Have you ever stopped to think what your staff users can do in Django admin? Did you know staff users with misconfigured permissions on the user model can make themselves superusers?
Permissive permissions to staff users can cause disastrous human errors at best, and lead to major data leaks at worst. With the great staff of RealPython, I wrote about ways to protect your Django admin and make it safer for users, and staff users.
Read "What You Need to Know to Manage Users in Django Admin" on RealPython ≫