mirror of
https://github.com/suitenumerique/docs.git
synced 2026-10-01 05:55:16 +02:00
🐛(backend) ignore CSPs for API docs in development
With Content Security Policies activated, swagger (and redoc) auto-generated API documentation is no longer accessible even locally. To restore this feature, we've excluded CSP for related URLs only in the `Development` configuration.
This commit is contained in:
@@ -15,6 +15,7 @@ and this project adheres to
|
||||
### Fixed
|
||||
|
||||
- 🐛(frontend) redirect homepage to login when homepage feat is disabled #2521
|
||||
- 🐛(backend) ignore CSPs for API docs in development
|
||||
|
||||
### Changed
|
||||
|
||||
|
||||
@@ -1283,6 +1283,10 @@ class Development(Base):
|
||||
def __init__(self):
|
||||
# pylint: disable=invalid-name
|
||||
self.INSTALLED_APPS += ["django_extensions", "drf_spectacular_sidecar"]
|
||||
self.CONTENT_SECURITY_POLICY["EXCLUDE_URL_PREFIXES"] += [
|
||||
f"/api/{self.API_VERSION}/swagger",
|
||||
f"/api/{self.API_VERSION}/redoc",
|
||||
]
|
||||
|
||||
|
||||
class Test(Base):
|
||||
|
||||
Reference in New Issue
Block a user