededACCOUNT_EMAIL_VERIFICATION = 'none'Only for internal tools; emails still stored

Social + Password Combo

ScenarioConfiguration
Social-only (no password)Set ACCOUNT_PASSWORD_REQUIRED = False; remove password URLs from nav
Both allowed, separate flowsDefault config; users choose at login
Password users can link socialEnable SOCIALACCOUNT_AUTO_SIGNUP = False; let users connect in settings

MFA Enablement

TimingApproach
Force at next loginSet MFA_REQUIRED = True; users redirected to /mfa/ on auth
Optional, encourageShow MFA status in profile; no enforcement
Per-role enforcementMiddleware: check request.user.groups, redirect high-priv users to /mfa/ if not enrolled

Session / Redirect Separation

SettingPurpose
LOGIN_REDIRECT_URLWhere authenticated users go after login (allauth uses this)
ACCOUNT_LOGIN_REDIRECT_URLOverrides LOGIN_REDIRECT_URL for allauth specifically
ACCOUNT_LOGOUT_REDIRECT_URLWhere users land after logout
Common failureSet both LOGIN_REDIRECT_URL and ACCOUNT_LOGIN_REDIRECT_URL inconsistently; pick one and stick with it

Adapters

Adapters are the structural chokepoint for auth logic. Customize here instead of patching allauth internals.

Custom Account Adapter

Why you need this: Add validation, enforce policies, integrate with external systems.

# myapp/adapter.py
from allauth.account.adapter import DefaultAccountAdapter
from django.core.exceptions import ValidationError

class CustomAccountAdapter(DefaultAccountAdapter):
    def save_user(self, request, user, form, commit=True):
        """Add profile row when user signs up."""
        user = super().save_user(request, user, form, commit=False)
        if commit:
            from myapp.models import Profile
            Profile.objects.create(user=user)
        return user
    
    def clean_email(self, request, email):
        """Reject disposable email domains."""
        email = super().clean_email(request, email)
        disposable_domains = {'tempmail.com', 'throwaway.email'}
        domain = email.split('@')[-1].lower()
        if domain in disposable_domains:
            raise ValidationError('Disposable email domains not allowed')
        return email

# settings.py
ACCOUNT_ADAPTER = 'myapp.adapter.CustomAccountAdapter'

Custom Social Account Adapter

Why you need this: Enforce allowlists, merge accounts, enforce org membership.

# myapp/adapter.py
from allauth.socialaccount.adapter import DefaultSocialAccountAdapter
from allauth.socialaccount.models import SocialLogin
from django.core.exceptions import PermissionDenied

class CustomSocialAccountAdapter(DefaultSocialAccountAdapter):
    ALLOWED_DOMAINS = {'company.com', 'partner.org'}
    
    def pre_social_login(self, request, sociallogin):
        """Reject signups from unauthorized domains."""
        if sociallogin.state.get('action') != 'login':
            return  # New signup flow
        
        email = sociallogin.user.email
        if not email:
            return  # Let provider handle it
        
        domain = email.split('@')[-1].lower()
        if domain not in self.ALLOWED_DOMAINS:
            raise PermissionDenied(f'@{domain} not authorized for signup')
    
    def populate_user(self, request, sociallogin, data):
        """Sync profile fields from provider."""
        user = super().populate_user(request, sociallogin, data)
        # Sync first/last name from provider data
        user.first_name = data.get('first_name', '')
        user.last_name = data.get('last_name', '')
        return user

# settings.py
SOCIALACCOUNT_ADAPTER = 'myapp.adapter.CustomSocialAccountAdapter'

Deep Dives

  • Examples — custom signup form, verified email middleware

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

aiohttp

無料

Use when building Python async HTTP services or clients with aiohttp - web server routing, middleware, WebSocket, SSE, streaming, client sessions, pytest-aiohttp testing, or troubleshooting SSL and timeout issues

日本語の概要は準備中です。原文の説明を表示しています。

CodeAtCode/oss-ai-skills222026年10月9日 更新

ast-grep

無料

Use when doing structural code search and rewriting - ast-grep linting, refactoring, multi-language patterns

日本語の概要は準備中です。原文の説明を表示しています。

CodeAtCode/oss-ai-skills222026年10月9日 更新

Use when building GBA games with the BPCore Lua engine - entity, sprite and tilemap functions, SRAM save and load, link cable multiplayer protocol, camera and scrolling, or optimization patterns

日本語の概要は準備中です。原文の説明を表示しています。

CodeAtCode/oss-ai-skills222026年10月9日 更新

celery

無料

Use when running background tasks with Celery - worker and broker configuration (Redis, RabbitMQ), task routing by name vs queue, chains/groups/chords, retry patterns (autoretry_for, retry_backoff), acks_late semantics, failure detection, and monitoring with Flower

日本語の概要は準備中です。原文の説明を表示しています。

CodeAtCode/oss-ai-skills222026年10月9日 更新

django

無料

Use when building Django applications - security hardening, authentication and permissions, ORM optimization, PostgreSQL features, Django 6.0, migrations, testing, and ecosystem libraries

日本語の概要は準備中です。原文の説明を表示しています。

CodeAtCode/oss-ai-skills222026年10月9日 更新

Use when customizing Django Admin - save_formset, get_search_results, formsets, queryset optimization, db_index, custom URLs

日本語の概要は準備中です。原文の説明を表示しています。

CodeAtCode/oss-ai-skills222026年10月9日 更新

CodeAtCode のスキルをすべて見る

このスキルの問題を報告する