0Pricing
Django Academy · درس

HTTPS وHSTS وملفات Cookies الآمنة

فرض اتصالات مشفرة وآمنة

HTTPS وHSTS وملفات Cookies الآمنة درس مجاني في Django Academy على CoddyKit. هذا هو الدرس 2 من أصل 4. يمكنك قراءة الدرس كاملاً أدناه مجاناً — ثم تمرن عليه مباشرة في المتصفح باستخدام محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7. هذا الدرس جزء من مسار التعلم في Django Academy، وتقدمك يتزامن عبر الويب وتطبيق CoddyKit. تتضمن دورة Django Academy 4 دروس في المجموع.

بعض أجزاء هذا الدرس لم تُترجم بعد وتظهر باللغة الإنجليزية.

Why HTTPS Matters

Plain HTTP sends passwords and cookies as readable text anyone on the network can grab. HTTPS encrypts the whole conversation between browser and server. 🔐

Redirect HTTP to HTTPS

Turn on SECURE_SSL_REDIRECT so Django bounces any plain HTTP request to its HTTPS version automatically. No more accidental insecure pages.

SECURE_SSL_REDIRECT = True

Trust the Proxy Header

Behind Nginx, Django needs to know the request arrived over TLS. The SECURE_PROXY_SSL_HEADER tells it which header to trust for that.

SECURE_PROXY_SSL_HEADER = ("HTTP_X_FORWARDED_PROTO", "https")

What HSTS Is

HSTS tells browsers to only ever talk to your site over HTTPS for a set time. Even typing http will be upgraded before any request leaves the browser.

Enable HSTS Carefully

Set SECURE_HSTS_SECONDS to enable HSTS. Start small while testing, since browsers will remember it and refuse plain HTTP until it expires.

SECURE_HSTS_SECONDS = 31536000

Extend HSTS Reach

Cover every subdomain and qualify for preload lists with two extra flags. They make HSTS apply broadly and let browsers ship it built in.

SECURE_HSTS_INCLUDE_SUBDOMAINS = True
SECURE_HSTS_PRELOAD = True

Cookies Travel With Requests

Your session and CSRF cookies authenticate users. If they leak over HTTP, an attacker can hijack the session, so they need protection flags too.

Secure the Session Cookie

Set SESSION_COOKIE_SECURE to True so the session cookie is only ever sent over HTTPS, never on an unencrypted connection.

SESSION_COOKIE_SECURE = True

Secure the CSRF Cookie

Do the same for CSRF protection. With CSRF_COOKIE_SECURE on, the token cookie also refuses to ride along over plain HTTP.

CSRF_COOKIE_SECURE = True

Block JavaScript Access

The HttpOnly flag hides the session cookie from JavaScript, so a cross-site script cannot read and steal it. Django sets it on sessions by default.

SESSION_COOKIE_HTTPONLY = True

Limit Cookie Sharing

The SameSite attribute stops cookies from being sent on cross-site requests, adding a second layer of CSRF defense. Django defaults it to Lax for you.

SESSION_COOKIE_SAMESITE = "Lax"

Quick Check

Let us see if the HSTS idea stuck.

Recap: Encrypted End to End

You forced HTTPS, taught browsers to remember it with HSTS, and marked your cookies secure and HttpOnly. Traffic and sessions are now encrypted end to end. ✨

الأسئلة الشائعة

هل درس «HTTPS وHSTS وملفات Cookies الآمنة» مجاني؟

نعم — نص درس «HTTPS وHSTS وملفات Cookies الآمنة» كامل متاح مجاناً هنا على الويب. لتمرينه بشكل تفاعلي (محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7) وفتح باقي دورة Django Academy، انتقل إلى CoddyKit PRO. تتضمن دورة Django Academy 4 دروس في المجموع.

ماذا ستتعلم في «HTTPS وHSTS وملفات Cookies الآمنة»؟

فرض اتصالات مشفرة وآمنة تتمرن على Django Academy مع أكواد عملية تشغلها مباشرة في المتصفح، ومدرس ذكاء اصطناعي متاح 24/7 يجيب على أسئلتك أثناء عملك.

هل أحتاج إلى خبرة سابقة لأبدأ Django Academy؟

لا تُشترط خبرة سابقة. Django Academy على CoddyKit منظم للمبتدئين حتى المتقدمين، لذا يمكنك البدء من هنا أو من البداية والتقدم بسرعتك الخاصة. هذا هو الدرس 2 من أصل 4.

كم من الوقت يستغرق درس «HTTPS وHSTS وملفات Cookies الآمنة»؟

معظم دروس CoddyKit تستغرق حوالي 5–10 دقائق. كل منها موجز وتفاعلي، لذا تحرز تقدماً مستمراً وتستأنف من حيث توقفت عبر الويب والتطبيق.

هل يمكنني كتابة وتشغيل أكواد في درس Django Academy هذا؟

نعم. كل درس في Django Academy يتضمن محرر أكواد مدمج، لذا تكتب وتشغل أكواداً حقيقية مباشرة في متصفحك وتحصل على تعليقات فورية من الذكاء الاصطناعي — بدون إعداد محلي.

جميع الدروس في هذه الدورة

  1. DEBUG وSECRET_KEY وALLOWED_HOSTS
  2. HTTPS وHSTS وملفات Cookies الآمنة
  3. دفاعات XSS وCSRF وSQL Injection
  4. تنفيذ قائمة التحقق من النشر
← العودة إلى Django Academy