diff options
Diffstat (limited to 'settings.py')
-rw-r--r-- | settings.py | 5 |
1 files changed, 3 insertions, 2 deletions
diff --git a/settings.py b/settings.py index 632ffbf..fce69da 100644 --- a/settings.py +++ b/settings.py @@ -117,7 +117,8 @@ APPEND_SLASH = False # never relevant because we have urls that match unknown fi SMART_APPEND_SLASH = True #not eorking as middleware different after Dj2.0 -LOGIN_REDIRECT_URL = '/' +LOGIN_REDIRECT_URL = '/' # does not seem to have any effect + SECURE_CONTENT_TYPE_NOSNIFF = True SECURE_BROWSER_XSS_FILTER = True # SESSION_COOKIE_SECURE = True # if enabled, cannot login to Django control panel, bug elsewhere? @@ -128,7 +129,7 @@ DEFAULT_AUTO_FIELD = 'django.db.models.BigAutoField' # from Django 3.2 INSTALLED_APPS = ( 'django.contrib.admin', - 'django.contrib.auth', + 'django.contrib.auth', # includes the url redirections for login, logout 'django.contrib.contenttypes', 'django.contrib.sessions', 'django.contrib.messages', |