Django
Comprehensive guide to Django covering security, ORM, PostgreSQL, GeoDjango, Django 6.0 essentials, admin extensions, and ecosystem tools.
Overview
Django provides a batteries-included web framework with robust features out of the box:
- Security - CSRF protection, authentication, sessions, password hashing, security middleware
- ORM - Powerful database abstraction with query optimization
- PostgreSQL - Full-text search, array fields, JSONB, range fields
- GeoDjango - Geographic database operations with GPS extraction
- Django 6.0 - Middleware changes, built-in tasks framework, CSP, GeneratedField
- Admin Extensions - Operational dashboards and monitoring tools
Specialized Skills
For deeper coverage of specific domains, see these dedicated skills:
- ↳ django-admin — Admin save_formset/get_search_results/db_index patterns
- ↳ django-transaction — atomic/select_for_update/on_commit/upserts
Deep Dives
Load these reference files on demand for detailed coverage:
- ↳ security.md — CSRF protection, sessions, security middleware, field-level encryption
- ↳ authentication-permissions.md — Authentication views, custom backends, password management, login templates, Django permissions
- ↳ orm-performance.md — ORM optimization, caching, response time, materialized views
- ↳ postgresql.md — pgvector, GeneratedField, GeoDjango, PostgreSQL features
- ↳ django6-modern.md — Django Tasks framework, 6.0 essentials, multi-DB routing, model fields, app naming
- ↳ testing-migrations.md — Testing optimization, migrations, signals, StreamingHttpResponse
- ↳ external-api.md — Operational dashboards, external API integration
- ↳ ecosystem.md — Django ecosystem libraries
Best Practices
- Always use {% csrf_token %} in POST forms
- Use HTTPS in production (SECURE_SSL_REDIRECT = True)
- Enable HSTS for secure connections
- Set secure cookies (SESSION_COOKIE_SECURE = True)
- Use strong password validation
- Use @login_required for protected views
- Never expose sensitive data in URLs or logs
- Validate file uploads carefully
- Use prepared statements (Django ORM does this automatically)