Перейти к содержимому
Все статьи
Security

Чек-лист безопасности Django перед запуском

Десять настроек и привычек, которые защищают Django-проект от самых распространённых атак.

Temurbek Murotov 1 мин чтения

Эта статья пока доступна только на английском языке.

Django is secure by default, but a few settings must be changed before production. Run python manage.py check --deploy and go through this list.

Settings

  1. DEBUG = False — never expose stack traces.
  2. Keep SECRET_KEY in an environment variable, never in Git.
  3. Set ALLOWED_HOSTS explicitly.
  4. SECURE_SSL_REDIRECT = True and SECURE_HSTS_SECONDS = 31536000.
  5. SESSION_COOKIE_SECURE = True and CSRF_COOKIE_SECURE = True.

Habits

  1. Never build SQL with string formatting. Use the ORM or query parameters.
  2. Escape output. Avoid |safe and mark_safe on user input.
  3. Validate uploads — check size and type, and never serve them from the app domain without care.
  4. Rate-limit login and forms (e.g. django-axes or DRF throttling).
  5. Keep dependencies updated — pip list --outdated and GitHub Dependabot.

Admin

Move the admin from /admin/ to a non-obvious URL, enforce strong passwords and consider 2FA with django-otp.

Security is not a one-time task, but these ten points close the doors most attackers try first.

  • #django
  • #security
  • #best-practices
Поделиться:

Похожие статьи

Есть идея проекта?

Давайте превратим её в надёжный продукт. Первая консультация и оценка — бесплатно.