# Login issue 'Please enter a correct username and password'

**URL:** <https://forum.djangoproject.com/t/login-issue-please-enter-a-correct-username-and-password/10774>\
**Category:** Using Django\
**Created:** [December 2, 2021, 1:21pm UTC](https://forum.djangoproject.com/t/login-issue-please-enter-a-correct-username-and-password/10774 "2021-12-02T13:21:05Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![pitagora04](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/pitagora04/32/1019_2.png) [@pitagora04](https://forum.djangoproject.com/u/pitagora04)\
**Post date:** [December 2, 2021, 1:21pm UTC](https://forum.djangoproject.com/t/login-issue-please-enter-a-correct-username-and-password/10774/1 "2021-12-02T13:21:05Z")

</div>

I created a dedicated app to handle the authentication and in this app I created a `login.html`.  
In the `urls.py` for this new app I added `path('accounts/', include('django.contrib.auth.urls'))`.  
When I enter the URL, I can normally see the login page.  
But when I enter credentials and try to login, I always get `Please enter a correct username and password. Note that both fields may be case-sensitive.` in `form.errors`.  
So I went into Django Admin and created additional user with superuser+active+staff and additionally I assigned to this user all possible permissions - but I still have the same issue (I’m typing the correct password - this is not the issue).  
Do you have any clue (based on what I described above), what could be the real issue behind ?

---

<div class="post-metadata">

**Author:** ![KenWhitesell](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/kenwhitesell/32/280_2.png) [@KenWhitesell](https://forum.djangoproject.com/u/KenWhitesell)\
**Post date:** [December 2, 2021, 1:46pm UTC](https://forum.djangoproject.com/t/login-issue-please-enter-a-correct-username-and-password/10774/2 "2021-12-02T13:46:33Z")

</div>

In general, if you’re trying to replace _just_ the system template for this, I’d start with doing a careful comparison between your template and the system default template.

> [@pitagora04](#):
>
> I created a dedicated app to handle the authentication and in this app I created a `login.html` .

Is “login.html” the only file in this app? Or are there also views and forms?

> [@pitagora04](#):
>
> In the `urls.py` for this new app I added `path('accounts/', include('django.contrib.auth.urls'))` .

This would imply to me that you’re trying to use the built-in Django views for this? Is your intent then that your `login.html` template to be used as replacement for the system default login page? If so, what’s the purpose of creating this as a separate app?

> [@pitagora04](#):
>
> When I enter the URL, I can normally see the login page.

What URL?

Which login page are you seeing? The system default page or your custom page?

---

<div class="post-metadata">

**Author:** ![pitagora04](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/pitagora04/32/1019_2.png) [@pitagora04](https://forum.djangoproject.com/u/pitagora04)\
**Post date:** [December 2, 2021, 2:57pm UTC](https://forum.djangoproject.com/t/login-issue-please-enter-a-correct-username-and-password/10774/3 "2021-12-02T14:57:08Z")

</div>

@KenWhitesell thank you for quick response. See my answers below.

> [@KenWhitesell](#):
>
> Is “login.html” the only file in this app? Or are there also views and forms?

login.html is the only file but it extends the html template from my other app where regular pages are.

> [@KenWhitesell](#):
>
> This would imply to me that you’re trying to use the built-in Django views for this? Is your intent then that your `login.html` template to be used as replacement for the system default login page? If so, what’s the purpose of creating this as a separate app?

Yes, the intent was to use my `login.html` since by reading the documentation I did not realized that there is `login.html` available out of the box - is it ?.  
The purpose of creating separate app was because I wanted to extend `AuthenticationForm` to add some more features to the form (recaptcha, widgets to define placeholders, etc.) but since I got the error described in my 1st post I went back to use default `AuthenticationForm` and default `path('accounts/', include('django.contrib.auth.urls'))` and wanted to make it works first this way.

> [@KenWhitesell](#):
>
> What URL?
> 
> Which login page are you seeing? The system default page or your custom page?

When I open `/accounts/login/` I see my custom login page.

---

<div class="post-metadata">

**Author:** ![KenWhitesell](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/kenwhitesell/32/280_2.png) [@KenWhitesell](https://forum.djangoproject.com/u/KenWhitesell)\
**Post date:** [December 2, 2021, 3:03pm UTC](https://forum.djangoproject.com/t/login-issue-please-enter-a-correct-username-and-password/10774/4 "2021-12-02T15:03:49Z")

</div>

> [@pitagora04](#):
>
> Yes, the intent was to use my `login.html` since by reading the documentation I did not realized that there is `login.html` available out of the box - is it ?.

Yes. If you don’t supply a template, the system uses a default form view. My first suggestion would be to remove/rename your login.html file to try using the standard form and see what happens. My guess is that your template doesn’t align with the form that Django uses for authentication.

---

<div class="post-metadata">

**Author:** ![pitagora04](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/pitagora04/32/1019_2.png) [@pitagora04](https://forum.djangoproject.com/u/pitagora04)\
**Post date:** [December 2, 2021, 7:37pm UTC](https://forum.djangoproject.com/t/login-issue-please-enter-a-correct-username-and-password/10774/5 "2021-12-02T19:37:29Z")

</div>

I’m getting

```auto
TemplateDoesNotExist at /accounts/login/
registration/login.html

```

In the same project I also use Django Admin for administrators - is that the problem ?

I did search `C:\Users\pitagora\AppData\Local\Programs\Python\Python38-32\Lib\site-packages` for `login.html` but I see only the one in Django Admin…

---

<div class="post-metadata">

**Author:** ![pitagora04](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/pitagora04/32/1019_2.png) [@pitagora04](https://forum.djangoproject.com/u/pitagora04)\
**Post date:** [December 2, 2021, 7:50pm UTC](https://forum.djangoproject.com/t/login-issue-please-enter-a-correct-username-and-password/10774/6 "2021-12-02T19:50:32Z")

</div>

I made additional test…

I created completely new project.  
I run makemigrations, migrate, createsuperuser, collectstatic…  
I created single test app.  
I added `path('accounts/', include('django.contrib.auth.urls'))` to proejct’s `urls.py`  
When I open `http://127.0.0.1:8000/accounts/login/` again I have this error:

```auto
TemplateDoesNotExist at /accounts/login/
registration/login.html

```

I’m using django 3.1.7.

---

<div class="post-metadata">

**Author:** ![KenWhitesell](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/kenwhitesell/32/280_2.png) [@KenWhitesell](https://forum.djangoproject.com/u/KenWhitesell)\
**Post date:** [December 2, 2021, 8:02pm UTC](https://forum.djangoproject.com/t/login-issue-please-enter-a-correct-username-and-password/10774/7 "2021-12-02T20:02:00Z")

</div>

Yep, my mistake. Core Django does not include a login.html page by default. There’s a sample at [Using the Django authentication system | Django documentation | Django](https://docs.djangoproject.com/en/3.2/topics/auth/default/#django.contrib.auth.views.LoginView) to use as a starting point, but that’s about it. I had gotten myself confused by looking at one of my projects that does something completely different.

Can you post your login.html template?

---

<div class="post-metadata">

**Author:** ![pitagora04](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/pitagora04/32/1019_2.png) [@pitagora04](https://forum.djangoproject.com/u/pitagora04)\
**Post date:** [December 2, 2021, 8:13pm UTC](https://forum.djangoproject.com/t/login-issue-please-enter-a-correct-username-and-password/10774/8 "2021-12-02T20:13:38Z")

</div>

Thanks for re-check !

Here is my `login.html`:

```auto
{% extends "myapp/_template.html" %}
{% load static %}
{% load thumbnail %}

{% block CONTENT %}

    {% if form.errors %}
        <p class="error">{{form.errors}}</p>
    {% endif %}

    {% if next %}
        {% if user.is_authenticated %}
        <p class="error">Your account doesn't have access to this page. To proceed, please login with an account that has access.</p>
        {% else %}
        <p class="error">Please login to see this page.</p>
        {% endif %}
    {% endif %}

    <form method="post" action="{% url 'myauth:login' %}">
        {% csrf_token %}
        <p>
        <span class="text-size-small">User:</span>
        {{ form.username }}
        </p>
        <p>
        <span class="text-size-small">Password:</span>
        {{ form.password }}
        </p>
        <p>
        {{ form.captcha }}
        </p>
    <button type="submit" class="btn btn-style-3" data-type="submit" value="login">Login</button>

    <input type="hidden" name="next" value="{{ next }}">
    </form>

    <p>
        <a href="{% url 'myauth:password_reset' %}" class="text-size-small">Lost password?</a>
    </p>
{% endblock %}

```

---

<div class="post-metadata">

**Author:** ![KenWhitesell](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/kenwhitesell/32/280_2.png) [@KenWhitesell](https://forum.djangoproject.com/u/KenWhitesell)\
**Post date:** [December 2, 2021, 8:27pm UTC](https://forum.djangoproject.com/t/login-issue-please-enter-a-correct-username-and-password/10774/9 "2021-12-02T20:27:58Z")

</div>

How did you set the password for the user you created?

---

<div class="post-metadata">

**Author:** ![pitagora04](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/pitagora04/32/1019_2.png) [@pitagora04](https://forum.djangoproject.com/u/pitagora04)\
**Post date:** [December 2, 2021, 8:53pm UTC](https://forum.djangoproject.com/t/login-issue-please-enter-a-correct-username-and-password/10774/10 "2021-12-02T20:53:50Z")

</div>

I was using Django Admin to create the user and set the password.

---

<div class="post-metadata">

**Author:** ![KenWhitesell](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/kenwhitesell/32/280_2.png) [@KenWhitesell](https://forum.djangoproject.com/u/KenWhitesell)\
**Post date:** [December 2, 2021, 8:56pm UTC](https://forum.djangoproject.com/t/login-issue-please-enter-a-correct-username-and-password/10774/11 "2021-12-02T20:56:09Z")

</div>

Ok. You mentioned you set all sorts of permissions on this user. Did you try to log on to the admin page with that user? (I’m trying to find a way to identify where the issue is being caused. I’m not seeing anything wrong with what you’ve posted, so I’m trying to think of things that will yield some useful information.)

---

<div class="post-metadata">

**Author:** ![pitagora04](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/pitagora04/32/1019_2.png) [@pitagora04](https://forum.djangoproject.com/u/pitagora04)\
**Post date:** [December 2, 2021, 10:00pm UTC](https://forum.djangoproject.com/t/login-issue-please-enter-a-correct-username-and-password/10774/12 "2021-12-02T22:00:18Z")

</div>

You’re right. The same error I got when logging in into Django Admin.  
So I tested my admin account, I can login into my custom `login.html` but for admin account I got:

```auto
Forbidden (403)
CSRF verification failed. Request aborted.

```

But this is some other issue, I assume…

---

<div class="post-metadata">

**Author:** ![KenWhitesell](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/kenwhitesell/32/280_2.png) [@KenWhitesell](https://forum.djangoproject.com/u/KenWhitesell)\
**Post date:** [December 2, 2021, 10:46pm UTC](https://forum.djangoproject.com/t/login-issue-please-enter-a-correct-username-and-password/10774/13 "2021-12-02T22:46:05Z")

</div>

> [@pitagora04](#):
>
> ```auto
> Forbidden (403)
> CSRF verification failed. Request aborted.
> 
> ```

I’m sorry, I’m confused by the previous sentence. What circumstance causes you to receive this error?

It could all be related. Can you post the middleware section of your settings file?

---

<div class="post-metadata">

**Author:** ![pitagora04](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/pitagora04/32/1019_2.png) [@pitagora04](https://forum.djangoproject.com/u/pitagora04)\
**Post date:** [December 3, 2021, 6:33pm UTC](https://forum.djangoproject.com/t/login-issue-please-enter-a-correct-username-and-password/10774/14 "2021-12-03T18:33:17Z")

</div>

When I try to login with admin account (created when the project was started) into my custom login, then I get:

```auto
Forbidden (403)
CSRF verification failed. Request aborted.

```

And middleware part in settings.py is:

```auto
MIDDLEWARE = [
    'django.middleware.security.SecurityMiddleware',
    'django.contrib.sessions.middleware.SessionMiddleware',
    'django.middleware.common.CommonMiddleware',
    'django.middleware.csrf.CsrfViewMiddleware',
    'django.contrib.auth.middleware.AuthenticationMiddleware',
    'django.contrib.messages.middleware.MessageMiddleware',
    'django.middleware.clickjacking.XFrameOptionsMiddleware',
]
```

---

<div class="post-metadata">

**Author:** ![KenWhitesell](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/kenwhitesell/32/280_2.png) [@KenWhitesell](https://forum.djangoproject.com/u/KenWhitesell)\
**Post date:** [December 3, 2021, 9:06pm UTC](https://forum.djangoproject.com/t/login-issue-please-enter-a-correct-username-and-password/10774/15 "2021-12-03T21:06:56Z")

</div>

I’m kinda stumpted at this point.

Have you changed or made any adjustments to any of the CSRF\_ settings in your settings file?

Is this form being submitted directly, or do you have some JavaScript actually performing the form submission?

---

<div class="post-metadata">

**Author:** ![awtimmering](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/awtimmering/32/4109_2.png) [@awtimmering](https://forum.djangoproject.com/u/awtimmering)\
**Post date:** [December 4, 2021, 3:29am UTC](https://forum.djangoproject.com/t/login-issue-please-enter-a-correct-username-and-password/10774/16 "2021-12-04T03:29:29Z")

</div>

I might be mistaken but I don’t think you can set the password from the admin. Could you try setting the password with `manage.py changepassword`?

I know the admin has a password field, but it’s the hashed password - so setting an actual password there doesn’t work IIRC.

---

<div class="post-metadata">

**Author:** ![KenWhitesell](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/kenwhitesell/32/280_2.png) [@KenWhitesell](https://forum.djangoproject.com/u/KenWhitesell)\
**Post date:** [December 4, 2021, 11:31am UTC](https://forum.djangoproject.com/t/login-issue-please-enter-a-correct-username-and-password/10774/17 "2021-12-04T11:31:48Z")

</div>

The current admin _does_ provide a facility for doing that. I’ve attached a screenshot showing what the standard default user page looks like in admin:

 ![image](https://us1.discourse-cdn.com/flex026/uploads/djangoproject/original/2X/6/65148257f01fb04e24e8627f632d89fc1b843bfd.png)

Now, if you’re using a custom User class or a custom User Admin page, your results may vary.

---

<div class="post-metadata">

**Author:** ![pitagora04](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/pitagora04/32/1019_2.png) [@pitagora04](https://forum.djangoproject.com/u/pitagora04)\
**Post date:** [December 4, 2021, 7:18pm UTC](https://forum.djangoproject.com/t/login-issue-please-enter-a-correct-username-and-password/10774/18 "2021-12-04T19:18:18Z")

</div>

Hm, after doing `manage.py changepassword` I really can login… Thanks.
