A copyable Django feature slice for moderated, multilingual customer reviews. The showcase also includes focused tests, host-integration snippets, and a small frontend shell to adapt.
- public approved-review listings with rating filters and pagination;
- a server-rendered submission form with CSRF, signed form evidence, a honeypot, verification challenges, rate limits, and idempotent acceptance;
- immutable submission evidence and an explicit public-field allowlist;
- owner moderation, replies, deletion, durable notification state, and explicit recovery for uncertain email delivery;
- progressive enhancement for the form, text counters, review targeting, and a homepage carousel;
- Dutch, French, and English UI catalogs.
This repository contains the reviews Django app and its focused tests. It is
a showcase and copyable implementation example, not a complete website. It
intentionally excludes project settings, authentication, a database,
deployment files, and production data.
The app expects the host project to provide these neutral integration points:
project.core.form_abuseandproject.core.client_ipfor challenge and trusted-client-IP helpers;project.routingwithis_local_preview_request,LOCAL_PUBLIC_NAMESPACE, andreverse_public;project.i18n.LANGUAGE_CHOICES;project.templatetags.site_tagswithsite_urlandlanguage_urltemplate tags;project.admin_sitewithOwnerModelAdminMixin,admin_site, andis_authorized_owner;project.templatetags.site_cspwithsite_csp_nonce_attr;- a
site/base.htmltemplate and the host project's public/admin URL namespaces (site_publicandsite_admin).
Rename these imports or provide compatible adapters when integrating the app.
The review app also uses django-post-office for durable email records and
requires its migrations and configured transactional backend.
- Copy
reviews/into the host project's import path. - Add
reviews.apps.ReviewsConfigtoINSTALLED_APPS. - Wire the three public views into the host's localized
site_publicURL namespace. The host integration reference contains a route snippet. - Provide the integration points above and the settings in
the settings example,
including
ReviewPrivacyMiddleware. Use.env.examplefor host-specific environment values. - Run migrations, collect the app's static files, and compile the locale catalogs from the host project.
- Add the app's public and Admin templates to the host template contract.
- Start with the example frontend, then
adapt
site/base.htmland its CSS to the host website.
The app uses REVIEWS_* settings for token lifetimes, rate limits, trusted
proxy ranges, the Admin host, and notification sender/recipient addresses.
It does not contain default credentials or production hosts.
The folder has no settings module, so the Python tests require a host test project that installs the app and its documented adapters. After integration, run:
python manage.py test tests
node --test tests/js/*.test.js
python manage.py makemigrations --check --dry-run
python manage.py checkThe JavaScript tests only require Node.js. The Python tests are integration oriented and are not claimed to run from this folder alone.
Use a strong private Django SECRET_KEY; signed form tokens depend on it.
Configure trusted proxy ranges conservatively, keep CSRF protection enabled,
and use a real transactional email backend. The app hashes client IPs rather
than storing them directly, keeps subject details out of public rendering, and
requires approval before publication. Review retention, privacy-notice links,
email access, and Admin authorization against the host project's legal and
operational requirements.
See LICENSE for the MIT license.