inventario/settings.py. Most production settings are controlled via environment variables.
Core Settings
DEBUG Mode
Controls Django’s debug mode and affects security settings.DEBUG
- Development: Set to
Truefor detailed error pages - Production: Must be
False(default)
SESSION_COOKIE_SECURE(disabled when DEBUG=True)CSRF_COOKIE_SECURE(disabled when DEBUG=True)
SECRET_KEY
Cryptographic signing key for sessions, CSRF tokens, and password resets.SECRET_KEY
ALLOWED_HOSTS
List of host/domain names that Django will serve.ALLOWED_HOSTS
Format: Comma-separated list of domains
CSRF_TRUSTED_ORIGINS
Trusted origins for CSRF protection when using HTTPS.CSRF_TRUSTED_ORIGINS
Format: Comma-separated URLs with protocol
Must include the full URL with
https:// protocol. This is required for POST requests to work correctly.Application Settings
Custom User Model
Inventario uses a custom user model:applications.cuentas and extends Django’s authentication.
Authentication Configuration
- Email/password authentication (ModelBackend)
- OAuth authentication via django-allauth (Google)
Django Allauth Configuration
Email and account settings:Site Configuration
Django sites framework configuration:The Site domain must match your deployment URL for OAuth to work correctly. Update via Django admin or in
build.sh.Localization
- Language: Spanish (Spain)
- Timezone: Colombia (America/Bogota)
- Internationalization: Enabled
- Timezone support: Enabled
Middleware Configuration
Middleware stack in order:- SecurityMiddleware: Adds security headers
- WhiteNoiseMiddleware: Serves static files (must be after SecurityMiddleware)
- ForzarCambioPasswordMiddleware: Custom middleware to enforce password changes
- AccountMiddleware: Required for django-allauth
Static and Media Files
Static Files
- Development static files:
static/directory - Collected static files:
staticfiles/directory - WhiteNoise handles compression and caching
Media Files
media/ directory.
Installed Applications
Core Django apps:django.contrib.admindjango.contrib.authdjango.contrib.contenttypesdjango.contrib.sessionsdjango.contrib.messagesdjango.contrib.staticfilesdjango.contrib.sites
allauth,allauth.account,allauth.socialaccountallauth.socialaccount.providers.googlewidget_tweaks
applications.usuarios- User managementapplications.cuentas- Account managementapplications.proveedores- Supplier managementapplications.productos- Product managementapplications.clientes- Customer managementapplications.ventas- Sales managementapplications.reportes- Reportingapplications.compras- Purchase managementapplications.configuracion- Configurationapplications.devoluciones- Returns management
Templates
applications/templates/