← Back to Django Course | Chapter 12: Signals & Middleware | Lesson 8 of 8

Built-in Middleware का Overview

Django ready-made checkpoints का एक toolbox लेकर आता है जो security, sessions, और logins आपके लिए handle करता है।

SecurityMiddleware

SecurityMiddleware हर response में HTTP security headers का एक set जोड़ता है, जैसे clickjacking और MIME-type sniffing के against protections।

उदाहरण: SecurityMiddleware

SecurityMiddleware adds a set of HTTP security headers to every response, such as protections against clickjacking and MIME-type sniffing.

markup
MIDDLEWARE = [
    "django.middleware.security.SecurityMiddleware",
]
SECURE_BROWSER_XSS_FILTER = True
{# Django-only code -- models.py/views.py/urls.py/settings.py snippets, or template markup using Django template tags/variables -- can't run standalone via Judge0 or the browser preview, since it needs a real Django project. Only this course's pure-Python examples (example_lang == 'python', no Django imports) are actually runnable, so those still get the button below. #}

SessionMiddleware और AuthenticationMiddleware

SessionMiddleware request.session attach करता है, और AuthenticationMiddleware उस session का उपयोग करके request.user attach करता है — साथ में वे Django का login system power करते हैं।

उदाहरण: SessionMiddleware & AuthenticationMiddleware

SessionMiddleware attaches request.session, and AuthenticationMiddleware uses that session to attach request.user — together they power Django's login system.

markup
MIDDLEWARE = [
    "django.contrib.sessions.middleware.SessionMiddleware",
    "django.contrib.auth.middleware.AuthenticationMiddleware",
]
{# Django-only code -- models.py/views.py/urls.py/settings.py snippets, or template markup using Django template tags/variables -- can't run standalone via Judge0 or the browser preview, since it needs a real Django project. Only this course's pure-Python examples (example_lang == 'python', no Django imports) are actually runnable, so those still get the button below. #}

CsrfViewMiddleware

CsrfViewMiddleware जांचता है कि POST requests में एक valid CSRF token शामिल है, forms को cross-site request forgery attacks से protect करते हुए।

उदाहरण: CsrfViewMiddleware

CsrfViewMiddleware checks that POST requests include a valid CSRF token, protecting forms from cross-site request forgery attacks.

markup
MIDDLEWARE = [
    "django.middleware.csrf.CsrfViewMiddleware",
]
{# Django-only code -- models.py/views.py/urls.py/settings.py snippets, or template markup using Django template tags/variables -- can't run standalone via Judge0 or the browser preview, since it needs a real Django project. Only this course's pure-Python examples (example_lang == 'python', no Django imports) are actually runnable, so those still get the button below. #}

CommonMiddleware

CommonMiddleware छोटी conveniences handle करता है जैसे उन URLs में trailing slash जोड़ना जिनमें यह missing है, APPEND_SLASH से controlled।

उदाहरण: CommonMiddleware

CommonMiddleware handles small conveniences like appending a trailing slash to URLs that are missing one, controlled by APPEND_SLASH.

markup
MIDDLEWARE = [
    "django.middleware.common.CommonMiddleware",
]
APPEND_SLASH = True
{# Django-only code -- models.py/views.py/urls.py/settings.py snippets, or template markup using Django template tags/variables -- can't run standalone via Judge0 or the browser preview, since it needs a real Django project. Only this course's pure-Python examples (example_lang == 'python', no Django imports) are actually runnable, so those still get the button below. #}
Related Topics
{# common_mistakes/chapter_summary/browser_support: on Hindi pages the view already swaps in the hi_ translation fields (or blanks these out if untranslated), so this renders correctly for both languages without a lang_code check here. #}
आम गलतियां
  1. SecurityMiddleware या CsrfViewMiddleware को यह समझे बिना हटाना कि वे कौन सी protection हटाते हैं।
  2. यह न realize करना कि AuthenticationMiddleware वही है जो views में request.user available बनाता है।
  3. यह मान लेना कि सारा built-in middleware required है — कुछ, जैसे GZipMiddleware, optional performance add-ons हैं।
चैप्टर सारांश
  • SecurityMiddleware HSTS और content-type sniffing protection जैसे HTTP security headers जोड़ता है।
  • SessionMiddleware और AuthenticationMiddleware साथ में request.user और sessions काम करने लायक बनाते हैं।
  • CsrfViewMiddleware POST forms को cross-site request forgery से protect करता है।
  • CommonMiddleware URL normalization जैसी चीज़ें handle करता है।

Login to run this code

C/C++/Java/PHP execution requires a free account. Your code is saved — you'll land right back in the editor after logging in.