← Back
Editing: base.cpython-311.pyc
� �|�e� � �� � d dl mZ d dlmZ ddlmZmZmZmZ h d�Z dZ dZdZ ed d �� � Z edd �� � Z edd�� � Z edd�� � Z edd�� � Z edd�� � Z edeee d�z d�� � Z edd�� � Z edd�� � Z edd�� � Z edd �� � Z ed!d"�� � Z ed#d$� d%� ee � � � � � � d&�'� � Z ed(d)�� � Zd*� Zd+� Z eej d,�-� � d.� � � Z! eej d,�-� � d/� � � Z" eej d,�-� � d0� � � Z# eej d,�-� � d1� � � Z$ eej d,�-� � d2� � � Z% eej d,�-� � d3� � � Z& eej d,�-� � d4� � � Z' eej d,�-� � d5� � � Z( eej d,�-� � d6� � � Z) eej d,�-� � d7� � � Z* eej d,�-� � d8� � � Z+ eej d,�-� � d9� � � Z, eej � � d:� � � Z-d;S )<� )�settings)�ImproperlyConfigured� )�Error�Tags�Warning�register> � unsafe-url�no-referrer�same-origin� strict-origin�origin-when-cross-origin�no-referrer-when-downgrade�strict-origin-when-cross-origin�originzdjango-insecure-�2 � z�You do not have 'django.middleware.security.SecurityMiddleware' in your MIDDLEWARE so the SECURE_HSTS_SECONDS, SECURE_CONTENT_TYPE_NOSNIFF, SECURE_BROWSER_XSS_FILTER, SECURE_REFERRER_POLICY, and SECURE_SSL_REDIRECT settings will have no effect.z security.W001)�ida3 You do not have 'django.middleware.clickjacking.XFrameOptionsMiddleware' in your MIDDLEWARE, so your pages will not be served with an 'x-frame-options' header. Unless there is a good reason for your site to be served in a frame, you should consider enabling this header to help prevent clickjacking attacks.z security.W002a, You have not set a value for the SECURE_HSTS_SECONDS setting. If your entire site is served only over SSL, you may want to consider setting a value and enabling HTTP Strict Transport Security. Be sure to read the documentation first; enabling HSTS carelessly can cause serious, irreversible problems.z security.W004a You have not set the SECURE_HSTS_INCLUDE_SUBDOMAINS setting to True. Without this, your site is potentially vulnerable to attack via an insecure connection to a subdomain. Only set this to True if you are certain that all subdomains of your domain should be served exclusively via SSL.z security.W005z�Your SECURE_CONTENT_TYPE_NOSNIFF setting is not set to True, so your pages will not be served with an 'X-Content-Type-Options: nosniff' header. You should consider enabling this header to prevent the browser from identifying content types incorrectly.z security.W006a Your SECURE_SSL_REDIRECT setting is not set to True. Unless your site should be available over both SSL and non-SSL connections, you may want to either set this setting True or configure a load balancer or reverse-proxy server to redirect all connections to HTTPS.z security.W008aR Your SECRET_KEY has less than %(min_length)s characters, less than %(min_unique_chars)s unique characters, or it's prefixed with '%(insecure_prefix)s' indicating that it was generated automatically by Django. Please generate a long and random SECRET_KEY, otherwise many of Django's security-critical features will be vulnerable to attack.)� min_length�min_unique_chars�insecure_prefixz security.W009z4You should not have DEBUG set to True in deployment.z security.W018z�You have 'django.middleware.clickjacking.XFrameOptionsMiddleware' in your MIDDLEWARE, but X_FRAME_OPTIONS is not set to 'DENY'. Unless there is a good reason for your site to serve other parts of itself in a frame, you should change it to 'DENY'.z security.W019z.ALLOWED_HOSTS must not be empty in deployment.z security.W020z�You have not set the SECURE_HSTS_PRELOAD setting to True. Without this, your site cannot be submitted to the browser preload list.z security.W021z�You have not set the SECURE_REFERRER_POLICY setting. Without this, your site will not send a Referrer-Policy header. You should consider enabling this header to protect user privacy.z security.W022zDYou have set the SECURE_REFERRER_POLICY setting to an invalid value.zValid values are: {}.z, z security.E023)�hintr z5DEFAULT_HASHING_ALGORITHM must be 'sha1' or 'sha256'.z security.E100c � � dt j v S )Nz-django.middleware.security.SecurityMiddleware�r � MIDDLEWARE� � �B/usr/lib/python3/dist-packages/django/core/checks/security/base.py�_security_middlewarer � s � �:�h�>Q�Q�Qr c � � dt j v S )Nz6django.middleware.clickjacking.XFrameOptionsMiddlewarer r r r �_xframe_middlewarer! � s � �C�x�GZ�Z�Zr T)�deployc �6 � t � � }|rg nt gS �N)r �W001��app_configs�kwargs�passed_checks r �check_security_middlewarer* � s � �'�)�)�L��)�2�2�D�6�)r c �6 � t � � }|rg nt gS r$ )r! �W002r&