The framework isn't fool proof (no one can protect developers from themselves). But I feel that Django does what it needs to do when it comes to protecting its users.
The framework isn't fool proof (no one can protect developers from themselves). But I feel that Django does what it needs to do when it comes to protecting its users.
The "last mile" is just making sure your code is using all those tools correctly.
And yet that example may only be the last item in a threat tree, which may have a zero-day vulnerability at its root.
Relying on tools or, in fact, any code you've not written yourself makes your system vulnerable. If you understand how an attacker might compromise a system (ref. STRIDE) you can mitigate.
Writing everything yourself, as opposed to widely, community tested open-source alternatives, makes your system vulnerable.
Your example seems to be at the farthest possible end of the spectrum from what I'm talking about.
Not that you shouldn't understand the potential vectors against your site, or shouldn't read how to use these tools correctly, but a widely tested and used tool or framework, just like a widely researched crytpo algorithm, is better than one with no other eyes on it.