fix: remove CSRF_TRUSTED_ORIGINS_WITH_SCHEME variable (#37195)
This commit is contained in:
@@ -247,8 +247,6 @@ CROSS_DOMAIN_CSRF_COOKIE_NAME: csrftoken
|
||||
CSRF_COOKIE_SECURE: true
|
||||
CSRF_TRUSTED_ORIGINS:
|
||||
- https://*.localhost
|
||||
CSRF_TRUSTED_ORIGINS_WITH_SCHEME:
|
||||
- https://*.localhost
|
||||
DATABASES:
|
||||
blockstore:
|
||||
CONN_MAX_AGE: 600
|
||||
|
||||
@@ -155,7 +155,6 @@ if 'staticfiles' in CACHES:
|
||||
# Once we have migrated to service assets off S3, then we can convert this back to
|
||||
# managed by the yaml file contents
|
||||
STATICFILES_STORAGE = os.environ.get('STATICFILES_STORAGE', STATICFILES_STORAGE)
|
||||
CSRF_TRUSTED_ORIGINS = _YAML_TOKENS.get('CSRF_TRUSTED_ORIGINS_WITH_SCHEME', [])
|
||||
|
||||
MKTG_URL_LINK_MAP.update(_YAML_TOKENS.get('MKTG_URL_LINK_MAP', {}))
|
||||
|
||||
|
||||
@@ -330,8 +330,6 @@ CROSS_DOMAIN_CSRF_COOKIE_NAME: ''
|
||||
CSRF_COOKIE_SECURE: true
|
||||
CSRF_TRUSTED_ORIGINS:
|
||||
- https://*.sandbox.localhost
|
||||
CSRF_TRUSTED_ORIGINS_WITH_SCHEME:
|
||||
- https://*.sandbox.localhost
|
||||
DASHBOARD_COURSE_LIMIT: 250
|
||||
DATABASES:
|
||||
blockstore:
|
||||
|
||||
@@ -197,8 +197,6 @@ LOGGING = get_logger_config(
|
||||
service_variant=SERVICE_VARIANT,
|
||||
)
|
||||
|
||||
CSRF_TRUSTED_ORIGINS = _YAML_TOKENS.get('CSRF_TRUSTED_ORIGINS_WITH_SCHEME', [])
|
||||
|
||||
if FEATURES['ENABLE_CORS_HEADERS'] or FEATURES.get('ENABLE_CROSS_DOMAIN_CSRF_COOKIE'):
|
||||
CORS_ALLOW_CREDENTIALS = True
|
||||
CORS_ORIGIN_WHITELIST = _YAML_TOKENS.get('CORS_ORIGIN_WHITELIST', ())
|
||||
|
||||
Reference in New Issue
Block a user