# Authentication Issue

**URL:** <https://forum.djangoproject.com/t/authentication-issue/18936>\
**Category:** Deployment\
**Created:** [February 18, 2023, 4:39pm UTC](https://forum.djangoproject.com/t/authentication-issue/18936 "2023-02-18T16:39:29Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![mfreitas64](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/mfreitas64/32/10995_2.png) [@mfreitas64](https://forum.djangoproject.com/u/mfreitas64)\
**Post date:** [February 18, 2023, 4:39pm UTC](https://forum.djangoproject.com/t/authentication-issue/18936/1 "2023-02-18T16:39:29Z")

</div>

Hi,

I’ve my app working on production with no problems except the reset password code bit.

This is my urls.py for the user app

```auto
urlpatterns = [
    path('admin/', admin.site.urls),
    path('register/', user_views.register, name='register'),
    path('profile/', user_views.profile, name='profile'),
    path('login/', auth_views.LoginView.as_view(template_name='users/login.html'), name='login'),
    path('logout/', auth_views.LogoutView.as_view(template_name='users/logout.html'), name='logout'),
    path('password-reset/',
         auth_views.PasswordResetView.as_view(template_name='users/password_reset.html'),
         name='password_reset'),
    path('password-reset/done',
         auth_views.PasswordResetDoneView.as_view(template_name='users/password_reset_done.html'),
         name='password_reset_done'),
    path('password-reset-confirm/<uidb64>/<token>/',
         auth_views.PasswordResetConfirmView.as_view(template_name='users/password_reset_confirm.html'),
         name='password_reset_confirm'),
    path('password-reset-complete/',
         auth_views.PasswordResetCompleteView.as_view(template_name='users/password_reset_complete.html'),
         name='password_reset_complete'),
    path('', include('books.urls')),
] + static(settings.MEDIA_URL, document_root=settings.MEDIA_ROOT)

```

This is my settings.py

```auto
EMAIL_BACKEND = 'django.core.mail.backends.smtp.EmailBackend'
EMAIL_HOST = 'smtp.sendgrid.com'
EMAIL_PORT = 587
EMAIL_USE_TLS = True
EMAIL_HOST_USER = os.environ.get('EMAIL_HOST_USER')
EMAIL_HOST_PASSWORD = os.environ.get('EMAIL_HOST_PASSWORD')

```

When I try to reset the password I get this error message:

```auto
# SMTPSenderRefused at /password-reset/

```

I’ve stored the username and password on local variables and they seem to be working but when the error pops-up I can see in the settings part that the EMAIL\_HOST\_USER is set to none

![Screenshot 2023-02-18 at 16.26.38](https://us1.discourse-cdn.com/flex026/uploads/djangoproject/original/2X/b/b732bd6e08341e834e2979049805603afde38187.png)

I’ve been able to send a message from the production server with telnet through the SendGrid SMTP Relay.

What is happening here? Why is the username none in the settings on the debug?

Any help would be much appreciated.  
Miguel

---

<div class="post-metadata">

**Author:** ![KenWhitesell](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/kenwhitesell/32/280_2.png) [@KenWhitesell](https://forum.djangoproject.com/u/KenWhitesell)\
**Post date:** [February 18, 2023, 5:19pm UTC](https://forum.djangoproject.com/t/authentication-issue/18936/2 "2023-02-18T17:19:57Z")

</div>

The most direct and obvious initial explanation is that you don’t have an environment variable named `EMAIL_HOST_USER` in the environment in which you’re running Django.

You can verify this by setting a default value in the `get` function to see if that’s what’s being applied.

Resolving this requires knowledge of how you’re running your Django app and how you’re setting the environment for those processes.

---

<div class="post-metadata">

**Author:** ![mfreitas64](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/mfreitas64/32/10995_2.png) [@mfreitas64](https://forum.djangoproject.com/u/mfreitas64)\
**Post date:** [February 18, 2023, 5:53pm UTC](https://forum.djangoproject.com/t/authentication-issue/18936/3 "2023-02-18T17:53:15Z")

</div>

The environment variables are defined in the .profile file and the system can see them, as you can see from the picture.  
 ![Screenshot 2023-02-18 at 17.51.17](https://us1.discourse-cdn.com/flex026/uploads/djangoproject/original/2X/2/2f4a15f9a746b9382071acb489958853a007c8f2.png)

---

<div class="post-metadata">

**Author:** ![KenWhitesell](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/kenwhitesell/32/280_2.png) [@KenWhitesell](https://forum.djangoproject.com/u/KenWhitesell)\
**Post date:** [February 18, 2023, 7:45pm UTC](https://forum.djangoproject.com/t/authentication-issue/18936/4 "2023-02-18T19:45:43Z")

</div>

Ok, you’ve defined them in a `.profile` file.

How are you running your Django instance, and how are the entries in that file being added to that process’ environment? (Hint: That second part doesn’t happen automatically with a non-login shell.)

---

<div class="post-metadata">

**Author:** ![mfreitas64](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/mfreitas64/32/10995_2.png) [@mfreitas64](https://forum.djangoproject.com/u/mfreitas64)\
**Post date:** [February 18, 2023, 9:14pm UTC](https://forum.djangoproject.com/t/authentication-issue/18936/5 "2023-02-18T21:14:49Z")

</div>

Are you talking about **.env** file? Do I need to install django-environ and declare all my environment variables there, and then update the settings.py accordingly?

---

<div class="post-metadata">

**Author:** ![KenWhitesell](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/kenwhitesell/32/280_2.png) [@KenWhitesell](https://forum.djangoproject.com/u/KenWhitesell)\
**Post date:** [February 18, 2023, 11:08pm UTC](https://forum.djangoproject.com/t/authentication-issue/18936/6 "2023-02-18T23:08:47Z")

</div>

> [@mfreitas64](#):
>
> Are you talking about **.env** file? …

Can you do it that way? Yes.  
Is the the only way? No  
Is it the “best” way? That depends…

> [@KenWhitesell](#):
>
> Resolving this requires knowledge of how you’re running your Django app and …

> [@KenWhitesell](#):
>
> How are you running your Django instance, … ?

I really can’t answer your question until you answer mine. Off the top of my head, I can think of at least 30 different ways to run a Django environment, each providing slightly different mechanisms for managing the environment, including the “in app” method you identify.

---

<div class="post-metadata">

**Author:** ![mfreitas64](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/mfreitas64/32/10995_2.png) [@mfreitas64](https://forum.djangoproject.com/u/mfreitas64)\
**Post date:** [February 18, 2023, 11:15pm UTC](https://forum.djangoproject.com/t/authentication-issue/18936/7 "2023-02-18T23:15:59Z")

</div>

I’m using a VM with ubuntu, nginx and gunicorn

DISTRIB\_ID=Ubuntu  
DISTRIB\_RELEASE=22.04  
DISTRIB\_CODENAME=jammy  
DISTRIB\_DESCRIPTION=“Ubuntu 22.04.1 LTS”

nginx version: nginx/1.18.0 (Ubuntu)

gunicorn (version 20.1.0)

---

<div class="post-metadata">

**Author:** ![KenWhitesell](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/kenwhitesell/32/280_2.png) [@KenWhitesell](https://forum.djangoproject.com/u/KenWhitesell)\
**Post date:** [February 18, 2023, 11:36pm UTC](https://forum.djangoproject.com/t/authentication-issue/18936/8 "2023-02-18T23:36:35Z")

</div>

How are you running gunicorn? Systemd, supervisord, runit, init.d, docker, ???

---

<div class="post-metadata">

**Author:** ![mfreitas64](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/mfreitas64/32/10995_2.png) [@mfreitas64](https://forum.djangoproject.com/u/mfreitas64)\
**Post date:** [February 18, 2023, 11:37pm UTC](https://forum.djangoproject.com/t/authentication-issue/18936/9 "2023-02-18T23:37:41Z")

</div>

I’m really new to this, so I have to ask, how do I know/check that?

---

<div class="post-metadata">

**Author:** ![KenWhitesell](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/kenwhitesell/32/280_2.png) [@KenWhitesell](https://forum.djangoproject.com/u/KenWhitesell)\
**Post date:** [February 18, 2023, 11:39pm UTC](https://forum.djangoproject.com/t/authentication-issue/18936/10 "2023-02-18T23:39:08Z")

</div>

“Something” is running gunicorn. You would have had to set it up to run - all those options above involve manual steps to get started.

When your server is booted, it’s not going to run gunicorn unless you’ve done something to make it start gunicorn after a boot. I’m trying to learn what that “something”, is.

---

<div class="post-metadata">

**Author:** ![mfreitas64](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/mfreitas64/32/10995_2.png) [@mfreitas64](https://forum.djangoproject.com/u/mfreitas64)\
**Post date:** [February 18, 2023, 11:45pm UTC](https://forum.djangoproject.com/t/authentication-issue/18936/11 "2023-02-18T23:45:31Z")

</div>

I haven’t done nothing, I think the server had already that “something” working. The only thing I have is a file called gunicorn.py that is on /etc/gunicorn.d

```auto
"""gunicorn WSGI server configuration."""
from multiprocessing import cpu_count
from os import environ

def max_workers():
    return cpu_count() * 2 + 1

max_requests = 1000
worker_class = 'gevent'
workers = max_workers()

```

---

<div class="post-metadata">

**Author:** ![KenWhitesell](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/kenwhitesell/32/280_2.png) [@KenWhitesell](https://forum.djangoproject.com/u/KenWhitesell)\
**Post date:** [February 18, 2023, 11:53pm UTC](https://forum.djangoproject.com/t/authentication-issue/18936/12 "2023-02-18T23:53:32Z")

</div>

So you’re working from a server that someone else configured? (This doesn’t happen magically or automatically, **someone** configured gunicorn to start after a system reboot.)

If that’s the case, you’d need to do some sleuthing to try and figure out what started gunicorn.

For example, you could start with the command (as root):  
`ps -AF | grep gunicorn`  
That’s going to hopefully show a line starting with a user in the first column, then two columns of numbers. If the second number is “1”, then odds are you’ve got this set up as a systemd task. If it’s not a “1”, then the command:  
`ps -AF | grep <number from second column>`  
should reveal the identity of the parent process.

---

<div class="post-metadata">

**Author:** ![mfreitas64](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/mfreitas64/32/10995_2.png) [@mfreitas64](https://forum.djangoproject.com/u/mfreitas64)\
**Post date:** [February 19, 2023, 12:08am UTC](https://forum.djangoproject.com/t/authentication-issue/18936/13 "2023-02-19T00:08:21Z")

</div>

I think it’s 1

 ![Screenshot 2023-02-19 at 00.06.56](https://us1.discourse-cdn.com/flex026/uploads/djangoproject/original/2X/5/568dff5c2fa2e8fc2f13a5c662b64f68517d3b17.png)

---

<div class="post-metadata">

**Author:** ![KenWhitesell](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/kenwhitesell/32/280_2.png) [@KenWhitesell](https://forum.djangoproject.com/u/KenWhitesell)\
**Post date:** [February 19, 2023, 12:24am UTC](https://forum.djangoproject.com/t/authentication-issue/18936/14 "2023-02-19T00:24:08Z")

</div>

Great!

That’s a fairly distinctive command line there - now it’s just a matter of finding what file contains that command.

You would likely find it somewhere in the `/etc` directory, possibly under `/etc/systemd` if that’s what’s being used to run it.

---

<div class="post-metadata">

**Author:** ![mfreitas64](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/mfreitas64/32/10995_2.png) [@mfreitas64](https://forum.djangoproject.com/u/mfreitas64)\
**Post date:** [February 19, 2023, 2:38am UTC](https://forum.djangoproject.com/t/authentication-issue/18936/15 "2023-02-19T02:38:58Z")

</div>

I think i found it.  
gunicorn.service on  
/etc/systemd/system

```auto
[Unit]
Description=Gunicorn daemon for Django Project
Before=nginx.service
After=network.target

[Service]
WorkingDirectory=/home/django/django_books
ExecStart=/usr/bin/gunicorn3 --name=django_books --pythonpath=/home/django/django_books --bind unix:/home/django/gunicorn.socket >
Restart=always
SyslogIdentifier=gunicorn
User=django
Group=django

[Install]
WantedBy=multi-user.target

```

---

<div class="post-metadata">

**Author:** ![KenWhitesell](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/kenwhitesell/32/280_2.png) [@KenWhitesell](https://forum.djangoproject.com/u/KenWhitesell)\
**Post date:** [February 19, 2023, 3:02am UTC](https://forum.djangoproject.com/t/authentication-issue/18936/16 "2023-02-19T03:02:58Z")

</div>

Yep, that would be it.

That gives you a couple different ways to do this.

First, you do have the option of using django-environ.

Second, you can use the env parameter on the ExecStart command to specify those settings with the command. (Or, on a related theme, you can put them in a configuration file and point gunicorn to use that file for its settings.)

Finally, there’s an Environment command available for within the service files. (See [Ubuntu Manpage: systemd.exec - Execution environment configuration](https://manpages.ubuntu.com/manpages/jammy/man5/systemd.exec.5.html#environment))

Any one of the three will work. The one you choose really is up to you - what makes the most sense to you.

---

<div class="post-metadata">

**Author:** ![mfreitas64](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/mfreitas64/32/10995_2.png) [@mfreitas64](https://forum.djangoproject.com/u/mfreitas64)\
**Post date:** [February 19, 2023, 3:44pm UTC](https://forum.djangoproject.com/t/authentication-issue/18936/17 "2023-02-19T15:44:31Z")

</div>

Ken, I’m trying with the django-environ option but now I get this error:

# SMTPServerDisconnected at /password-reset/

Connection unexpectedly closed

What could that be?

---

<div class="post-metadata">

**Author:** ![KenWhitesell](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/kenwhitesell/32/280_2.png) [@KenWhitesell](https://forum.djangoproject.com/u/KenWhitesell)\
**Post date:** [February 19, 2023, 6:55pm UTC](https://forum.djangoproject.com/t/authentication-issue/18936/18 "2023-02-19T18:55:18Z")

</div>

In the general case, that’s going to be caused by incorrect connection settings. It could be an incorrect password, or it could be some other connection setting. From what I can see _here_, my guess is that your password isn’t correct for the user you’re trying to use.

---

<div class="post-metadata">

**Author:** ![mfreitas64](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/mfreitas64/32/10995_2.png) [@mfreitas64](https://forum.djangoproject.com/u/mfreitas64)\
**Post date:** [February 19, 2023, 11:26pm UTC](https://forum.djangoproject.com/t/authentication-issue/18936/19 "2023-02-19T23:26:44Z")

</div>

Hi Ken, it’s working, finally! There was some incorrect information, you were right, has always. Thank you very much for this BIG BIG help.  
Cheers
