Skip to main content

Overview

Inventario uses Django’s built-in session-based authentication with CSRF protection. The system also supports OAuth 2.0 via Google Sign-In through Django Allauth.

Authentication Methods

Session Authentication

The primary authentication method uses Django sessions with cookies.

Login

string
required
User’s username
string
required
User’s password
Response: Redirects to /dashboard/ with session cookie set

Logout

Response: Session terminated, redirects to home page

Google OAuth 2.0

Inventario supports Google Sign-In via Django Allauth.

Initiate Google Login

This redirects to Google’s OAuth consent screen. After authorization, users are redirected to:

CSRF Protection

All POST, PUT, DELETE requests require a valid CSRF token.

Getting CSRF Token

  1. From Cookie: Django sets csrftoken cookie on first visit
  2. From HTML Form: Extract from hidden input in rendered forms

Using CSRF Token

Form-Encoded Requests

AJAX/JSON Requests

User Registration

Create New User Account

string
required
Unique username
string
required
Valid email address (must be unique)
string
required
Password (minimum length validation applies)
string
required
Password confirmation (must match password1)
Response: User created with admin role by default, redirects to email verification

Email Verification

New users must verify their email address.

Verification Flow

  1. User registers
  2. System generates 64-character token
  3. Verification email sent with link: /verificar-email/<uidb64>/
  4. Token valid for 24 hours
  5. User clicks link to verify

Verify Email Endpoint

Response: Sets email_verified=True, redirects to login

Password Reset

Inventario implements a custom 6-digit code password reset flow.

Step 1: Request Reset Code

string
required
Registered email address
Response: 6-digit code sent to email (valid for 10 minutes)

Step 2: Verify Reset Code

string
required
6-digit verification code from email
Response: Session marked for password reset

Step 3: Set New Password

string
required
New password
string
required
Password confirmation
Response: Password updated, redirects to login

User Model

The custom User model extends Django’s AbstractUser:
integer
Unique user identifier
string
Unique username
string
Unique email address (required)
string
User role: admin or vendedor
string
First name (optional)
string
Last name (optional)
string
Phone number (optional)
file
Profile photo upload
string
Google profile photo URL (for OAuth users)
boolean
Email verification status
boolean
Whether user has completed tutorial
boolean
Forces password change on next login (for vendedor accounts)
integer
Foreign key to admin user who created this account (for vendedor users)

Role-Based Access Control

Admin Role (rol='admin')

Full access to all endpoints:
  • Create, edit, delete products
  • Manage purchases
  • Create/manage vendedor accounts
  • Access all reports
  • System configuration

Vendedor Role (rol='vendedor')

Limited access:
  • View products (read-only)
  • Create sales
  • View own sales history
  • Cannot modify products or purchases

Enforcing Permissions

Many endpoints use the @admin_required decorator:
Response for unauthorized access: HTTP 403 Forbidden

Session Management

Django sets a sessionid cookie upon successful authentication:

Session Timeout

Configured in Django settings (default: 2 weeks)

Checking Authentication Status

All views decorated with @login_required will redirect to /login/ if not authenticated.
Unauthenticated Response: HTTP 302 redirect to /login/

Security Features

Password Validation

Custom validators in applications.cuentas.validators:
  1. LongitudMinimaValidator - Minimum length requirement
  2. ContraseñaComunValidator - Prevents common passwords
  3. ContraseñaNumericaValidator - Prevents purely numeric passwords

CSRF Protection

Enabled via CsrfViewMiddleware - all state-changing operations require valid CSRF token

Force Password Change

Vendedor users created by admin have debe_cambiar_password=True and are redirected via ForzarCambioPasswordMiddleware until they set a new password.

Example: Complete Authentication Flow