Skip to main content
Inventario’s configuration is managed through Django settings in inventario/settings.py. Most production settings are controlled via environment variables.

Core Settings

DEBUG Mode

Controls Django’s debug mode and affects security settings.
Environment variable: DEBUG
  • Development: Set to True for detailed error pages
  • Production: Must be False (default)
Never run production with DEBUG=True. This exposes sensitive configuration and security vulnerabilities.
DEBUG mode also controls:
  • SESSION_COOKIE_SECURE (disabled when DEBUG=True)
  • CSRF_COOKIE_SECURE (disabled when DEBUG=True)

SECRET_KEY

Cryptographic signing key for sessions, CSRF tokens, and password resets.
Environment variable: SECRET_KEY
The default key is insecure and only for development. Generate a new key for production:

ALLOWED_HOSTS

List of host/domain names that Django will serve.
Environment variable: ALLOWED_HOSTS Format: Comma-separated list of domains
The default * allows all hosts and is insecure. Always specify exact domains in production.

CSRF_TRUSTED_ORIGINS

Trusted origins for CSRF protection when using HTTPS.
Environment variable: CSRF_TRUSTED_ORIGINS Format: Comma-separated URLs with protocol
Must include the full URL with https:// protocol. This is required for POST requests to work correctly.

Application Settings

Custom User Model

Inventario uses a custom user model:
The custom user model is defined in applications.cuentas and extends Django’s authentication.

Authentication Configuration

Supports both:
  • Email/password authentication (ModelBackend)
  • OAuth authentication via django-allauth (Google)

Django Allauth Configuration

Email and account settings:
Social account settings:

Site Configuration

Django sites framework configuration:
The Site domain must match your deployment URL for OAuth to work correctly. Update via Django admin or in build.sh.

Localization

  • Language: Spanish (Spain)
  • Timezone: Colombia (America/Bogota)
  • Internationalization: Enabled
  • Timezone support: Enabled

Middleware Configuration

Middleware stack in order:
Key middleware:
  • SecurityMiddleware: Adds security headers
  • WhiteNoiseMiddleware: Serves static files (must be after SecurityMiddleware)
  • ForzarCambioPasswordMiddleware: Custom middleware to enforce password changes
  • AccountMiddleware: Required for django-allauth

Static and Media Files

Static Files

  • Development static files: static/ directory
  • Collected static files: staticfiles/ directory
  • WhiteNoise handles compression and caching

Media Files

User-uploaded files are stored in the media/ directory.
For production deployments, consider using object storage (S3, Cloudinary, etc.) for media files instead of local filesystem storage.

Installed Applications

Core Django apps:
  • django.contrib.admin
  • django.contrib.auth
  • django.contrib.contenttypes
  • django.contrib.sessions
  • django.contrib.messages
  • django.contrib.staticfiles
  • django.contrib.sites
Third-party apps:
  • allauth, allauth.account, allauth.socialaccount
  • allauth.socialaccount.providers.google
  • widget_tweaks
Inventario apps:
  • applications.usuarios - User management
  • applications.cuentas - Account management
  • applications.proveedores - Supplier management
  • applications.productos - Product management
  • applications.clientes - Customer management
  • applications.ventas - Sales management
  • applications.reportes - Reporting
  • applications.compras - Purchase management
  • applications.configuracion - Configuration
  • applications.devoluciones - Returns management

Templates

Template directory: applications/templates/

Adapters

Custom adapter for social account handling:
This adapter customizes the OAuth flow and user creation process.