test
This commit is contained in:
+133
-6
@@ -11,38 +11,165 @@ https://docs.djangoproject.com/en/6.0/ref/settings/
|
||||
"""
|
||||
|
||||
from pathlib import Path
|
||||
import os
|
||||
|
||||
# Build paths inside the project like this: BASE_DIR / 'subdir'.
|
||||
BASE_DIR = Path(__file__).resolve().parent.parent
|
||||
|
||||
|
||||
# Quick-start development settings - unsuitable for production
|
||||
# See https://docs.djangoproject.com/en/6.0/howto/deployment/checklist/
|
||||
|
||||
# 安全设置
|
||||
SECURE_SSL_REDIRECT = False
|
||||
SESSION_COOKIE_SECURE = False
|
||||
CSRF_COOKIE_SECURE = False
|
||||
SECURE_HSTS_SECONDS = 31536000
|
||||
SECURE_HSTS_INCLUDE_SUBDOMAINS = True
|
||||
SECURE_HSTS_PRELOAD = True
|
||||
SECURE_PROXY_SSL_HEADER = ('HTTP_X_FORWARDED_PROTO', 'https')
|
||||
|
||||
# SECURITY WARNING: keep the secret key used in production secret!
|
||||
SECRET_KEY = 'django-insecure-j+-psq=m++l7hup73k1eg+wm-b&2_)!+_^o=6(=xc$1px*kqt@'
|
||||
|
||||
# SECURITY WARNING: don't run with debug turned on in production!
|
||||
DEBUG = True
|
||||
|
||||
ALLOWED_HOSTS = []
|
||||
# 生产环境配置
|
||||
if not DEBUG:
|
||||
# 从环境变量获取,并过滤空值
|
||||
cors_env = os.environ.get('CORS_ALLOWED_ORIGINS', '')
|
||||
|
||||
if cors_env:
|
||||
# 解析并验证每个 origin
|
||||
allowed_origins = []
|
||||
for origin in cors_env.split(','):
|
||||
origin = origin.strip()
|
||||
if origin: # 非空
|
||||
# 确保有协议(http:// 或 https://)
|
||||
if not origin.startswith(('http://', 'https://')):
|
||||
# 自动添加 https://
|
||||
origin = f'https://{origin}'
|
||||
allowed_origins.append(origin)
|
||||
|
||||
# Application definition
|
||||
CORS_ALLOWED_ORIGINS = allowed_origins
|
||||
CORS_ALLOW_ALL_ORIGINS = False
|
||||
else:
|
||||
# 如果没有设置,使用默认
|
||||
CORS_ALLOWED_ORIGINS = []
|
||||
CORS_ALLOW_ALL_ORIGINS = False
|
||||
else:
|
||||
# 开发环境
|
||||
CORS_ALLOW_ALL_ORIGINS = True
|
||||
CORS_ALLOWED_ORIGINS = []
|
||||
|
||||
ALLOWED_HOSTS = ["*"]
|
||||
|
||||
CORS_ALLOWED_ORIGINS = [
|
||||
"http://localhost:3000", # 例如:您的React/Vue开发服务器
|
||||
"http://127.0.0.1:3000",
|
||||
]
|
||||
|
||||
# CORS设置
|
||||
CORS_ALLOW_ALL_ORIGINS = False
|
||||
|
||||
# 允许凭据
|
||||
CORS_ALLOW_CREDENTIALS = True
|
||||
|
||||
# 允许的请求头
|
||||
CORS_ALLOW_HEADERS = [
|
||||
'accept',
|
||||
'accept-encoding',
|
||||
'authorization',
|
||||
'content-type',
|
||||
'dnt',
|
||||
'origin',
|
||||
'user-agent',
|
||||
'x-csrftoken',
|
||||
'x-requested-with',
|
||||
]
|
||||
|
||||
# 允许的 HTTP 方法
|
||||
CORS_ALLOW_METHODS = [
|
||||
'DELETE',
|
||||
'GET',
|
||||
'OPTIONS',
|
||||
'PATCH',
|
||||
'POST',
|
||||
'PUT',
|
||||
]
|
||||
|
||||
CORS_PREFLIGHT_MAX_AGE = 86400
|
||||
|
||||
REST_FRAMEWORK = {
|
||||
'DEFAULT_RENDERER_CLASSES': [
|
||||
'rest_framework.renderers.JSONRenderer',
|
||||
],
|
||||
'DEFAULT_PARSER_CLASSES': [
|
||||
'rest_framework.parsers.JSONParser',
|
||||
],
|
||||
|
||||
'DEFAULT_AUTHENTICATION_CLASSES': [
|
||||
'rest_framework_simplejwt.authentication.JWTAuthentication',
|
||||
'rest_framework.authentication.SessionAuthentication',
|
||||
# 如果您不需要标准的TokenAuthentication,可以移除下面这行
|
||||
# 'rest_framework.authentication.TokenAuthentication',
|
||||
],
|
||||
'DEFAULT_PERMISSION_CLASSES': [
|
||||
'rest_framework.permissions.IsAuthenticated',
|
||||
],
|
||||
}
|
||||
|
||||
from datetime import timedelta
|
||||
|
||||
# Simple JWT 设置
|
||||
SIMPLE_JWT = {
|
||||
'ACCESS_TOKEN_LIFETIME': timedelta(minutes=60), # 访问令牌有效期
|
||||
'REFRESH_TOKEN_LIFETIME': timedelta(days=7), # 刷新令牌有效期
|
||||
'ROTATE_REFRESH_TOKENS': True, # 刷新访问令牌时返回新刷新令牌
|
||||
'BLACKLIST_AFTER_ROTATION': True, # 启用黑名单应用(需安装django-rest-framework-simplejwt.token_blacklist)
|
||||
'UPDATE_LAST_LOGIN': True, # 更新用户最后登录时间
|
||||
|
||||
'ALGORITHM': 'HS256', # 加密算法
|
||||
'SIGNING_KEY': SECRET_KEY, # 签名密钥,使用您的SECRET_KEY
|
||||
'VERIFYING_KEY': None,
|
||||
'AUDIENCE': None,
|
||||
'ISSUER': None,
|
||||
|
||||
'AUTH_HEADER_TYPES': ('Bearer',), # 认证头前缀,通常是`Bearer`
|
||||
'AUTH_HEADER_NAME': 'HTTP_AUTHORIZATION',
|
||||
'USER_ID_FIELD': 'id', # 用户模型标识字段
|
||||
'USER_ID_CLAIM': 'user_id',
|
||||
}
|
||||
|
||||
AUTH_USER_MODEL = 'user.FUser'
|
||||
|
||||
INSTALLED_APPS = [
|
||||
'app.apps.AppConfig',
|
||||
"user.apps.UserConfig",
|
||||
"api.apps.ApiConfig",
|
||||
|
||||
'django.contrib.admin',
|
||||
'django.contrib.auth',
|
||||
'django.contrib.contenttypes',
|
||||
'django.contrib.sessions',
|
||||
'django.contrib.messages',
|
||||
'django.contrib.staticfiles',
|
||||
'app.apps.AppConfig',
|
||||
|
||||
|
||||
# 第三方应用
|
||||
'rest_framework',
|
||||
'rest_framework_simplejwt',
|
||||
'corsheaders',
|
||||
'channels',
|
||||
'django_filters',
|
||||
'drf_yasg',
|
||||
'django_extensions',
|
||||
|
||||
]
|
||||
|
||||
MIDDLEWARE = [
|
||||
'django.middleware.security.SecurityMiddleware',
|
||||
'django.contrib.sessions.middleware.SessionMiddleware',
|
||||
'corsheaders.middleware.CorsMiddleware',
|
||||
'django.middleware.common.CommonMiddleware',
|
||||
'django.middleware.csrf.CsrfViewMiddleware',
|
||||
'django.contrib.auth.middleware.AuthenticationMiddleware',
|
||||
@@ -68,7 +195,7 @@ TEMPLATES = [
|
||||
},
|
||||
]
|
||||
|
||||
WSGI_APPLICATION = 'chunyu_project.wsgi.application'
|
||||
ASGI_APPLICATION = 'chunyu_project.asgi.application'
|
||||
|
||||
|
||||
# Database
|
||||
|
||||
Reference in New Issue
Block a user