Instagram Django site admin
instagram.com
instagram.com
We're also part of Facebook's bug bounty whitehat program (https://www.facebook.com/whitehat/bounty/), if anyone comes across something in the future, we welcome responsible disclosure and pay out bounties through the program as well.
Also: obviously I don't speak for either Facebook or Google, but I strongly recommend against brute-forcing login prompts to try to prove the point that an exposed console is a real finding.
^That's Facebook's. Theoretically, an exposed login page "could...enable access to a system within the Facebook infrastructure", but to be fair, I doubt they had that in mind.
//edit: oh, now I see somebody thought of my idea too https://github.com/dmpayton/django-admin-honeypot
http://www.ibm.com/developerworks/lotus/library/ls-SSL_clien...
Really, though, unless you're extremely security-conscious, a hidden URL over HTTPS with a good password is sufficient for your purposes.
Also, don't serve any pages over plain HTTP, login pages even less so.
openssl req -new -x509 -nodes \
-out /nuxeo/certs/server.crt \
-keyout /nuxeo/certs/server.key \
-batch
you will get a warning about the certificate being suspect; but at least the traffic will be encryptedHeroku will still probably charge you a basic fee for enabling SSL, since each certificate requires a dedicated (non-shared) IP address... at least until SNI support becomes more commonplace.
Edit: Just to reiterate what others have said, this is a server-side certificate, which is primarily used for encryption. You'll also want to generate a client-side certificate for authentication purposes. That's something you'd do entirely on your own, no need to go through a third-party CA for that.
Unfortunately I have no idea how this would work on Heroku.
There's a great article about client authentication for HAProxy (might be interesting even if you're not using HAProxy): http://blog.exceliance.fr/2012/10/03/ssl-client-certificate-...
[1] - https://chrome.google.com/webstore/detail/stylish/fjnbnpbmke...
#header {
... css ...
background: <whatever color you want>;
... more css ...
}Maybe someone can give some insight.
Other than Grappelli, I've historically used the admin pretty much as-is. Creating admin functions is one thing, but lots of custom screens is quite another.
I also think that's one thing really lacking from the Django documentation, really great customization of the Admin.