Ask a Question
Ask Question Login
Corporate Training
  1. Community
  2. SQL Server
  3. Question
SQL Server

Is it secure for me to use a Django https site only?

Asked by Anisha Dalal Dec 24, 2021 520 views 1 answer
Share

About this question

 Is it really secure for me to make a Django based site use HTTPS only? Will it provide at least as much security as a standard HTTPS-only site would have? Is the fact that Django transmits a http-prefix URL, enough to compromise its security?

I came across some lines regarding Django security that were enough to pique my interest - Using Django templates protects you against the majority of XSS attacks. However it is possible to turn off this protection, and the protection isn't automatically applied to all tags that wouldn't normally be populated by user input (for example, the help_text in a form field is usually not user-supplied, so Django doesn't escape those values).

It is also possible for XSS attacks to originate from other untrusted source of data, such as cookies, Web services or uploaded files (whenever the data is not sufficiently sanitized before including in a page). If you're displaying data from these sources, then you may need to add your own sanitisation code.

Your answer

1 Answer

More SQL Server discussions

Learn & Explore

Free tutorials and interview questions from industry experts — learn the skill, then get ready to prove it.

Latest SQL Server Blogs

Guides, tips and career advice on SQL Server from JanBask experts.