Internal
Public Access
Update security settings for NPM SSL/HSTS handling
Since Nginx Proxy Manager handles SSL termination, Force SSL, and HSTS: - Set SECURE_HSTS_SECONDS = 0 (NPM sends HSTS headers) - Added SECURE_PROXY_SSL_HEADER to trust X-Forwarded-Proto from NPM - Added SESSION_COOKIE_HTTPONLY for additional session security - Documented NPM configuration: Force SSL = On, HSTS Enabled = On This prevents duplicate HSTS headers and ensures Django correctly detects HTTPS connections behind the reverse proxy. Cookie security (SESSION/CSRF_COOKIE_SECURE) remains enabled as these are application-level settings independent of the reverse proxy. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 4.5
parent
a06b4365ed
commit
19ff672562
@@ -105,20 +105,22 @@ CSRF_TRUSTED_ORIGINS = os.environ.get(
|
|||||||
# ===================================================================
|
# ===================================================================
|
||||||
|
|
||||||
# SSL/HTTPS Security
|
# SSL/HTTPS Security
|
||||||
# Note: SECURE_SSL_REDIRECT is False because Nginx Proxy Manager handles SSL termination
|
# Note: SSL termination, HTTP→HTTPS redirect, and HSTS are handled by Nginx Proxy Manager
|
||||||
# NPM redirects HTTP to HTTPS at the reverse proxy level
|
# NPM is configured with: Force SSL = On, HSTS Enabled = On
|
||||||
SECURE_SSL_REDIRECT = False # NPM handles this
|
SECURE_SSL_REDIRECT = False # NPM handles HTTP→HTTPS redirect
|
||||||
|
SECURE_PROXY_SSL_HEADER = ('HTTP_X_FORWARDED_PROTO', 'https') # Trust NPM's X-Forwarded-Proto header
|
||||||
|
|
||||||
# HTTP Strict Transport Security (HSTS)
|
# HSTS - Disabled in Django since NPM sends HSTS headers
|
||||||
# Tells browsers to always use HTTPS for this domain (1 year = 31536000 seconds)
|
# NPM is configured to send: Strict-Transport-Security: max-age=31536000
|
||||||
SECURE_HSTS_SECONDS = 31536000
|
# Enabling here would create duplicate headers
|
||||||
SECURE_HSTS_INCLUDE_SUBDOMAINS = True
|
SECURE_HSTS_SECONDS = 0 # Disabled - NPM handles HSTS
|
||||||
SECURE_HSTS_PRELOAD = True
|
|
||||||
|
|
||||||
# Cookie Security
|
# Cookie Security
|
||||||
|
# These are still needed even though NPM handles SSL
|
||||||
SESSION_COOKIE_SECURE = True # Only send session cookies over HTTPS
|
SESSION_COOKIE_SECURE = True # Only send session cookies over HTTPS
|
||||||
CSRF_COOKIE_SECURE = True # Only send CSRF cookies over HTTPS
|
CSRF_COOKIE_SECURE = True # Only send CSRF cookies over HTTPS
|
||||||
CSRF_COOKIE_HTTPONLY = True # Prevent JavaScript access to CSRF cookie
|
CSRF_COOKIE_HTTPONLY = True # Prevent JavaScript access to CSRF cookie
|
||||||
|
SESSION_COOKIE_HTTPONLY = True # Prevent JavaScript access to session cookie
|
||||||
|
|
||||||
# Additional Security Headers
|
# Additional Security Headers
|
||||||
SECURE_BROWSER_XSS_FILTER = True
|
SECURE_BROWSER_XSS_FILTER = True
|
||||||
|
|||||||
Reference in New Issue
Block a user