mirror of
https://github.com/Lyxminxx/jast.git
synced 2026-10-11 20:57:43 +02:00
fixed csrf
This commit is contained in:
1 parent
90ad2f05ce
commit
befd450016
1 file changed
+16
-5
+16
-5
@@ -12,6 +12,8 @@ https://docs.djangoproject.com/en/6.1/ref/settings/
|
|||||||
|
|
||||||
from pathlib import Path
|
from pathlib import Path
|
||||||
|
|
||||||
|
import os
|
||||||
|
|
||||||
# Build paths inside the project like this: BASE_DIR / 'subdir'.
|
# Build paths inside the project like this: BASE_DIR / 'subdir'.
|
||||||
BASE_DIR = Path(__file__).resolve().parent.parent
|
BASE_DIR = Path(__file__).resolve().parent.parent
|
||||||
|
|
||||||
@@ -26,14 +28,23 @@ SECRET_KEY = 'django-insecure-m#==%hz74d192o)4!#_!dpz%$yox@!hkabc9)pggkkiuvc7((q
|
|||||||
DEBUG = False
|
DEBUG = False
|
||||||
|
|
||||||
ALLOWED_HOSTS = ['*']
|
ALLOWED_HOSTS = ['*']
|
||||||
|
|
||||||
|
ALLOWED_HOSTS = os.getenv(
|
||||||
|
"ALLOWED_HOSTS",
|
||||||
|
"jastapi.mydomain.com,jast.mydomain.com,backend,localhost,127.0.0.1"
|
||||||
|
).split(",")
|
||||||
|
|
||||||
|
csrf_origins_env = os.getenv("CSRF_TRUSTED_ORIGINS", "")
|
||||||
|
if csrf_origins_env:
|
||||||
|
CSRF_TRUSTED_ORIGINS = [origin.strip() for origin in csrf_origins_env.split(",") if origin.strip()]
|
||||||
|
|
||||||
|
else:
|
||||||
CSRF_TRUSTED_ORIGINS = [
|
CSRF_TRUSTED_ORIGINS = [
|
||||||
'https://jast.maddiemightcry.xyz',
|
"https://jast.mydomain.com",
|
||||||
'http://100.104.132.118:8000',
|
"https://jastapi.mydomain.com",
|
||||||
'http://localhost:8000',
|
|
||||||
'http://127.0.0.1:8000',
|
|
||||||
]
|
]
|
||||||
|
|
||||||
# Application definition
|
SECURE_PROXY_SSL_HEADER = ('HTTP_X_FORWARDED_PROTO', 'https')
|
||||||
|
|
||||||
INSTALLED_APPS = [
|
INSTALLED_APPS = [
|
||||||
'django.contrib.admin',
|
'django.contrib.admin',
|
||||||
|
|||||||
Reference in new issue
Block a user