django-security

Installation
Summary

Django security best practices covering authentication, authorization, CSRF, SQL injection, and XSS prevention.

  • Provides production-ready settings configurations including HTTPS enforcement, secure cookies, HSTS headers, and password validation with minimum 12-character requirements
  • Covers authentication patterns: custom user models, Argon2 password hashing, session management, and role-based access control (RBAC)
  • Includes authorization strategies: Django permissions, custom permission classes for REST APIs, and object-level access control mixins
  • Demonstrates SQL injection prevention via Django ORM, parameterized raw queries, and Q objects; XSS prevention through template auto-escaping and safe string handling
  • Addresses file upload validation, API rate limiting, Content Security Policy headers, and security event logging
SKILL.md

Django Security Best Practices

Comprehensive security guidelines for Django applications to protect against common vulnerabilities.

When to Activate

  • Setting up Django authentication and authorization
  • Implementing user permissions and roles
  • Configuring production security settings
  • Reviewing Django application for security issues
  • Deploying Django applications to production

Core Security Settings

Production Settings Configuration

# settings/production.py
import os
Related skills
Installs
4.4K
GitHub Stars
179.7K
First Seen
Feb 1, 2026