Skip to content

Latest commit

 

History

3 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Django Reviews Showcase

A copyable Django feature slice for moderated, multilingual customer reviews. The showcase also includes focused tests, host-integration snippets, and a small frontend shell to adapt.

Demonstrates

  • public approved-review listings with rating filters and pagination;
  • a server-rendered submission form with CSRF, signed form evidence, a honeypot, verification challenges, rate limits, and idempotent acceptance;
  • immutable submission evidence and an explicit public-field allowlist;
  • owner moderation, replies, deletion, durable notification state, and explicit recovery for uncertain email delivery;
  • progressive enhancement for the form, text counters, review targeting, and a homepage carousel;
  • Dutch, French, and English UI catalogs.

Public boundary

This repository contains the reviews Django app and its focused tests. It is a showcase and copyable implementation example, not a complete website. It intentionally excludes project settings, authentication, a database, deployment files, and production data.

The app expects the host project to provide these neutral integration points:

  • project.core.form_abuse and project.core.client_ip for challenge and trusted-client-IP helpers;
  • project.routing with is_local_preview_request, LOCAL_PUBLIC_NAMESPACE, and reverse_public;
  • project.i18n.LANGUAGE_CHOICES;
  • project.templatetags.site_tags with site_url and language_url template tags;
  • project.admin_site with OwnerModelAdminMixin, admin_site, and is_authorized_owner;
  • project.templatetags.site_csp with site_csp_nonce_attr;
  • a site/base.html template and the host project's public/admin URL namespaces (site_public and site_admin).

Rename these imports or provide compatible adapters when integrating the app. The review app also uses django-post-office for durable email records and requires its migrations and configured transactional backend.

Integration

  1. Copy reviews/ into the host project's import path.
  2. Add reviews.apps.ReviewsConfig to INSTALLED_APPS.
  3. Wire the three public views into the host's localized site_public URL namespace. The host integration reference contains a route snippet.
  4. Provide the integration points above and the settings in the settings example, including ReviewPrivacyMiddleware. Use .env.example for host-specific environment values.
  5. Run migrations, collect the app's static files, and compile the locale catalogs from the host project.
  6. Add the app's public and Admin templates to the host template contract.
  7. Start with the example frontend, then adapt site/base.html and its CSS to the host website.

The app uses REVIEWS_* settings for token lifetimes, rate limits, trusted proxy ranges, the Admin host, and notification sender/recipient addresses. It does not contain default credentials or production hosts.

Documentation

Tests

The folder has no settings module, so the Python tests require a host test project that installs the app and its documented adapters. After integration, run:

python manage.py test tests
node --test tests/js/*.test.js
python manage.py makemigrations --check --dry-run
python manage.py check

The JavaScript tests only require Node.js. The Python tests are integration oriented and are not claimed to run from this folder alone.

Security and privacy

Use a strong private Django SECRET_KEY; signed form tokens depend on it. Configure trusted proxy ranges conservatively, keep CSRF protection enabled, and use a real transactional email backend. The app hashes client IPs rather than storing them directly, keeps subject details out of public rendering, and requires approval before publication. Review retention, privacy-notice links, email access, and Admin authorization against the host project's legal and operational requirements.

See LICENSE for the MIT license.

About

A Django app for moderated, multilingual customer reviews. With spam protection, owner replies, and a homepage carousel.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages