From b297d79c32f59e2b43a01594f35a6b10fd9048d7 Mon Sep 17 00:00:00 2001 From: Julien Maupetit Date: Mon, 27 Jul 2026 16:39:46 +0200 Subject: [PATCH] =?UTF-8?q?=F0=9F=90=9B(backend)=20ignore=20CSPs=20for=20A?= =?UTF-8?q?PI=20docs=20in=20development?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit With Content Security Policies activated, swagger (and redoc) auto-generated API documentation is no longer accessible even locally. To restore this feature, we've excluded CSP for related URLs only in the `Development` configuration. --- CHANGELOG.md | 1 + src/backend/impress/settings.py | 4 ++++ 2 files changed, 5 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index fc2b9e814..586ef05c7 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -15,6 +15,7 @@ and this project adheres to ### Fixed - 🐛(frontend) redirect homepage to login when homepage feat is disabled #2521 +- 🐛(backend) ignore CSPs for API docs in development ### Changed diff --git a/src/backend/impress/settings.py b/src/backend/impress/settings.py index 491b7fc96..bce3ea815 100755 --- a/src/backend/impress/settings.py +++ b/src/backend/impress/settings.py @@ -1283,6 +1283,10 @@ class Development(Base): def __init__(self): # pylint: disable=invalid-name self.INSTALLED_APPS += ["django_extensions", "drf_spectacular_sidecar"] + self.CONTENT_SECURITY_POLICY["EXCLUDE_URL_PREFIXES"] += [ + f"/api/{self.API_VERSION}/swagger", + f"/api/{self.API_VERSION}/redoc", + ] class Test(Base):