turn on ALLOWED_HOSTS if SSL_ONLY
This commit is contained in:
parent
ba555e8de7
commit
376d5e1a0e
1 changed files with 8 additions and 8 deletions
|
@ -236,13 +236,6 @@ MASTODON_ALLOWED_SITES: str = env("NEODB_LOGIN_MASTODON_WHITELIST") # type:igno
|
||||||
# Allow user to login via any Mastodon/Pleroma sites
|
# Allow user to login via any Mastodon/Pleroma sites
|
||||||
MASTODON_ALLOW_ANY_SITE = len(MASTODON_ALLOWED_SITES) == 0
|
MASTODON_ALLOW_ANY_SITE = len(MASTODON_ALLOWED_SITES) == 0
|
||||||
|
|
||||||
ALTERNATIVE_DOMAINS = [d.lower() for d in env("NEODB_ALTERNATIVE_DOMAINS", default=[])] # type: ignore
|
|
||||||
|
|
||||||
SITE_DOMAINS = [SITE_DOMAIN] + ALTERNATIVE_DOMAINS
|
|
||||||
|
|
||||||
# ALLOWED_HOSTS = SITE_DOMAINS + ["127.0.0.1"]
|
|
||||||
ALLOWED_HOSTS = ["*"]
|
|
||||||
|
|
||||||
ENABLE_LOCAL_ONLY = env("NEODB_ENABLE_LOCAL_ONLY")
|
ENABLE_LOCAL_ONLY = env("NEODB_ENABLE_LOCAL_ONLY")
|
||||||
|
|
||||||
# Timeout of requests to Mastodon, in seconds
|
# Timeout of requests to Mastodon, in seconds
|
||||||
|
@ -459,16 +452,23 @@ USE_L10N = True
|
||||||
USE_TZ = True
|
USE_TZ = True
|
||||||
|
|
||||||
USE_X_FORWARDED_HOST = True
|
USE_X_FORWARDED_HOST = True
|
||||||
SECURE_PROXY_SSL_HEADER = ("HTTP_X_FORWARDED_PROTO", "https")
|
|
||||||
DATA_UPLOAD_MAX_MEMORY_SIZE = 100 * 1024 * 1024
|
DATA_UPLOAD_MAX_MEMORY_SIZE = 100 * 1024 * 1024
|
||||||
|
|
||||||
CSRF_COOKIE_SECURE = True
|
CSRF_COOKIE_SECURE = True
|
||||||
SESSION_COOKIE_SECURE = True
|
SESSION_COOKIE_SECURE = True
|
||||||
|
|
||||||
SSL_ONLY = env("SSL_ONLY")
|
SSL_ONLY = env("SSL_ONLY")
|
||||||
|
SECURE_PROXY_SSL_HEADER = ("HTTP_X_FORWARDED_PROTO", "https")
|
||||||
|
SECURE_REDIRECT_EXEMPT = [r"^nodeinfo/"]
|
||||||
SECURE_SSL_REDIRECT = SSL_ONLY
|
SECURE_SSL_REDIRECT = SSL_ONLY
|
||||||
SECURE_HSTS_PRELOAD = SSL_ONLY
|
SECURE_HSTS_PRELOAD = SSL_ONLY
|
||||||
SECURE_HSTS_INCLUDE_SUBDOMAINS = SSL_ONLY
|
SECURE_HSTS_INCLUDE_SUBDOMAINS = SSL_ONLY
|
||||||
SECURE_HSTS_SECONDS = 2592000 if SSL_ONLY else 0
|
SECURE_HSTS_SECONDS = 2592000 if SSL_ONLY else 0
|
||||||
|
|
||||||
|
ALTERNATIVE_DOMAINS = [d.lower() for d in env("NEODB_ALTERNATIVE_DOMAINS", default=[])] # type: ignore
|
||||||
|
SITE_DOMAINS = [SITE_DOMAIN] + ALTERNATIVE_DOMAINS
|
||||||
|
ALLOWED_HOSTS = SITE_DOMAINS + ["127.0.0.1"] if SSL_ONLY else ["*"]
|
||||||
|
|
||||||
STATIC_URL = "/s/"
|
STATIC_URL = "/s/"
|
||||||
STATIC_ROOT = env("NEODB_STATIC_ROOT", default=os.path.join(BASE_DIR, "static/")) # type: ignore
|
STATIC_ROOT = env("NEODB_STATIC_ROOT", default=os.path.join(BASE_DIR, "static/")) # type: ignore
|
||||||
|
|
||||||
|
|
Loading…
Add table
Reference in a new issue