Ishga tushirishdan oldin Django xavfsizlik ro‘yxati
Django loyihangizni eng keng tarqalgan hujumlardan himoya qiluvchi o‘nta sozlama va odat.
Bu maqola hozircha faqat ingliz tilida mavjud.
Django is secure by default, but a few settings must be changed before production. Run python manage.py check --deploy and go through this list.
Settings
DEBUG = False— never expose stack traces.- Keep
SECRET_KEYin an environment variable, never in Git. - Set
ALLOWED_HOSTSexplicitly. SECURE_SSL_REDIRECT = TrueandSECURE_HSTS_SECONDS = 31536000.SESSION_COOKIE_SECURE = TrueandCSRF_COOKIE_SECURE = True.
Habits
- Never build SQL with string formatting. Use the ORM or query parameters.
- Escape output. Avoid
|safeandmark_safeon user input. - Validate uploads — check size and type, and never serve them from the app domain without care.
- Rate-limit login and forms (e.g.
django-axesor DRF throttling). - Keep dependencies updated —
pip list --outdatedand GitHub Dependabot.
Admin
Move the admin from /admin/ to a non-obvious URL, enforce strong passwords and consider 2FA with django-otp.
Security is not a one-time task, but these ten points close the doors most attackers try first.