Skip to main content

DJANGO-SECRETS-FIELDS

❯ Encrypted fields in Django

license last-commit code-cov


🔗 Table of Contents


📍 Overview

Django encrypted fields with support for multiple backends, currently supports symmetric encryption using Fernet and AWS Secrets Manager. Two fields types are currently supported, SecretTextField and SecretJSONField.


👾 Features

  • Symmetric Encryption: Encrypt fields using Fernet encryption.
  • AWS Secrets Manager: Use AWS Secrets Manager as a backend for storing secrets.
  • Multiple Backends: Use multiple backends for different fields.

🚀 Getting Started

☑️ Prerequisites

Before getting started with django-secrets-fields, ensure your runtime environment meets the following requirements:

  • Programming Language: Python 3.10+

⚙️ Installation

Install django-secrets-fields:

pip install django-secrets-fields

To use backend that requires AWS install using:

pip install django-secrets-fields[aws]

🤖 Usage

settings.py

DJANGO_SECRETS_FIELDS = {
    "default": {
        "backend": "secrets_fields.backends.encrypted.EncryptedBackend",
        "encryption_key": b"<fernet key>",
    },
    "aws": {
        "backend": "secrets_fields.backends.secretsmanager.SecretsManagerBackend",
        "prefix": "/path/",
    },
}

# If you need to migrate from plaintext fields, set this value to True and run `manage.py migrate_encrypted` - this could take a long time depending on the number of models and instances.
DJANGO_SECRETS_FIELDS_MIGRATE = True

A Fernet key can be generated using the following command:

python manage.py generate_fernet_key

models.py

from django.db import models
from secrets_fields.fields import SecretJSONField, SecretTextField


class MyModel(models.Model):
	secret_text = SecretTextField(backend="aws")
	secret_json = SecretJSONField()

📌 Project Roadmap

  • Symmetric backend: Add symmetric encryption backend.
  • Asymmetric backedn: Add asymmetric encryption backend.
  • AWS Parameter Store: Add AWS Parameter Store backend.

🔰 Contributing

Contributing Guidelines
  1. Fork the Repository: Start by forking the project repository to your github account.
  2. Clone Locally: Clone the forked repository to your local machine using a git client.
    git clone https://github.com/ryan-shaw/django-secrets-fields
    
  3. Create a New Branch: Always work on a new branch, giving it a descriptive name.
    git checkout -b new-feature-x
    
  4. Make Your Changes: Develop and test your changes locally.
  5. Commit Your Changes: Commit with a clear message describing your updates.
    git commit -m 'Implemented new feature x.'
    
  6. Push to github: Push the changes to your forked repository.
    git push origin new-feature-x
    
  7. Submit a Pull Request: Create a PR against the original project repository. Clearly describe the changes and their motivations.
  8. Review: Once your PR is reviewed and approved, it will be merged into the main branch. Congratulations on your contribution!
Contributor Graph


🎗 License

This project is protected under the MIT License. For more details, refer to the LICENSE file.


Release files for django-secrets-fields 1.0.5

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for django-secrets-fields 1.0.5
File Size Uploaded
django_secrets_fields-1.0.5.tar.gz 10.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for django-secrets-fields 1.0.5
File Interpreter ABI Platform
django_secrets_fields-1.0.5-py3-none-any.whl Python 3 none any Details

Total release size: 22.9 kB

Release files / django_secrets_fields-1.0.5.tar.gz

Download URL django_secrets_fields-1.0.5.tar.gz
Size 10.4 kB
Tags Source
SHA-256 checksum
How to use checksums
c56b864387c806b00401e68657c0ba8c590888cbf496580ca21fe13b49521d9d
BLAKE2b-256 checksum
How to use checksums
7df14896b00da4cba6e1731b6d5d5cc0bb7d088864e268c5ac7e099bd66c06c9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.12.8

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Feb 6, 2025.

Transparency log

Release files / django_secrets_fields-1.0.5-py3-none-any.whl

Download URL django_secrets_fields-1.0.5-py3-none-any.whl
Size 12.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
b80386d6184ce85de1349b14adce8515ad6eaa6182ad9d67f677c50e4eca7b76
BLAKE2b-256 checksum
How to use checksums
8c9beb539ab7edc0bd8b45ff11d2a11e58797b1dd50e45a0d12ee32c3e6576bc
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.12.8

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Feb 6, 2025.

Transparency log
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page