dynamically determine CSRF trusted origins
This commit is contained in:
@@ -36,8 +36,8 @@ if PRODUCTION:
|
|||||||
SECRET_KEY = _get_env_secret_key()
|
SECRET_KEY = _get_env_secret_key()
|
||||||
DEBUG = False
|
DEBUG = False
|
||||||
ALLOWED_HOSTS = _get_env_allowed_hosts()
|
ALLOWED_HOSTS = _get_env_allowed_hosts()
|
||||||
|
CSRF_TRUSTED_ORIGINS = [f"https://{host}" for host in ALLOWED_HOSTS]
|
||||||
STATIC_ROOT = _get_env_static_root()
|
STATIC_ROOT = _get_env_static_root()
|
||||||
CSRF_TRUSTED_ORIGINS = ["https://finance.schokobier.de", ]
|
|
||||||
else:
|
else:
|
||||||
SECRET_KEY = "QetNMYdSKo3kefmltcEeAu52HbyZBxXsROiYesIEwYwnX0rCuv"
|
SECRET_KEY = "QetNMYdSKo3kefmltcEeAu52HbyZBxXsROiYesIEwYwnX0rCuv"
|
||||||
DEBUG = True
|
DEBUG = True
|
||||||
|
|||||||
Reference in New Issue
Block a user