Overview
Inventario provides a secure authentication system with multiple login methods, email verification, and password recovery features. The system is built on Django’s authentication framework with custom extensions.Login Methods
Username/Password Authentication
Users can log in using either their username or email address with their password.Flexible Login: Users can authenticate using either their username or email address. The system automatically detects email addresses by checking for the
@ symbol.Google OAuth Integration
Inventario supports Google OAuth for streamlined authentication usingdjango-allauth.
1
Configure OAuth Settings
OAuth settings are configured in
settings.py:2
Auto-capture Profile Photos
When users log in with Google, their profile photo is automatically saved:
3
Redirect After Login
Users are redirected based on their role:
- Superusers:
/admin/ - Admin:
/dashboard/ - Vendedor: Sales list view
Email Verification
Registration Flow
New users must verify their email address before account activation.1
User Registration
User submits registration form with email, username, and password.
2
Email Verification Sent
A verification email with a unique 64-character token is sent. The token is valid for 24 hours.
3
User Clicks Verification Link
User account is created in the database with
is_active=False.4
Admin Activation
An administrator must manually activate the account before the user can log in.
Two-Step Verification: The system implements a two-step verification process:
- Email verification (automated)
- Admin approval (manual)
Password Reset
6-Digit Code System
Inventario uses a secure 6-digit code system for password recovery instead of traditional reset links.Password Reset Flow
1
Request Reset Code
User submits their email address at
password_reset_request view:2
Receive 6-Digit Code
A random 6-digit code is generated and emailed. The code expires in 10 minutes.
3
Verify Code
User enters the code at
password_reset_verify view. The system validates:- Code matches the user’s record
- Code has not expired
4
Set New Password
User creates a new password with validation:
- Minimum 8 characters
- Cannot be a common password
- Must contain numbers and letters
Session Management
Session Configuration
Session security is configured insettings.py:
inventario/settings.py
Session Security Features
Secure Cookies
Session cookies are marked as secure in production to prevent transmission over HTTP.
CSRF Protection
All forms include CSRF tokens to prevent cross-site request forgery attacks.
Password Rehashing
When users change passwords, sessions are maintained using
update_session_auth_hash.Cache Control
Sensitive pages use the
@no_cache decorator to prevent browser caching.Account Status Validation
Before allowing login, the system checks account status:applications/cuentas/views.py:241-244
Inactive accounts receive a clear error message directing them to contact an administrator.
Password Validators
Custom password validators ensure strong passwords:inventario/settings.py
Validator Details
Validator Details
- LongitudMinimaValidator: Ensures minimum 8 characters
- ContraseñaComunValidator: Prevents common passwords
- ContraseñaNumericaValidator: Requires a mix of numbers and letters
Email Service
Inventario uses Resend for email delivery:Related Resources
User Roles
Learn about Admin and Vendedor roles and permissions
Profile Management
Manage user profiles and settings
Security
Advanced security configuration
Environment Variables
Configure authentication environment variables