Fixed #49: set CSRF_TRUSTED_ORIGINS from ALLOWED_HOSTS

merge-requests/154/head
Eliot Berriot 2017-12-15 23:10:42 +01:00
rodzic aa3815dcdb
commit 6b1b2a1227
Nie znaleziono w bazie danych klucza dla tego podpisu
ID klucza GPG: DD6965E2476E5C27
2 zmienionych plików z 9 dodań i 1 usunięć

Wyświetl plik

@ -5,11 +5,17 @@ Changelog
0.2.5 (unreleased)
------------------
Features:
- Import: can now specify search template when querying import sources (#45)
- Player: better handling of errors when fetching the audio file (#46)
- Login form: now redirect to previous page after login (#2)
- 404: a decent 404 template, at least (#48)
Bugfixes:
- Player: better handling of errors when fetching the audio file (#46)
- Csrf: default CSRF_TRUSTED_ORIGINS to ALLOWED_HOSTS to avoid Csrf issues on admin (#49)
0.2.4 (2017-12-14)
------------------

Wyświetl plik

@ -55,6 +55,8 @@ SECURE_PROXY_SSL_HEADER = ('HTTP_X_FORWARDED_PROTO', 'https')
# Hosts/domain names that are valid for this site
# See https://docs.djangoproject.com/en/1.6/ref/settings/#allowed-hosts
ALLOWED_HOSTS = env.list('DJANGO_ALLOWED_HOSTS')
CSRF_TRUSTED_ORIGINS = ALLOWED_HOSTS
# END SITE CONFIGURATION
INSTALLED_APPS += ("gunicorn", )