A complete production-style Django web application for managing documents with role-based access control, department-based organization, and comprehensive permission management.
- Role-Based Access Control (RBAC) with three roles:
- Super Admin: Full system access
- Department Admin: Department-level management
- Employee: View and download authorized documents
- Custom User model with role and department fields
- Profile management with profile pictures
- Password change functionality
- Create, edit, and delete departments
- Track users and documents per department
- Department-based document organization
- Define custom roles with granular permissions
- Configure permissions for:
- User management
- Department management
- Document management
- System administration
- Upload documents (PDF, DOCX, XLSX, TXT)
- Document versioning with history tracking
- Soft delete with restore functionality
- File preview for PDF documents
- Advanced search and filtering
- Drag and drop upload support
- File validation (type and size)
- Role-based permissions
- Department-based permissions
- User-specific permissions
- Granular access control (view, download, edit, delete)
- Track all user actions
- Log login/logout events
- Document upload/download tracking
- Permission change logging
- IP address tracking
- JWT authentication
- Complete CRUD operations for all entities
- Pagination, filtering, and search
- Secure endpoint access
- Django 5+
- Django REST Framework
- SQLite (development) / PostgreSQL (production)
- Django Simple JWT
- Django Templates
- HTML5
- CSS3
- Bootstrap 5
- JavaScript
- Django Authentication System
- Custom User Model
- JWT Tokens (API)
smart_dms/
├── accounts/ # User management app
├── departments/ # Department management app
├── roles/ # Role management app
├── documents/ # Document management app
├── permissions_app/ # Permission management app
├── activity_logs/ # Activity logging app
├── api/ # REST API app
├── templates/ # HTML templates
├── static/ # Static files (CSS, JS)
├── media/ # Uploaded files
├── smart_dms/ # Project settings
├── manage.py # Django management script
├── requirements.txt # Python dependencies
├── .env.example # Environment variables template
├── seed_data.py # Database seeding script
└── README.md # This file
- Python 3.9+
- pip (Python package manager)
cd c:\Users\NIKHITHA\OneDrive\Desktop\DjangoFrameworkSamplepython -m venv venv
venv\Scripts\activate # On Windows
# source venv/bin/activate # On Linux/Macpip install -r requirements.txtcp .env.example .envEdit .env file with your configuration (optional for SQLite):
SECRET_KEY=your-secret-key-here
DEBUG=True
ALLOWED_HOSTS=localhost,127.0.0.1
# Email configuration (optional, for password reset)
EMAIL_HOST=smtp.gmail.com
EMAIL_PORT=587
EMAIL_HOST_USER=your-email@gmail.com
EMAIL_HOST_PASSWORD=your-app-password
DEFAULT_FROM_EMAIL=noreply@smartdms.compython manage.py makemigrations
python manage.py migratepython manage.py createsuperuserpython seed_data.pyThis will create sample departments, roles, users, and documents.
python manage.py runserverThe application will be available at http://localhost:8000
| Role | Username | Password |
|---|---|---|
| Super Admin | admin | admin123 |
| HR Admin | hr_admin | hr123 |
| Finance Admin | finance_admin | finance123 |
| Engineer | engineer1 | engineer123 |
- Login with super admin credentials
- Access dashboard to view system statistics
- Manage departments (Create/Edit/Delete)
- Manage roles and permissions
- Upload and manage documents
- View activity logs
- Access Django Admin panel at
/admin/
- Login with department admin credentials
- View department-specific dashboard
- Upload documents for department
- Manage department documents
- View department activity logs
- Cannot access other departments
- Login with employee credentials
- View accessible documents
- Search and filter documents
- Download authorized documents
- View document details
- Cannot upload or delete documents
POST /api/auth/login/- User loginPOST /api/auth/logout/- User logoutPOST /api/auth/token/- Get JWT tokenPOST /api/auth/token/refresh/- Refresh JWT token
GET /api/users/- List usersPOST /api/users/- Create userGET /api/users/{id}/- Get user detailsPUT /api/users/{id}/- Update userDELETE /api/users/{id}/- Delete user
GET /api/departments/- List departmentsPOST /api/departments/- Create departmentGET /api/departments/{id}/- Get department detailsPUT /api/departments/{id}/- Update departmentDELETE /api/departments/{id}/- Delete department
GET /api/documents/- List documentsPOST /api/documents/- Upload documentGET /api/documents/{id}/- Get document detailsPUT /api/documents/{id}/- Update documentDELETE /api/documents/{id}/- Delete documentPOST /api/documents/{id}/download/- Download documentPOST /api/documents/{id}/restore/- Restore document
GET /api/permissions/- List permissionsPOST /api/permissions/- Create permissionGET /api/permissions/{id}/- Get permission detailsDELETE /api/permissions/{id}/- Delete permission
GET /api/activity-logs/- List activity logs
- CSRF protection
- File upload validation (type and size)
- Role-based route protection
- Secure media access
- Login required decorators
- Permission checks
- Input validation
- JWT authentication for API
- Password hashing
- Maximum file size: 10MB
- Allowed file types: PDF, DOCX, XLSX, TXT
python manage.py testpython manage.py startapp custom_appNavigate to http://localhost:8000/admin/ and login with super admin credentials.
# 1. Clone the repository
git clone https://github.com/Nikhitha-spec/DocVault.git
cd DocVault
# 2. Create and activate virtual environment
python -m venv venv
venv\Scripts\activate # Windows
# source venv/bin/activate # Linux/Mac
# 3. Install dependencies
pip install -r requirements.txt
# 4. Configure environment variables
cp .env.example .env
# Edit .env with your production settings
# 5. Run migrations
python manage.py makemigrations
python manage.py migrate
# 6. Collect static files
python manage.py collectstatic --noinput
# 7. Create superuser
python manage.py createsuperuser
# 8. Seed database (optional)
python seed_data.py# On PythonAnywhere dashboard:
# 1. Create a new web app
# 2. Choose "Manual Configuration" with Python 3.9+
# 3. Go to the virtual environment tab and run:
pip install -r requirements.txt
# 4. In the Files tab, upload your project
# 5. In the Web tab, set the working directory to your project folder
# 6. Set the WSGI configuration file to: smart_dms/wsgi.py
# 7. Add static files mapping: /static/ -> /path/to/staticfiles
# 8. Set environment variables in the Web tab
# 9. Reload the web appPythonAnywhere WSGI Configuration:
import os
import sys
path = '/home/yourusername/DocVault'
if path not in sys.path:
sys.path.append(path)
os.environ['DJANGO_SETTINGS_MODULE'] = 'smart_dms.settings'
from django.core.wsgi import get_wsgi_application
application = get_wsgi_application()# Create a render.com account
# Create a new Web Service
# Connect your GitHub repository
# Build Command:
pip install -r requirements.txt
python manage.py collectstatic --noinput
# Start Command:
gunicorn smart_dms.wsgi:application
# Environment Variables (add in Render dashboard):
DEBUG=False
SECRET_KEY=your-secret-key-here
ALLOWED_HOSTS=your-app.onrender.com
DATABASE_URL=postgresql://...Create render.yaml in project root:
services:
- type: web
name: docvault
env: python
buildCommand: pip install -r requirements.txt && python manage.py collectstatic --noinput
startCommand: gunicorn smart_dms.wsgi:application
envVars:
- key: DEBUG
value: False
- key: SECRET_KEY
generateValue: true
- key: DATABASE_URL
fromDatabase:
name: docvault-db
property: connectionString
databases:
- name: docvault-db
databaseName: docvault
user: docvault_user# Install Heroku CLI
# Login to Heroku
heroku login
# Create Heroku app
heroku create docvault
# Add PostgreSQL addon
heroku addons:create heroku-postgresql:mini
# Set environment variables
heroku config:set DEBUG=False
heroku config:set SECRET_KEY=your-secret-key-here
heroku config:set ALLOWED_HOSTS=docvault.herokuapp.com
# Push to Heroku
git push heroku main
# Run migrations
heroku run python manage.py migrate
# Create superuser
heroku run python manage.py createsuperuser
# Seed database
heroku run python manage.py shell
# Then run: exec(open('seed_data.py').read())Create Procfile in project root:
web: gunicorn smart_dms.wsgi:application
Create runtime.txt in project root:
python-3.9.16
- Set DEBUG = False in
smart_dms/settings.py - Update ALLOWED_HOSTS with your domain:
ALLOWED_HOSTS = ['yourdomain.com', 'www.yourdomain.com']
- Use strong SECRET_KEY (generate with:
python -c "from django.core.management.utils import get_random_secret_key; print(get_random_secret_key())") - Configure production database (PostgreSQL recommended)
- Set up static file serving (Whitenoise recommended)
Add to
pip install whitenoise
settings.py:MIDDLEWARE = [ 'whitenoise.middleware.WhiteNoiseMiddleware', # ... other middleware ] STATIC_ROOT = BASE_DIR / 'staticfiles'
- Configure email backend for password reset (optional)
- Enable HTTPS (required for production)
- Set CSRF_COOKIE_SECURE = True
- Set SESSION_COOKIE_SECURE = True
- Set SECURE_SSL_REDIRECT = True
- Set SECURE_HSTS_SECONDS = 31536000
# Install Gunicorn
pip install gunicorn
# Run with Gunicorn
gunicorn smart_dms.wsgi:application
# Run with 4 workers
gunicorn -w 4 -b 0.0.0.0:8000 smart_dms.wsgi:application
# Run with Gunicorn and systemd (Linux)
# Create /etc/systemd/system/docvault.service:
[Unit]
Description=DocVault Django Application
After=network.target
[Service]
User=www-data
Group=www-data
WorkingDirectory=/path/to/DocVault
ExecStart=/path/to/DocVault/venv/bin/gunicorn --workers 3 --bind unix:/path/to/DocVault/docvault.sock smart_dms.wsgi:application
Restart=always
[Install]
WantedBy=multi-user.targetserver {
listen 80;
server_name yourdomain.com www.yourdomain.com;
location /static/ {
alias /path/to/DocVault/staticfiles/;
}
location /media/ {
alias /path/to/DocVault/media/;
}
location / {
proxy_pass http://unix:/path/to/DocVault/docvault.sock;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}PostgreSQL:
# Install PostgreSQL
# Create database
createdb docvault
# Update settings.py
DATABASES = {
'default': {
'ENGINE': 'django.db.backends.postgresql',
'NAME': 'docvault',
'USER': 'docvault_user',
'PASSWORD': 'your-password',
'HOST': 'localhost',
'PORT': '5432',
}
}
# Install psycopg2-binary
pip install psycopg2-binary# Collect static files for production
python manage.py collectstatic --noinput
# Use Whitenoise for static file serving
pip install whitenoiseUsing Let's Encrypt with Certbot:
# Install Certbot
sudo apt-get install certbot python3-certbot-nginx
# Get SSL certificate
sudo certbot --nginx -d yourdomain.com -d www.yourdomain.com
# Auto-renewal is configured automatically# Enable Django logging in settings.py
LOGGING = {
'version': 1,
'disable_existing_loggers': False,
'handlers': {
'file': {
'level': 'ERROR',
'class': 'logging.FileHandler',
'filename': '/path/to/DocVault/logs/django.log',
},
},
'loggers': {
'django': {
'handlers': ['file'],
'level': 'ERROR',
'propagate': True,
},
},
}- Ensure PostgreSQL is running
- Check database credentials in
.env - Verify database exists
python manage.py makemigrations --empty
python manage.py migrate --fake-initialpython manage.py collectstatic --noinput- Check user role and permissions
- Verify document permissions are set correctly
- Ensure user is assigned to correct department
This project is for educational and demonstration purposes.
For issues and questions, please refer to the Django documentation:
This is a sample project for demonstration purposes. Feel free to extend and modify as needed.