Skip to content
Snippets Groups Projects
Commit 7527ded9 authored by Bastien Abadie's avatar Bastien Abadie Committed by Erwan Rouchet
Browse files

Set default frontend urls as CSRF trusted origin

parent 4de1c2ed
No related branches found
No related tags found
1 merge request!1589Set default frontend urls as CSRF trusted origin
......@@ -132,7 +132,7 @@ def get_settings_parser(base_dir):
csrf_parser.add_option('cookie_domain', type=str, default=None)
csrf_parser.add_option('cookie_secure', type=bool, default=False)
csrf_parser.add_option('cookie_samesite', type=CookieSameSiteOption, default=CookieSameSiteOption.Lax)
csrf_parser.add_option('trusted_origins', type=str, many=True, default=[])
csrf_parser.add_option('trusted_origins', type=str, many=True, default=['http://localhost:8080', 'http://127.0.0.1:8080'])
session_parser = parser.add_subparser('session', default={})
session_parser.add_option('cookie_name', type=str, default='arkindex.auth')
......
......@@ -17,7 +17,9 @@ csrf:
cookie_name: arkindex.csrf
cookie_samesite: lax
cookie_secure: false
trusted_origins: []
trusted_origins:
- http://localhost:8080
- http://127.0.0.1:8080
database:
host: localhost
name: arkindex_dev
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment