diff --git a/config/settings/selfhosted.py b/config/settings/selfhosted.py index 31b9450..6b69d6f 100644 --- a/config/settings/selfhosted.py +++ b/config/settings/selfhosted.py @@ -100,6 +100,31 @@ CSRF_TRUSTED_ORIGINS = os.environ.get( 'http://localhost:8000' ).split(',') +# =================================================================== +# Security Settings +# =================================================================== + +# SSL/HTTPS Security +# Note: SECURE_SSL_REDIRECT is False because Nginx Proxy Manager handles SSL termination +# NPM redirects HTTP to HTTPS at the reverse proxy level +SECURE_SSL_REDIRECT = False # NPM handles this + +# HTTP Strict Transport Security (HSTS) +# Tells browsers to always use HTTPS for this domain (1 year = 31536000 seconds) +SECURE_HSTS_SECONDS = 31536000 +SECURE_HSTS_INCLUDE_SUBDOMAINS = True +SECURE_HSTS_PRELOAD = True + +# Cookie Security +SESSION_COOKIE_SECURE = True # Only send session cookies over HTTPS +CSRF_COOKIE_SECURE = True # Only send CSRF cookies over HTTPS +CSRF_COOKIE_HTTPONLY = True # Prevent JavaScript access to CSRF cookie + +# Additional Security Headers +SECURE_BROWSER_XSS_FILTER = True +SECURE_CONTENT_TYPE_NOSNIFF = True +X_FRAME_OPTIONS = 'DENY' # Prevent clickjacking + # Static files STATICFILES_STORAGE = 'whitenoise.storage.CompressedManifestStaticFilesStorage'