Skip to content

Commit

Permalink
Update settings.py
Browse files Browse the repository at this point in the history
  • Loading branch information
idabblewith committed Aug 14, 2024
1 parent e6ff878 commit bdc9cfb
Showing 1 changed file with 25 additions and 19 deletions.
44 changes: 25 additions & 19 deletions config/settings.py
Original file line number Diff line number Diff line change
Expand Up @@ -109,10 +109,16 @@
ALLOW_LIST = list(set(ALLOW_LIST))
ALLOWED_HOSTS = ALLOW_LIST

# CSRF_TRUSTED_ORIGINS = [
# r"^https://.*\.dbca\.wa\.gov\.au$",
# r"^http://127\.0\.0\.1:3000$",
# ]
CSRF_TRUSTED_ORIGINS = [
"https://scienceprojects-migrated.dbca.wa.gov.au",
"https://scienceprojects-test.dbca.wa.gov.au",
"https://scienceprojects.dbca.wa.gov.au",
"https://profiles-test.dbca.wa.gov.au",
"https://profiles-migrated.dbca.wa.gov.au",
"https://profiles.dbca.wa.gov.au",
"http://127.0.0.1:3000",
"http://127.0.0.1",
]

if DEBUG:
# Ensure all dbca subroutes allowed and local dev
Expand Down Expand Up @@ -195,7 +201,20 @@

INSTALLED_APPS = SYSTEM_APPS + THIRD_PARTY_APPS + CUSTOM_APPS

# HAS NO CSRF
# # HAS NO CSRF
# MIDDLEWARE = [
# "corsheaders.middleware.CorsMiddleware",
# "django.middleware.security.SecurityMiddleware",
# "whitenoise.middleware.WhiteNoiseMiddleware",
# "django.contrib.sessions.middleware.SessionMiddleware",
# "django.contrib.auth.middleware.AuthenticationMiddleware",
# "config.dbca_middleware.DBCAMiddleware",
# "django.middleware.common.CommonMiddleware",
# "django.contrib.messages.middleware.MessageMiddleware",
# "django.middleware.clickjacking.XFrameOptionsMiddleware",
# ]

# if DEBUG:
MIDDLEWARE = [
"corsheaders.middleware.CorsMiddleware",
"django.middleware.security.SecurityMiddleware",
Expand All @@ -204,24 +223,11 @@
"django.contrib.auth.middleware.AuthenticationMiddleware",
"config.dbca_middleware.DBCAMiddleware",
"django.middleware.common.CommonMiddleware",
"django.middleware.csrf.CsrfViewMiddleware",
"django.contrib.messages.middleware.MessageMiddleware",
"django.middleware.clickjacking.XFrameOptionsMiddleware",
]

if DEBUG:
MIDDLEWARE = [
"corsheaders.middleware.CorsMiddleware",
"django.middleware.security.SecurityMiddleware",
"whitenoise.middleware.WhiteNoiseMiddleware",
"django.contrib.sessions.middleware.SessionMiddleware",
"django.contrib.auth.middleware.AuthenticationMiddleware",
"config.dbca_middleware.DBCAMiddleware",
"django.middleware.common.CommonMiddleware",
"django.middleware.csrf.CsrfViewMiddleware",
"django.contrib.messages.middleware.MessageMiddleware",
"django.middleware.clickjacking.XFrameOptionsMiddleware",
]

REST_FRAMEWORK = {
"DEFAULT_PERMISSION_CLASSES": [
"rest_framework.permissions.IsAuthenticated",
Expand Down

0 comments on commit bdc9cfb

Please sign in to comment.