diff --git a/config/settings/production.py b/config/settings/production.py index f972aa9..5bbd7ef 100644 --- a/config/settings/production.py +++ b/config/settings/production.py @@ -21,6 +21,30 @@ SECURE_HSTS_SECONDS = 31536000 # 1 year SECURE_HSTS_INCLUDE_SUBDOMAINS = True SECURE_HSTS_PRELOAD = True +# Security Headers +SECURE_BROWSER_XSS_FILTER = True +SECURE_CONTENT_TYPE_NOSNIFF = True +X_FRAME_OPTIONS = 'DENY' # Prevents clickjacking +SECURE_REFERRER_POLICY = 'strict-origin-when-cross-origin' + +# Cookie Security +SESSION_COOKIE_HTTPONLY = True +SESSION_COOKIE_SAMESITE = 'Strict' +CSRF_COOKIE_HTTPONLY = True +CSRF_COOKIE_SAMESITE = 'Strict' + +# Content Security Policy (CSP) +# Note: Adjust as needed based on your frontend requirements +CSP_DEFAULT_SRC = ("'self'",) +CSP_SCRIPT_SRC = ("'self'",) # Remove 'unsafe-inline' if possible +CSP_STYLE_SRC = ("'self'",) # Remove 'unsafe-inline' if possible +CSP_IMG_SRC = ("'self'", "data:", "https:") +CSP_FONT_SRC = ("'self'",) +CSP_CONNECT_SRC = ("'self'",) +CSP_FRAME_ANCESTORS = ("'none'",) # Prevents embedding in iframes +CSP_BASE_URI = ("'self'",) +CSP_FORM_ACTION = ("'self'",) + # Database import dj_database_url DATABASES = { @@ -46,6 +70,9 @@ CACHES = { # CORS CORS_ALLOWED_ORIGINS = os.environ.get('CORS_ALLOWED_ORIGINS', '').split(',') +# CSRF +CSRF_TRUSTED_ORIGINS = os.environ.get('CSRF_TRUSTED_ORIGINS', '').split(',') if os.environ.get('CSRF_TRUSTED_ORIGINS') else [] + # Static files STATICFILES_STORAGE = 'whitenoise.storage.CompressedManifestStaticFilesStorage'