🐛(backend) ignore CSPs for API docs in development

With Content Security Policies activated, swagger (and redoc)
auto-generated API documentation is no longer accessible even locally.
To restore this feature, we've excluded CSP for related URLs only in
the `Development` configuration.
This commit is contained in:
Julien Maupetit
2026-08-05 10:39:48 +02:00
parent b956be12e5
commit b297d79c32
2 changed files with 5 additions and 0 deletions
+1
View File
@@ -15,6 +15,7 @@ and this project adheres to
### Fixed
- 🐛(frontend) redirect homepage to login when homepage feat is disabled #2521
- 🐛(backend) ignore CSPs for API docs in development
### Changed
+4
View File
@@ -1283,6 +1283,10 @@ class Development(Base):
def __init__(self):
# pylint: disable=invalid-name
self.INSTALLED_APPS += ["django_extensions", "drf_spectacular_sidecar"]
self.CONTENT_SECURITY_POLICY["EXCLUDE_URL_PREFIXES"] += [
f"/api/{self.API_VERSION}/swagger",
f"/api/{self.API_VERSION}/redoc",
]
class Test(Base):