Browse Source

Desactivation des réglages de sécurité HTTPS par défault

rewrite_authors
Gabriel Detraz 8 years ago
parent
commit
c2c1daab79
  1. 12
      re2o/settings_local.example.py

12
re2o/settings_local.example.py

@ -53,12 +53,12 @@ DATABASES = {
}
}
# Security settings
SECURE_CONTENT_TYPE_NOSNIFF = True
SECURE_BROWSER_XSS_FILTER = True
SESSION_COOKIE_SECURE = True
CSRF_COOKIE_SECURE = True
CSRF_COOKIE_HTTPONLY = True
# Security settings, à activer une fois https en place
SECURE_CONTENT_TYPE_NOSNIFF = False
SECURE_BROWSER_XSS_FILTER = False
SESSION_COOKIE_SECURE = False
CSRF_COOKIE_SECURE = False
CSRF_COOKIE_HTTPONLY = False
X_FRAME_OPTIONS = 'DENY'
SESSION_COOKIE_AGE = 60 * 60 * 3

Loading…
Cancel
Save