diff --git a/config/settings/selfhosted.py b/config/settings/selfhosted.py index 6b69d6f..8fc0480 100644 --- a/config/settings/selfhosted.py +++ b/config/settings/selfhosted.py @@ -105,20 +105,22 @@ CSRF_TRUSTED_ORIGINS = os.environ.get( # =================================================================== # SSL/HTTPS Security -# Note: SECURE_SSL_REDIRECT is False because Nginx Proxy Manager handles SSL termination -# NPM redirects HTTP to HTTPS at the reverse proxy level -SECURE_SSL_REDIRECT = False # NPM handles this +# Note: SSL termination, HTTP→HTTPS redirect, and HSTS are handled by Nginx Proxy Manager +# NPM is configured with: Force SSL = On, HSTS Enabled = On +SECURE_SSL_REDIRECT = False # NPM handles HTTP→HTTPS redirect +SECURE_PROXY_SSL_HEADER = ('HTTP_X_FORWARDED_PROTO', 'https') # Trust NPM's X-Forwarded-Proto header -# HTTP Strict Transport Security (HSTS) -# Tells browsers to always use HTTPS for this domain (1 year = 31536000 seconds) -SECURE_HSTS_SECONDS = 31536000 -SECURE_HSTS_INCLUDE_SUBDOMAINS = True -SECURE_HSTS_PRELOAD = True +# HSTS - Disabled in Django since NPM sends HSTS headers +# NPM is configured to send: Strict-Transport-Security: max-age=31536000 +# Enabling here would create duplicate headers +SECURE_HSTS_SECONDS = 0 # Disabled - NPM handles HSTS # Cookie Security +# These are still needed even though NPM handles SSL SESSION_COOKIE_SECURE = True # Only send session cookies over HTTPS CSRF_COOKIE_SECURE = True # Only send CSRF cookies over HTTPS CSRF_COOKIE_HTTPONLY = True # Prevent JavaScript access to CSRF cookie +SESSION_COOKIE_HTTPONLY = True # Prevent JavaScript access to session cookie # Additional Security Headers SECURE_BROWSER_XSS_FILTER = True