Secure Coding in Python
1h 37mAdvanced2024-12-16
Authors

Ronnie Sheer
Software Developer and Instructor
Course details
Learn how to develop more secure Python applications. In this course, targeted uniquely at advanced Python users, instructor Ronnie Sheer reviews the most common vulnerabilities in Python apps and explains how to set up a coding environment that helps you develop code with security in mind. Learn how to avoid common pitfalls associated with loose typing and assertions and find out how to deserialize Pickle data. Then explore the security features—such as code generation and secrets management—in Django, a popular Python framework. Ronnie also explains how to secure a RESTful API in Django using permissions, data serialization, and automated testing. By the end of this course, you’ll also be equipped with practical tips and strategies for securing applications written with Flask, the powerful micro web framework.
Skills covered
Software Development SecurityGenerative AIPythonArtificial Intelligence (AI)CybersecurityProgramming LanguagesOpen SourceSoftware DevelopmentOne-Off
Concepts
Introduction
- Developing Python securely
- What you should know
- What are secure coding, CERT and other standards
- What is the OWASP Top 10
- Using Codespaces
Setting Up
- Installing software with due caution
- Installing pipenv, Python, Django, Flask, and the Django REST Framework
- Common vulnerabilities and exposures checks
- A few words about encryption and injection
Avoiding Python Pitfalls
- Dynamic typing with Python
- Explicit assertions with Python
- Don't get yourself into a Pickle
- Challenge - Secure the endpoint
- Solution - Secure the endpoint
Securing Django
- Using a separate Python environment for isolation
- Django's batteries included approach
- Generating new projects
AI and Secure Coding
- Generative AI and software development
- AI-powered developer tools
- Prompt injection and jailbreaking
Securing a RESTful API
- Safe serializing
- Permissions
- Testing and security
- Challenge - Run the test, fix the code
- Solution - Serializer fields
Securing Flask
- The challenge of securing Flask
- Flask secrets
- Password hashing with Flask
Conclusion
- Next steps - Secure coding