Git Product home page Git Product logo

master's Introduction

Django roles access

Django Roles Access

Build Status codecov

Application for securing access to views with roles (Django contrib Groups).

django_roles_access is a Django app for securing access to views. It's built on top of Django contrib Groups interpreted as role. The objective of the app are:

  • Provide secure access to views.

  • Be able to administrate access to views without the need to restart the server (at run time).

  • Minimize the need of new code, or eliminate it at all (when using django_roles_access middleware). Also free developers from the task of coding any view access.

  • django_roles_access also provides a security report by registering checkviewaccess action.

Works with:

  • Django 1.10+ (Python 2.7, Python 3.5+)

  • Django 2 (Python 3.5+)

  • Documentation

Requirements

Django roles access use Django contrib Groups, Django contrib User. Also Django admin interface is necessary to create and administrate views access (django_roles_access.models.ViewAccess). So Django roles access is dependent of Django admin site and because of this it has the same requirements than it. This can be checked in the official documentation:

Quick start

Installation and configuration

  1. Install django_roles_access from pypi:

    pip install django-roles-access

  2. Add 'django_roles_access' to your INSTALLED_APPS setting:

    INSTALLED_APPS = [ ... 'django_roles_access', ]

  3. Run migrations to create the django_roles_access models:

    python manage.py migrate

Note:

If nothing else is done, then Django site security keeps without modification.

Access configuration

Quick view access configuration in two steps.

Step 1

In Django admin interface create a django_roles_access.models.ViewAccess object and configure it:

  1. view attribute: name of the view you to be secured. Format used: <app_name:view_name>( Namespaces and View name).

  2. type attribute: select the access type for the view:

    • Public: Any visitor can access the view.

    • Authorized: Only authorized (logged) Django contrib User can access the view.

    • By roles: Only Django contrib User belonging to any added Django contrib user will access the view.

  3. roles attribute: When By roles is selected as access type, this attribute hold any Django contrib Group whose members will access the view.

Step 2

In the view to be secured use:

For example:

In case of view is a function:

from django_roles_access.decorators import access_by_role

@access_by_role()
myview(request):
   ...

In case of classes based views use mixin:

from django_roles_access.mixin import RolesMixin

class MyView(RolesMixin, View):

    ...

Note:

When user has no access to a view, by default django_roles_access response with django.http.HttpResponseForbidden.

Warning:

Pre existent security behavior can be modified if a django_roles_access configuration for the same view results in a more restricted view access.

Test Django roles access

You can check the django_roles_access test execution at Travis CI integration (Build Status)

You can also check dajngo_roles_access test coverage at Coverage (codecov)

Or:

  1. Create a virtual environment.

  2. Get into and activate virtual environment.

  3. Clone django_roles_access:

    git clone https://github.com/django-roles-access/master.git

  4. Install tox:

    pip install tox

  5. Run the tests:

    tox

Related sites

master's People

Contributors

vicente-ramos avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar

master's Issues

Checkviewaccess by roles or views

Make possible to filter access to views report by a list of roles or views.

Documentation proposed as starting point for BDD:

Roles security

It is also possible to use checkviewaccess using a role name (
:class:django.contrib.auth.models.Group name) for getting all views where
such role have access:

python manage.py checkviewaccess <role_name>

Views security

If in place of role name, checkviewaccess is used with a view name, It
will report the configured access to the view (configured with Django roles
tools):

python manage.py checkviewaccess <view_name>

Add Disabled as application type

Actually an application can have 4 type:

  • Not Configured
  • NOT_SECURED
  • PUBLIC
  • SECURED

Add a new type: ‘DISABLED’, with default behavior disabling all access to the views of the application.
An advantage could be, for example, install a new application and keep it “off-line” for a while.

checkviewaccess output in csv format

checkviewaccess should output information with csv format so it can be imported by other tool.

Documentation proposed as starting point for BDD:

Output format

Is possible to export site’s view access in csv format with the next columns:

  • App Name: Application name to which belong the view being reported.

  • Type: ['None','NOT_SECURED', 'PUBLIC', 'SECURED']

  • View Name: The name of the vie or blank.

  • Url: The regex (django 1.10 and django 1.11) or pattern (django 2+)

  • Status: Normal, Warning, Error.

  • Status description: If there is a description for the state it should be reported here; eg cause of error or warning.

    python manage.py checkviewaccess --output-format csv

Add new field to ViewAccess and TemplateAccess

Add to both model next generic fields:
• description (text)
• created (datetime)
• updated (datetime)

ViewAccess data model can add next fields:
#: Description for the view access restriction.

#: When view access was created.

#: When was the last update of the view access.

TemplateAccess data model can add next fields:
#: Description for the template tag restriction.

#: When template tag was created.

#: When was the last update of the template tag.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.