1. 18 Feb, 2016 3 commits
    • Vladimir Mencl's avatar
      Revise secure URL settings (cont.) · 6d829672
      Vladimir Mencl authored
      Actually remove the X-Forwarded-SSL header from the Apache mod_wsgi snippet.
      6d829672
    • Vladimir Mencl's avatar
      Revise secure URL settings · 262e5434
      Vladimir Mencl authored
      As per discussion in in #8 (primary mode of deployment is with mod_wsgi):
      
      * Comment out the header setting at Django side and also move it from
        settings.py to local_settings.py (because it's now a customizable item).
      * Change the header name to ````X-Forwarded-Protocol: https````
      * Change the Apache recommendation to use the header name and take it out of
        the mod_uwsgi snippet - and instead add a new section describing
        mod_proxy_http as an option.
      262e5434
    • Vladimir Mencl's avatar
      Use secure URLs when already using SSL · 2c10a316
      Vladimir Mencl authored
      Django constructs redirect URLs as https only if request.is_secure() is true.
      
      And that evaluates to true if either uwsgi sets wsgi.url_scheme to https, or
      if the request header contains a key + value configured as a tuple in
      settings.SECURE_PROXY_SSL_HEADER
      
      As some parts might be accessed over plain http and some over https (if Apache
      exposes both ports), the easiest is to:
      
      * Use the conventional header:
      
              X-Forwarded-SSL: on
      
      * Set this header from Apache SSL VirtualHost
      
      * Configure Django to check for this header with:
      
              SECURE_PROXY_SSL_HEADER = ('X-Forwarded-SSL', 'on')
      
      As this is an essential security setting that shouldn't need additional tweaks,
      adding the setting to settings.py (and not local_settings.py).
      
      Without this fix, the login form at /admin/ would upon successful login
      redirect to plain http, even when accessed over https.
      2c10a316
  2. 21 Nov, 2015 1 commit
  3. 20 Nov, 2015 1 commit
  4. 04 Nov, 2015 1 commit
  5. 28 Sep, 2015 1 commit
  6. 14 Jul, 2015 1 commit
  7. 29 Oct, 2014 1 commit
  8. 06 Oct, 2014 1 commit
  9. 02 Oct, 2014 8 commits
  10. 30 Sep, 2014 4 commits
  11. 29 Sep, 2014 14 commits
  12. 26 Sep, 2014 3 commits
  13. 05 Aug, 2014 1 commit