Internal
Public Access
Since Nginx Proxy Manager is handling Content Security Policy headers at the reverse proxy level, removed django-csp from Django to avoid duplication and simplify configuration. Changes: - Removed django-csp from requirements.txt - Removed CSPMiddleware from middleware stack - Removed CSP_* settings from selfhosted.py - Added comment noting CSP is configured in NPM CSP is now exclusively managed in NPM's Advanced configuration with: - default-src 'self' - script-src/style-src 'self' 'unsafe-inline' (for Django admin) - img-src 'self' data: https: - frame-ancestors 'none' - And other security directives This keeps configuration in one place (NPM) and eliminates dependency on django-csp package. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
31 lines
532 B
Plaintext
31 lines
532 B
Plaintext
# Django core
|
|
Django>=5.0,<6.0
|
|
django-environ>=0.11.0
|
|
django-cors-headers>=4.3.0
|
|
django-filter>=24.0
|
|
|
|
# Django REST Framework
|
|
djangorestframework>=3.14.0
|
|
djangorestframework-simplejwt>=5.3.0
|
|
|
|
# Database
|
|
psycopg2-binary>=2.9.9 # PostgreSQL driver
|
|
dj-database-url>=2.1.0 # Universal database URL parser
|
|
|
|
# Task queue
|
|
celery>=5.3.0
|
|
redis>=5.0.0
|
|
django-celery-beat>=2.5.0
|
|
|
|
# Push notifications
|
|
firebase-admin>=6.4.0
|
|
pywebpush>=1.14.0
|
|
|
|
# Utilities
|
|
python-dateutil>=2.8.2
|
|
Pillow>=10.0.0
|
|
|
|
# Production
|
|
gunicorn>=21.0.0
|
|
whitenoise>=6.6.0
|