Skip to main content
Django SSL Slapper
===================

Django-SSL-Slapper is a middleware that allows you to set urls to ssl only. It can also redirects anonymous users off your https service onto your http. Logged-in users may also be directed to https.

Django-SSL-Slapper can also use cache to count the number of login attempts and slap away excessive entries (default more than 20 per minute). THe user account is temporary locked for a timer period (default 1 minute). The default settings should disrupt automated attempts for entry without bothering even the quickest users.

Installation
------------

```pip install django-ssl-slapper```

Add ```'ssl_slapper.middleware.ssl_redirect'``` to middleware in your django settings file for redirection

Add ```'ssl_slapper.middleware.rate_limit'``` to middleware in your django settings file for rate_limiting. You will want to enable memcache for this.

It is recommended that you set ```SESSION_COOKIE_SECURE = True``` to ensure that your site is secured to use https only for authenticated users.

That's it! The middleware shuld automatically detect your login pages and slap away!

SSL_Redirect Settings
--------

```SSL_SLAPPER_SSL_ONLY_PAGES = (reverse(django.contrib.auth.views.login), [[any admin pages]])``` Add to this list any pages that you want to always redirect to https.

```SSL_SLAPPER_SSL_REDIRECT_ANONYMOUS=True``` Set to true to redirect anonymous users to http.

```SSL_SLAPPER_SSL_REDIRECT_AUTHENTICATED=True``` Set to true to redirect authenticated users to https.

```SSL_REDIRECT_COOKIE= 'logged-in'``` Set to the name you want for the cookie to identify logged-in users

```SSL_SLAPPER_SSL_IGNORE_PAGES=None``` Set to a list containing any urls, for examples API url, that should not be redirected.

SSL_Rate_Limit Settings
--------

```SSL_SLAPPER_RATE_LIMIT_PAGES = SSL_ONLY_PAGES``` Add to this list any pages that you want to ratelimit.
```SSL_SLAPPER_RATE_LIMIT_MINUTES=1``` = Minutes to wait before login counter is reset
```SSL_SLAPPER_RATE_LIMIT_KEY_FIELD='username'``` Field, if present, to track login attemps. If missing, then will use ip address
```SSL_SLAPPER_RATE_LIMIT_MAX_REQUESTS=20``` Set to the maximum number of requests within the RATE_LIMIT_MINUTES before the account will be locked.
```SSL_SLAPPER_RATE_LIMIT_CACHE_PREFIX='rl-'``` Cache prefix for rate limit cache



Release files for django-ssl-slapper 1.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for django-ssl-slapper 1.2
File Size Uploaded
django-ssl-slapper-1.2.tar.gz 5.6 kB Details

Built distributions (wheels)

Table of built distributions (wheels) for django-ssl-slapper 1.2
File Interpreter ABI Platform
django_ssl_slapper-1.2-py2.py3-none-any.whl Python 2, Python 3 none any Details
django_ssl_slapper-1.2-py2-none-any.whl Python 2 none any Details

Total release size: 19.1 kB

Release files / django-ssl-slapper-1.2.tar.gz

Download URL django-ssl-slapper-1.2.tar.gz
Size 5.6 kB
Tags Source
SHA-256 checksum
How to use checksums
ffd02320f8fee4d885c85d000046dad8b13a25832795b1464ab070d87c661016
BLAKE2b-256 checksum
How to use checksums
624755499d204fe73dcc421a1a3413fda30b61d539630f308cb740f210a83f12
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release files / django_ssl_slapper-1.2-py2.py3-none-any.whl

Download URL django_ssl_slapper-1.2-py2.py3-none-any.whl
Size 6.8 kB
Tags Python 2 Python 3
SHA-256 checksum
How to use checksums
bddc3871bd2218c561f2551c23fe12c90b33275a3c239a27bb0df1f81ea63061
BLAKE2b-256 checksum
How to use checksums
ed81716654da254aff38bf0f3d86c1b934d5b935ee854c9eea67280e529eeb9f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release files / django_ssl_slapper-1.2-py2-none-any.whl

Download URL django_ssl_slapper-1.2-py2-none-any.whl
Size 6.8 kB
Tags Python 2
SHA-256 checksum
How to use checksums
1668a6ad11a3f731259620a595f1116656222a4e7c36519f7234d4d616efbeab
BLAKE2b-256 checksum
How to use checksums
f4c0b2e3fb49d75f067bfbd2a92924ddadd286b615fc74daac879bd2de116b65
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page