Asosiy qismga o‘tish
Barcha maqolalar
Security

Ishga tushirishdan oldin Django xavfsizlik ro‘yxati

Django loyihangizni eng keng tarqalgan hujumlardan himoya qiluvchi o‘nta sozlama va odat.

Temurbek Murotov 1 daqiqa o‘qish

Bu maqola hozircha faqat ingliz tilida mavjud.

Django is secure by default, but a few settings must be changed before production. Run python manage.py check --deploy and go through this list.

Settings

  1. DEBUG = False — never expose stack traces.
  2. Keep SECRET_KEY in an environment variable, never in Git.
  3. Set ALLOWED_HOSTS explicitly.
  4. SECURE_SSL_REDIRECT = True and SECURE_HSTS_SECONDS = 31536000.
  5. SESSION_COOKIE_SECURE = True and CSRF_COOKIE_SECURE = True.

Habits

  1. Never build SQL with string formatting. Use the ORM or query parameters.
  2. Escape output. Avoid |safe and mark_safe on user input.
  3. Validate uploads — check size and type, and never serve them from the app domain without care.
  4. Rate-limit login and forms (e.g. django-axes or DRF throttling).
  5. Keep dependencies updated — pip list --outdated and GitHub Dependabot.

Admin

Move the admin from /admin/ to a non-obvious URL, enforce strong passwords and consider 2FA with django-otp.

Security is not a one-time task, but these ten points close the doors most attackers try first.

  • #django
  • #security
  • #best-practices
Ulashish:

O‘xshash maqolalar

Loyiha g‘oyangiz bormi?

Keling, uni ishonchli mahsulotga aylantiramiz. Birinchi konsultatsiya va baho — bepul.