Keep track of failed login attempts in Django-powered sites.
Find a file
Christian Bundy 2241dbe011 Set AXES_VERBOSE default to AXES_ENABLED
Problem: When `AXES_ENABLED == False` we still see log output because `AXES_VERBOSE == True`.

Solution: Change `AXES_VERBOSE` default so that if django-axes is disabled then we don't output to stdout.
2021-02-20 15:30:59 +02:00
.github/workflows Reconfigure GitHub test matrix for Django 3.2 2021-02-15 20:33:21 +02:00
axes Set AXES_VERBOSE default to AXES_ENABLED 2021-02-20 15:30:59 +02:00
docs Fix docs AXES_HANDLER default handler 2021-02-19 10:59:01 +02:00
tests Add support to reset attempts on the cache handler 2021-02-15 20:20:49 +02:00
.gitignore Write coverage file. 2020-11-26 11:03:50 +01:00
.prospector.yaml Upgrade CI tooling to use automatic code formatting 2019-09-28 19:28:17 +03:00
CHANGES.rst Update CHANGES.rst 2021-02-19 11:00:30 +02:00
codecov.yml Raise minimum test coverage to 90% 2019-02-10 19:22:13 +02:00
LICENSE Update author and licence information 2019-03-13 16:56:56 +02:00
manage.py Move tests outside project source folder 2021-01-07 18:23:33 +02:00
mypy.ini Drop Python 3.5 support 2019-03-09 21:49:45 +02:00
pyproject.toml PyPy adjustments 2021-02-15 20:37:50 +02:00
README.rst Remove Travis cruft. 2020-11-26 11:31:02 +01:00
requirements-qa.txt Bump mypy from 0.790 to 0.800 2021-01-25 10:30:53 +00:00
requirements-test.txt Bump coverage from 5.3.1 to 5.4 2021-01-27 10:30:58 +00:00
requirements.txt Bump tox from 3.21.4 to 3.22.0 2021-02-16 10:46:43 +00:00
setup.py Move tests outside project source folder 2021-01-07 18:23:33 +02:00

django-axes
===========

.. image:: https://jazzband.co/static/img/badge.svg
   :target: https://jazzband.co/
   :alt: Jazzband

.. image:: https://img.shields.io/github/stars/jazzband/django-axes.svg?label=Stars&style=socialcA
   :target: https://github.com/jazzband/django-axes
   :alt: GitHub

.. image:: https://img.shields.io/pypi/v/django-axes.svg
   :target: https://pypi.org/project/django-axes/
   :alt: PyPI release

.. image:: https://img.shields.io/readthedocs/django-axes.svg
   :target: https://django-axes.readthedocs.io/
   :alt: Documentation

.. image:: https://github.com/jazzband/django-axes/workflows/Test/badge.svg
   :target: https://github.com/jazzband/django-axes/actions
   :alt: GitHub Actions

.. image:: https://codecov.io/gh/jazzband/django-axes/branch/master/graph/badge.svg
   :target: https://codecov.io/gh/jazzband/django-axes
   :alt: Coverage


Axes is a Django plugin for keeping track of suspicious
login attempts for your Django based website
and implementing simple brute-force attack blocking.

The name is sort of a geeky pun, since it can be interpreted as:

* ``access``, as in monitoring access attempts, or
* ``axes``, as in tools you can use to hack (generally on wood).


Functionality
-------------

Axes records login attempts to your Django powered site and prevents attackers
from attempting further logins to your site when they exceed the configured attempt limit.

Axes can track the attempts and persist them in the database indefinitely,
or alternatively use a fast and DDoS resistant cache implementation.

Axes can be configured to monitor login attempts by
IP address, username, user agent, or their combinations.

Axes supports cool off periods, IP address whitelisting and blacklisting,
user account whitelisting, and other features for Django access management.


Documentation
-------------

For more information on installation and configuration see the documentation at:

https://django-axes.readthedocs.io/


Issues
------

If you have questions or have trouble using the app please file a bug report at:

https://github.com/jazzband/django-axes/issues


Contributions
-------------

All contributions are welcome!

It is best to separate proposed changes and PRs into small, distinct patches
by type so that they can be merged faster into upstream and released quicker.

One way to organize contributions would be to separate PRs for e.g.

* bugfixes,
* new features,
* code and design improvements,
* documentation improvements, or
* tooling and CI improvements.

Merging contributions requires passing the checks configured
with the CI. This includes running tests and linters successfully
on the currently officially supported Python and Django versions.

The test automation is run automatically with GitHub Actions, but you can
run it locally with the ``tox`` command before pushing commits.

Please note that this is a `Jazzband <https://jazzband.co>`_ project.
By contributing you agree to abide by the
`Contributor Code of Conduct <https://jazzband.co/about/conduct>`_
and follow the `guidelines <https://jazzband.co/about/guidelines>`_.