Python and Django utilities for encrypted fields using pgcrypto.
Project description
django-pgcrypto
A set of utility functions for dealing with ASCII Armor (http://www.ietf.org/rfc/rfc2440.txt) and padding, and a collection of Django field classes that utilize these functions in a way that is compatible with pgcrypto functions.
Installation
pip install django-pgcrypto
Quickstart
There are several encrypted versions of Django fields that you can use (mostly) as you would use a normal Django field:
from django.db import models
import pgcrypto
class Employee (models.Model):
name = models.CharField(max_length=100)
ssn = pgcrypto.EncryptedTextField()
pay_rate = pgcrypto.EncryptedDecimalField()
date_hired = pgcrypto.EncryptedDateField(cipher="bf", key="datekey", auto_now_add=True)
If not specified when creating the field (as in ssn
and pay_rate
above), fields are encrypted according to the following settings:
PGCRYPTO_DEFAULT_CIPHER
(aes
orbf
, default:aes
) - The default algorithm to use when encrypting fields.PGCRYPTO_DEFAULT_KEY
(default:settings.SECRET_KEY
) - The default key to use for encryption.
You must also make sure the pgcrypto extension is installed in your database. Django makes this easy with a CryptoExtension migration.
Querying
It is possible to filter on encrypted fields as you would normal fields via exact
, gt
, gte
, lt
, and lte
lookups. For example, querying the model above is possible like so:
Employee.objects.filter(date_hired__gt="1981-01-01", salary__lt=60000)
Caveats
This library encrypts and encodes data in a way that works with pgcrypto's raw encryption functions. All the warnings there about using direct keys and the lack of integrity checking apply here.
This library also predates Django's BinaryField, which is why the fields are essentially TextField
s that store armored encrypted data. This may or may not be ideal for your application, and a hypothetical future version might include a switch to store binary data.
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distributions
Built Distribution
File details
Details for the file django_pgcrypto-2.0.0-py3-none-any.whl
.
File metadata
- Download URL: django_pgcrypto-2.0.0-py3-none-any.whl
- Upload date:
- Size: 8.6 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/3.2.0 pkginfo/1.5.0.1 requests/2.24.0 setuptools/40.8.0 requests-toolbelt/0.9.1 tqdm/4.48.2 CPython/3.7.4
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | 0c64e947f5d1a71efe3ba5ea125aa565ecb26d35e7e33fe1ae4a3c6968ac9a8f |
|
MD5 | f88cb32550de0983d8f01b9a8aa0cee5 |
|
BLAKE2b-256 | 7bd0e9b4f93edeb4828c6da2cb806f103ae216282648edcca0025e3a564fcd37 |