Skill-
Forge
Learn
Notes
Language & Framework notes
CS Core Subjects
OS, DBMS, Networks, OOP & more
System Design
Architecture & High-Scale
Roadmaps
Guided developer learning paths
Cheat Sheets
Quick syntax references
Resources
Curated books, guides & links
Practice
Problems
DSA & coding challenges
Quizzes
Test your knowledge
Algorithms
Explanations & visualizations
Git Visualizer
Interactive Git graph & CLI playground
Aptitude
Placement & logic prep
Formula Simulators
Real-time quant equation simulators
Build
Projects Hub
Step-by-step real world projects
Resume Builder
ATS-friendly resumes, live preview & score
Tools
Online compilers & utilities
Skills
Core professional & tech skills
Error Encyclopedia
Search
⌘K
Install App
Start Learning
Menu
Learn
Notes
CS Core Subjects
System Design
Roadmaps
Cheat Sheets
Resources
Practice
Problems
Quizzes
Algorithms
Git Visualizer
Aptitude
Formula Simulators
Build
Projects Hub
Resume Builder
Tools
Skills
Error Encyclopedia
Search
Install Skill-Forge App
Appearance
Start Learning
Skip to main content
Cheatsheets
16 sections
42 cards
Django 5.x · DRF 3.15 · Python 3.12 · 2025
🎸
Django Cheat Sheet
Models · ORM · Views · URLs · Templates · DRF · Auth · Admin · Signals · Testing
Browse sections
Shortcuts
?
Hide Sidebar
Search cheatsheet sections
/
or
⌘K
Progress
0%
Table of contents
Shortcuts
?
⚡
Setup & Project Structure
🛠️
manage.py Commands
🗄️
Models & Fields
🔍
ORM & QuerySets
🔁
Migrations
👁️
Views — FBV & CBV
🔀
URLs
🎨
Django Template Language (DTL)
📝
Django Forms
📡
Django REST Framework (DRF)
🔒
Authentication & Permissions
⚙️
Django Admin
🪝
Middleware & Signals
🗃️
Caching
🧪
Testing Django
📋
Quick Reference & Gotchas
J
K
Jump
/
Search
Esc
Clear
⚡
Setup & Project Structure
Installation & Architecture
Install & Create Project
Project Layout
settings.py Key Settings
Django Request/Response Cycle
🛠️
manage.py Commands
Django CLI
All Essential Commands 🔥
🗄️
Models & Fields
ORM Schema Definition
Model Definition 🔥
Field Types Reference
Field Options & on_delete
Custom Model Methods & Managers
🔍
ORM & QuerySets
Database Queries
QuerySet Methods 🔥
get_object_or_404 & Shortcuts
Raw SQL & Transactions
🔁
Migrations
Schema Evolution
Migration Workflow
Data Migration (RunPython)
👁️
Views — FBV & CBV
Function & Class-Based Views
Function-Based Views (FBV)
Class-Based Views (CBV) 🔥
CBV Hierarchy & Mixins
🔀
URLs
URL Configuration
URL Patterns 🔥
🎨
Django Template Language (DTL)
Template Syntax & Tags
DTL Syntax Reference 🔥
Custom Template Tags
📝
Django Forms
Form & ModelForm
Form & ModelForm
Form in Views & Templates
Common Form Fields & Widgets
📡
Django REST Framework (DRF)
Serializers · ViewSets · Routers
DRF Complete Pattern 🔥
DRF Settings & JWT Auth
Serializer Field Types
🔒
Authentication & Permissions
Users · Groups · Custom Auth
Custom User Model (do this first!) 🔥
Auth Views & Decorators
Permissions & Groups
⚙️
Django Admin
ModelAdmin Customization
ModelAdmin Full Reference 🔥
🪝
Middleware & Signals
Hooks & Event System
Custom Middleware
Django Signals 🔥
Built-in Signals
🗃️
Caching
Redis · Memcached · Per-View
Cache Configuration
View & Template Caching
🧪
Testing Django
TestCase · Client · Factory Boy
TestCase Full Pattern 🔥
DRF API Testing
pytest-django + Factory Boy
📋
Quick Reference & Gotchas
Imports · Patterns · Pitfalls
Essential Imports Cheat Sheet 🔥
Useful Packages Reference
Django Gotchas ⭐
<b>Custom User Model first</b> — set AUTH_USER_MODEL BEFORE your first migration. Changing it later is very painful.
<b>get_user_model() not User</b> — always use get_user_model() to reference the user model in other apps.
<b>N+1 queries</b> — always use select_related() for FKs and prefetch_related() for M2M/reverse FKs.
<b>QuerySets are lazy</b> — they hit the DB only when evaluated (iteration, slicing, len(), list(), bool()).
<b>auto_now vs auto_now_add</b> — auto_now updates on every save; auto_now_add only on create. Both make the field non-editable.
<b>null vs blank</b> — null=True for DB; blank=True for form validation. Text fields: use blank=True only, not null=True.
<b>Signals and AppConfig.ready()</b> — always import signals in AppConfig.ready() or they won't be registered.
<b>admin.register vs site.register</b> — prefer @admin.register(Model) decorator over admin.site.register(Model, Admin).
<b>reverse_lazy vs reverse</b> — use reverse_lazy for class attributes (success_url in CBVs); reverse() for runtime calls.
<b>CSRF on AJAX</b> — include X-CSRFToken header; get token from cookie or {% csrf_token %} template tag.
<b>Static files in prod</b> — run collectstatic; use WhiteNoise or nginx to serve /staticfiles/.
<b>DEBUG=True in prod</b> — exposes full traceback and settings to the world. Never!
Security Checklist ⭐
Run <code>python manage.py check --deploy</code> — catches common security issues
Set <b>ALLOWED_HOSTS</b> to specific domains — never <code>['*']</code> in production
Use <b>django.middleware.security.SecurityMiddleware</b> for HTTPS, HSTS
Set <b>SECURE_SSL_REDIRECT=True</b> and <b>SESSION_COOKIE_SECURE=True</b>
Use <b>{% csrf_token %}</b> in all POST forms — Django checks automatically
Always use ORM / F() expressions — never string-format raw SQL with user input
Use <b>FileField with allowed extensions + finfo MIME check</b> for uploads
Store secrets in environment variables — never commit .env to git
Use <b>Content-Security-Policy</b> headers (django-csp package)
Enable <b>SECURE_BROWSER_XSS_FILTER</b> and <b>X_FRAME_OPTIONS='DENY'</b>