Think Build Implement Repeat
London, UK +44 7367 067226
WhatsApp FOLLOW f in X
  1. Home
  2. Blog
  3. What to Check Before and After Launch
Python & Django

What to Check Before and After Launch

A Django security checklist beyond the defaults: authorisation logic, file handling, dependency updates, production settings and the deployment check.

Updated 2 min readBy SpiderHunts Technologies

Free estimateNo obligation

Get a free estimate

Tell us what you need. A senior engineer reads every enquiry.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →

Quick answer — TL;DR

Django's defaults cover the common web vulnerabilities well. What remains is your authorisation logic, file handling, dependency currency and production configuration.

The defaults do a lot

Django protects against injection through the ORM, escapes template output by default, includes cross-site request forgery protection and provides sensible password hashing.

Most Django vulnerabilities are in code that worked around the defaults: raw SQL with string formatting, marked-safe template output, or exempted CSRF views.

What still needs your attention

  1. Authorisation — record-level access, which Django does not provide
  2. File uploads — where they are stored and how they are served
  3. Dependencies — audited automatically on every build
  4. Production settings — debug, hosts, cookies, HTTPS
  5. Secrets — out of the repository, rotated

Where the defaults get bypassed

BypassRisk
Raw SQL with string formattingInjection
Marking user content as safeCross-site scripting
CSRF exemption on a viewRequest forgery
Serving media from the code directoryCode execution
Disabling checks to make something workWhatever they protected against

Each of those has a legitimate use and each should be an explicit, reviewed decision rather than a convenience.

Run the built-in check

Django includes a deployment check that reports on production configuration. Running it before launch catches the common misconfigurations in seconds.

It should be part of the deployment pipeline rather than something someone remembers to run.

Test authorisation adversarially

  • Two accounts trying to reach each other's records
  • Direct URL access with another user's identifiers
  • Exports and API endpoints, not just screens
  • Admin access, which is powerful and frequently over-granted

FAQ

Frequently asked questions

The questions readers ask us after this guide.

Still have a question?

Ask us directly — a senior engineer will get back to you.

Ask about your project

Is Django secure by default?

Against the common web vulnerabilities, largely. Your authorisation logic and configuration are where the remaining risk sits.

How often should we audit dependencies?

Automatically on every build. Security updates applied within days.

What about the admin?

Powerful, and access should be restricted to those who need it. Log and review admin actions.

Do we need a web application firewall?

As an additional layer it adds value. It is not a substitute for the checks above.

Keep reading

More on Python & Django

Python & Django

An API Other Systems Can Depend On

Designing a Python API service others can depend on: validation at the boundary, consistent errors and status codes, early versioning and documentation.

Python & Django

Moving and Transforming Data Reliably

Building data pipelines in Python that cope with malformed input: restartable stages, quarantining failures, reconciling counts and alerting on absence.

Start here

Never run the deployment check?

It takes seconds and it catches the common production misconfigurations. Worth doing today.

  1. You tell us what you needTwo minutes on the form, or a message on WhatsApp.
  2. A senior engineer reviews itAnd comes back with questions, a realistic range and an honest view on fit.
  3. Free 30-minute scoping callWe talk through scope, options and a realistic estimate — with no obligation.
Free estimateNo obligation

Talk to someone who builds this

Send a short brief and we will come back with an honest view and a realistic range.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →