A logout system allows an authenticated user to end their current login session and safely leave a protected area of a Django application.
Django provides a built-in logout() function that can be used
to log the current user out.
Logout means ending the authenticated session of the currently logged-in user.
A simple logout process looks like this:
User is Logged In
↓
Clicks Logout
↓
logout(request)
↓
Session Authentication Removed
↓
User is Logged Out
Logout is important when users access private or personal information.
Django provides the logout() function through
django.contrib.auth.
from django.contrib.auth import logout
The function accepts the current request.
logout(request)
A simple logout view can call logout() and then redirect the
user to another page.
from django.contrib.auth import logout
from django.shortcuts import redirect
def logout_view(request):
logout(request)
return redirect("login")
Create a URL pattern that points to the logout view.
from django.urls import path
from . import views
urlpatterns = [
path(
"logout/",
views.logout_view,
name="logout"
),
]
The name logout can be used for URL reversing.
A simple logout link can point to the logout URL.
<a href="{% url 'logout' %}">
Logout
</a>
However, for applications where logout changes authentication state, using a POST request is a common pattern.
A logout form can use POST to explicitly submit the logout action.
<form
method="post"
action="{% url 'logout' %}"
>
{% csrf_token %}
<button type="submit">
Logout
</button>
</form>
The CSRF token provides protection for the internal POST request.
If you want your custom logout view to accept only POST requests, check the request method.
def logout_view(request):
if request.method == "POST":
logout(request)
return redirect("login")
return redirect("dashboard")
This makes the intended logout action explicit.
After logout, the user can be redirected to the login page.
logout(request)
return redirect("login")
The destination can also be another public page, such as a home page.
Before logout, request.user represents the authenticated user.
After logout, the current request is no longer associated with an authenticated user for subsequent authentication checks.
logout(request)
return redirect("login")
Django provides is_authenticated for checking authentication
status.
if request.user.is_authenticated:
print("User is logged in")
else:
print("User is logged out")
After logout, later requests from that browser will not be treated as authenticated by Django's authentication system.
Private pages should be protected using appropriate authentication checks.
from django.contrib.auth.decorators import login_required
@login_required
def dashboard(request):
return render(
request,
"dashboard.html"
)
If a user is no longer authenticated, they cannot access the protected view as an authenticated user.
A complete authentication system normally includes both login and logout.
Login
↓
authenticate()
↓
login()
↓
Protected Page
↓
Logout
↓
logout()
↓
Login Page
from django.contrib.auth import logout
from django.shortcuts import redirect
def logout_view(request):
logout(request)
return redirect("login")
This is a basic custom logout view.
from django.contrib.auth import logout
from django.shortcuts import redirect
def logout_view(request):
if request.method == "POST":
logout(request)
return redirect("login")
return redirect("dashboard")
This version performs the logout operation only for a POST request.
A button can be placed inside a POST form to create a logout control.
<form
method="post"
action="{% url 'logout' %}"
>
{% csrf_token %}
<button
type="submit"
>
Logout
</button>
</form>
A template can display a logout button only when the current user is authenticated.
{% if user.is_authenticated %}
<form
method="post"
action="{% url 'logout' %}"
>
{% csrf_token %}
<button type="submit">
Logout
</button>
</form>
{% endif %}
The same template can display a login link when the user is not authenticated.
{% if user.is_authenticated %}
<span>
Welcome {{ user.username }}
</span>
{% else %}
<a href="{% url 'login' %}">
Login
</a>
{% endif %}
Django also provides authentication views that can be included using
django.contrib.auth.urls.
from django.urls import include, path
urlpatterns = [
path(
"accounts/",
include(
"django.contrib.auth.urls"
)
),
]
This includes Django's standard authentication URL patterns.
When using Django's built-in authentication URLs, the logout route is available under the included authentication URL prefix.
For example, with:
path(
"accounts/",
include(
"django.contrib.auth.urls"
)
)
the logout URL is conventionally:
/accounts/logout/
If you use Django's built-in logout view and configure it to render a logout page, you can provide a template for that purpose.
A simple logout confirmation page might contain:
<h2>
You have been logged out.
</h2>
<a href="{% url 'login' %}">
Login Again
</a>
A dashboard commonly contains a logout button.
<h1>
Welcome {{ request.user.username }}
</h1>
<form
method="post"
action="{% url 'logout' %}"
>
{% csrf_token %}
<button type="submit">
Logout
</button>
</form>
The logout operation removes the authentication information associated with the current session.
This means subsequent requests are not treated as authenticated through that login session.
logout(request)
Always use Django's authentication API instead of trying to manually remove authentication information.
Logout is useful when multiple people use the same computer or browser.
A typical flow is:
User A
↓
Login
↓
Use Application
↓
Logout
↓
User B
↓
Login
This prevents the next user from simply continuing with the previous authenticated session.
logout() function.logout.logout() without passing request.from django.urls import path
from . import views
urlpatterns = [
path(
"login/",
views.login_view,
name="login"
),
path(
"logout/",
views.logout_view,
name="logout"
),
path(
"dashboard/",
views.dashboard,
name="dashboard"
),
]
These URLs connect the authentication views with the application.
User Logged In
↓
Dashboard
↓
Clicks Logout
↓
POST Request
↓
logout(request)
↓
Authentication Session Ends
↓
Redirect to Login
↓
User Logged Out
views.py
from django.contrib.auth import logout
from django.shortcuts import redirect
def logout_view(request):
if request.method == "POST":
logout(request)
return redirect("login")
return redirect("dashboard")
Template:
<form
method="post"
action="{% url 'logout' %}"
>
{% csrf_token %}
<button type="submit">
Logout
</button>
</form>
Django makes logout simple through its built-in authentication framework.
logout(request) to log out the current user.{% csrf_token %} in internal POST forms.login_required.request.user to access the current user.is_authenticated to check authentication status.logout() ends the current authenticated session.request.Question: Which Django function is used to log out the current user?