validation.txt 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418
  1. .. currentmodule:: django.forms
  2. .. _form-and-field-validation:
  3. Form and field validation
  4. =========================
  5. Form validation happens when the data is cleaned. If you want to customize
  6. this process, there are various places you can change, each one serving a
  7. different purpose. Three types of cleaning methods are run during form
  8. processing. These are normally executed when you call the ``is_valid()``
  9. method on a form. There are other things that can trigger cleaning and
  10. validation (accessing the ``errors`` attribute or calling ``full_clean()``
  11. directly), but normally they won't be needed.
  12. In general, any cleaning method can raise ``ValidationError`` if there is a
  13. problem with the data it is processing, passing the relevant information to
  14. the ``ValidationError`` constructor. :ref:`See below <raising-validation-error>`
  15. for the best practice in raising ``ValidationError``. If no ``ValidationError``
  16. is raised, the method should return the cleaned (normalized) data as a Python
  17. object.
  18. Most validation can be done using `validators`_ - simple helpers that can be
  19. reused easily. Validators are simple functions (or callables) that take a single
  20. argument and raise ``ValidationError`` on invalid input. Validators are run
  21. after the field's ``to_python`` and ``validate`` methods have been called.
  22. Validation of a Form is split into several steps, which can be customized or
  23. overridden:
  24. * The ``to_python()`` method on a Field is the first step in every
  25. validation. It coerces the value to correct datatype and raises
  26. ``ValidationError`` if that is not possible. This method accepts the raw
  27. value from the widget and returns the converted value. For example, a
  28. FloatField will turn the data into a Python ``float`` or raise a
  29. ``ValidationError``.
  30. * The ``validate()`` method on a Field handles field-specific validation
  31. that is not suitable for a validator, It takes a value that has been
  32. coerced to correct datatype and raises ``ValidationError`` on any error.
  33. This method does not return anything and shouldn't alter the value. You
  34. should override it to handle validation logic that you can't or don't
  35. want to put in a validator.
  36. * The ``run_validators()`` method on a Field runs all of the field's
  37. validators and aggregates all the errors into a single
  38. ``ValidationError``. You shouldn't need to override this method.
  39. * The ``clean()`` method on a Field subclass. This is responsible for
  40. running ``to_python``, ``validate`` and ``run_validators`` in the correct
  41. order and propagating their errors. If, at any time, any of the methods
  42. raise ``ValidationError``, the validation stops and that error is raised.
  43. This method returns the clean data, which is then inserted into the
  44. ``cleaned_data`` dictionary of the form.
  45. * The ``clean_<fieldname>()`` method in a form subclass -- where
  46. ``<fieldname>`` is replaced with the name of the form field attribute.
  47. This method does any cleaning that is specific to that particular
  48. attribute, unrelated to the type of field that it is. This method is not
  49. passed any parameters. You will need to look up the value of the field
  50. in ``self.cleaned_data`` and remember that it will be a Python object
  51. at this point, not the original string submitted in the form (it will be
  52. in ``cleaned_data`` because the general field ``clean()`` method, above,
  53. has already cleaned the data once).
  54. For example, if you wanted to validate that the contents of a
  55. ``CharField`` called ``serialnumber`` was unique,
  56. ``clean_serialnumber()`` would be the right place to do this. You don't
  57. need a specific field (it's just a ``CharField``), but you want a
  58. formfield-specific piece of validation and, possibly,
  59. cleaning/normalizing the data.
  60. This method should return the cleaned value obtained from cleaned_data,
  61. regardless of whether it changed anything or not.
  62. * The Form subclass's ``clean()`` method. This method can perform
  63. any validation that requires access to multiple fields from the form at
  64. once. This is where you might put in things to check that if field ``A``
  65. is supplied, field ``B`` must contain a valid email address and the
  66. like. This method can return a completely different dictionary if it wishes,
  67. which will be used as the ``cleaned_data``.
  68. Since the field validation methods have been run by the time ``clean()`` is
  69. called, you also have access to the form's errors attribute which
  70. contains all the errors raised by cleaning of individual fields.
  71. Note that any errors raised by your :meth:`Form.clean()` override will not
  72. be associated with any field in particular. They go into a special
  73. "field" (called ``__all__``), which you can access via the
  74. :meth:`~django.forms.Form.non_field_errors` method if you need to. If you
  75. want to attach errors to a specific field in the form, you need to call
  76. :meth:`~django.forms.Form.add_error()`.
  77. Also note that there are special considerations when overriding
  78. the ``clean()`` method of a ``ModelForm`` subclass. (see the
  79. :ref:`ModelForm documentation
  80. <overriding-modelform-clean-method>` for more information)
  81. These methods are run in the order given above, one field at a time. That is,
  82. for each field in the form (in the order they are declared in the form
  83. definition), the ``Field.clean()`` method (or its override) is run, then
  84. ``clean_<fieldname>()``. Finally, once those two methods are run for every
  85. field, the `:meth:`Form.clean()` method, or its override, is executed whether
  86. or not the previous methods have raised errors.
  87. Examples of each of these methods are provided below.
  88. As mentioned, any of these methods can raise a ``ValidationError``. For any
  89. field, if the ``Field.clean()`` method raises a ``ValidationError``, any
  90. field-specific cleaning method is not called. However, the cleaning methods
  91. for all remaining fields are still executed.
  92. .. _raising-validation-error:
  93. Raising ``ValidationError``
  94. ---------------------------
  95. In order to make error messages flexible and easy to override, consider the
  96. following guidelines:
  97. * Provide a descriptive error ``code`` to the constructor::
  98. # Good
  99. ValidationError(_('Invalid value'), code='invalid')
  100. # Bad
  101. ValidationError(_('Invalid value'))
  102. * Don't coerce variables into the message; use placeholders and the ``params``
  103. argument of the constructor::
  104. # Good
  105. ValidationError(
  106. _('Invalid value: %(value)s'),
  107. params={'value': '42'},
  108. )
  109. # Bad
  110. ValidationError(_('Invalid value: %s') % value)
  111. * Use mapping keys instead of positional formatting. This enables putting
  112. the variables in any order or omitting them altogether when rewriting the
  113. message::
  114. # Good
  115. ValidationError(
  116. _('Invalid value: %(value)s'),
  117. params={'value': '42'},
  118. )
  119. # Bad
  120. ValidationError(
  121. _('Invalid value: %s'),
  122. params=('42',),
  123. )
  124. * Wrap the message with ``gettext`` to enable translation::
  125. # Good
  126. ValidationError(_('Invalid value'))
  127. # Bad
  128. ValidationError('Invalid value')
  129. Putting it all together::
  130. raise ValidationError(
  131. _('Invalid value: %(value)s'),
  132. code='invalid',
  133. params={'value': '42'},
  134. )
  135. Following these guidelines is particularly necessary if you write reusable
  136. forms, form fields, and model fields.
  137. While not recommended, if you are at the end of the validation chain
  138. (i.e. your form ``clean()`` method) and you know you will *never* need
  139. to override your error message you can still opt for the less verbose::
  140. ValidationError(_('Invalid value: %s') % value)
  141. .. versionadded:: 1.7
  142. The :meth:`Form.errors.as_data() <django.forms.Form.errors.as_data()>` and
  143. :meth:`Form.errors.as_json() <django.forms.Form.errors.as_json()>` methods
  144. greatly benefit from fully featured ``ValidationError``\s (with a ``code`` name
  145. and a ``params`` dictionary).
  146. Raising multiple errors
  147. ~~~~~~~~~~~~~~~~~~~~~~~
  148. If you detect multiple errors during a cleaning method and wish to signal all
  149. of them to the form submitter, it is possible to pass a list of errors to the
  150. ``ValidationError`` constructor.
  151. As above, it is recommended to pass a list of ``ValidationError`` instances
  152. with ``code``\s and ``params`` but a list of strings will also work::
  153. # Good
  154. raise ValidationError([
  155. ValidationError(_('Error 1'), code='error1'),
  156. ValidationError(_('Error 2'), code='error2'),
  157. ])
  158. # Bad
  159. raise ValidationError([
  160. _('Error 1'),
  161. _('Error 2'),
  162. ])
  163. Using validation in practice
  164. ----------------------------
  165. The previous sections explained how validation works in general for forms.
  166. Since it can sometimes be easier to put things into place by seeing each
  167. feature in use, here are a series of small examples that use each of the
  168. previous features.
  169. .. _validators:
  170. Using validators
  171. ~~~~~~~~~~~~~~~~
  172. Django's form (and model) fields support use of simple utility functions and
  173. classes known as validators. A validator is merely a callable object or
  174. function that takes a value and simply returns nothing if the value is valid or
  175. raises a :exc:`~django.core.exceptions.ValidationError` if not. These can be
  176. passed to a field's constructor, via the field's ``validators`` argument, or
  177. defined on the :class:`~django.forms.Field` class itself with the
  178. ``default_validators`` attribute.
  179. Simple validators can be used to validate values inside the field, let's have
  180. a look at Django's ``SlugField``::
  181. from django.forms import CharField
  182. from django.core import validators
  183. class SlugField(CharField):
  184. default_validators = [validators.validate_slug]
  185. As you can see, ``SlugField`` is just a ``CharField`` with a customized
  186. validator that validates that submitted text obeys to some character rules.
  187. This can also be done on field definition so::
  188. slug = forms.SlugField()
  189. is equivalent to::
  190. slug = forms.CharField(validators=[validators.validate_slug])
  191. Common cases such as validating against an email or a regular expression can be
  192. handled using existing validator classes available in Django. For example,
  193. ``validators.validate_slug`` is an instance of
  194. a :class:`~django.core.validators.RegexValidator` constructed with the first
  195. argument being the pattern: ``^[-a-zA-Z0-9_]+$``. See the section on
  196. :doc:`writing validators </ref/validators>` to see a list of what is already
  197. available and for an example of how to write a validator.
  198. Form field default cleaning
  199. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  200. Let's firstly create a custom form field that validates its input is a string
  201. containing comma-separated email addresses. The full class looks like this::
  202. from django import forms
  203. from django.core.validators import validate_email
  204. class MultiEmailField(forms.Field):
  205. def to_python(self, value):
  206. "Normalize data to a list of strings."
  207. # Return an empty list if no input was given.
  208. if not value:
  209. return []
  210. return value.split(',')
  211. def validate(self, value):
  212. "Check if value consists only of valid emails."
  213. # Use the parent's handling of required fields, etc.
  214. super(MultiEmailField, self).validate(value)
  215. for email in value:
  216. validate_email(email)
  217. Every form that uses this field will have these methods run before anything
  218. else can be done with the field's data. This is cleaning that is specific to
  219. this type of field, regardless of how it is subsequently used.
  220. Let's create a simple ``ContactForm`` to demonstrate how you'd use this
  221. field::
  222. class ContactForm(forms.Form):
  223. subject = forms.CharField(max_length=100)
  224. message = forms.CharField()
  225. sender = forms.EmailField()
  226. recipients = MultiEmailField()
  227. cc_myself = forms.BooleanField(required=False)
  228. Simply use ``MultiEmailField`` like any other form field. When the
  229. ``is_valid()`` method is called on the form, the ``MultiEmailField.clean()``
  230. method will be run as part of the cleaning process and it will, in turn, call
  231. the custom ``to_python()`` and ``validate()`` methods.
  232. Cleaning a specific field attribute
  233. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  234. Continuing on from the previous example, suppose that in our ``ContactForm``,
  235. we want to make sure that the ``recipients`` field always contains the address
  236. ``"fred@example.com"``. This is validation that is specific to our form, so we
  237. don't want to put it into the general ``MultiEmailField`` class. Instead, we
  238. write a cleaning method that operates on the ``recipients`` field, like so::
  239. from django import forms
  240. class ContactForm(forms.Form):
  241. # Everything as before.
  242. ...
  243. def clean_recipients(self):
  244. data = self.cleaned_data['recipients']
  245. if "fred@example.com" not in data:
  246. raise forms.ValidationError("You have forgotten about Fred!")
  247. # Always return the cleaned data, whether you have changed it or
  248. # not.
  249. return data
  250. Sometimes you may want to add an error message to a particular field from the
  251. form's :meth:`~Form.clean()` method, in which case you can use
  252. :meth:`~django.forms.Form.add_error()`. Note that this won't always be
  253. appropriate and the more typical situation is to raise a ``ValidationError``
  254. from , which is turned into a form-wide error that is available through the
  255. :meth:`Form.non_field_errors() <django.forms.Form.non_field_errors>` method.
  256. .. _validating-fields-with-clean:
  257. Cleaning and validating fields that depend on each other
  258. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  259. Suppose we add another requirement to our contact form: if the ``cc_myself``
  260. field is ``True``, the ``subject`` must contain the word ``"help"``. We are
  261. performing validation on more than one field at a time, so the form's
  262. :meth:`~Form.clean()` method is a good spot to do this. Notice that we are
  263. talking about the ``clean()`` method on the form here, whereas earlier we were
  264. writing a ``clean()`` method on a field. It's important to keep the field and
  265. form difference clear when working out where to validate things. Fields are
  266. single data points, forms are a collection of fields.
  267. By the time the form's ``clean()`` method is called, all the individual field
  268. clean methods will have been run (the previous two sections), so
  269. ``self.cleaned_data`` will be populated with any data that has survived so
  270. far. So you also need to remember to allow for the fact that the fields you
  271. are wanting to validate might not have survived the initial individual field
  272. checks.
  273. There are two ways to report any errors from this step. Probably the most
  274. common method is to display the error at the top of the form. To create such
  275. an error, you can raise a ``ValidationError`` from the ``clean()`` method. For
  276. example::
  277. from django import forms
  278. class ContactForm(forms.Form):
  279. # Everything as before.
  280. ...
  281. def clean(self):
  282. cleaned_data = super(ContactForm, self).clean()
  283. cc_myself = cleaned_data.get("cc_myself")
  284. subject = cleaned_data.get("subject")
  285. if cc_myself and subject:
  286. # Only do something if both fields are valid so far.
  287. if "help" not in subject:
  288. raise forms.ValidationError("Did not send for 'help' in "
  289. "the subject despite CC'ing yourself.")
  290. .. versionchanged:: 1.7
  291. In previous versions of Django, ``form.clean()`` was required to return
  292. a dictionary of ``cleaned_data``. This method may still return a dictionary
  293. of data to be used, but it's no longer required.
  294. In this code, if the validation error is raised, the form will display an
  295. error message at the top of the form (normally) describing the problem.
  296. Note that the call to ``super(ContactForm, self).clean()`` in the example code
  297. ensures that any validation logic in parent classes is maintained.
  298. The second approach might involve assigning the error message to one of the
  299. fields. In this case, let's assign an error message to both the "subject" and
  300. "cc_myself" rows in the form display. Be careful when doing this in practice,
  301. since it can lead to confusing form output. We're showing what is possible
  302. here and leaving it up to you and your designers to work out what works
  303. effectively in your particular situation. Our new code (replacing the previous
  304. sample) looks like this::
  305. from django import forms
  306. class ContactForm(forms.Form):
  307. # Everything as before.
  308. ...
  309. def clean(self):
  310. cleaned_data = super(ContactForm, self).clean()
  311. cc_myself = cleaned_data.get("cc_myself")
  312. subject = cleaned_data.get("subject")
  313. if cc_myself and subject and "help" not in subject:
  314. msg = "Must put 'help' in subject when cc'ing yourself."
  315. self.add_error('cc_myself', msg)
  316. self.add_error('subject', msg)
  317. The second argument of ``add_error()`` can be a simple string, or preferably
  318. an instance of ``ValidationError``. See :ref:`raising-validation-error` for
  319. more details. Note that ``add_error()`` automatically removes the field
  320. from ``cleaned_data``.