I'm trying to create an interactive website with Django for a chat bot. I have a model that stores the chat logs, ChatLogs. It has two fields: sender and message. sender, as the name might suggest, is a foreign key denoting who the sender of message is. It can be either the bot or a user. Here's how I have it set up:
class ChatLogs(models.Model):
sender = models.ForeignKey(User, on_delete=models.CASCADE)
message = models.CharField(max_length=255)
Since the sender can be the bot or a user, I thought to create a record in the User table for the bot:
$ python3 manage.py shell
>>> from django.contrib.auth.models import User
>>> User.objects.create_user("Bot")
I created the user without a password because, according to the Django documentation for createsuperuser, an account created as such can't be used to login. Which I think is a secure way to handle this. My question is, is there any reason I should not be doing this?
From the Django documentation (for createsuperuser):
When run non-interactively, you can provide a password by setting the DJANGO_SUPERUSER_PASSWORD environment variable. Otherwise, no password will be set, and the superuser account will not be able to log in until a password has been manually set for it.