From 726b28d4fa63c6374abf462f62e69b498d08c908 Mon Sep 17 00:00:00 2001 From: Douglas Hall Date: Mon, 5 Nov 2018 14:31:56 -0500 Subject: [PATCH] Add LOGIN_REDIRECT_WHITELIST setting to production settings. --- lms/envs/production.py | 3 +++ 1 file changed, 3 insertions(+) diff --git a/lms/envs/production.py b/lms/envs/production.py index 2d63d25dbe..0dac57a254 100644 --- a/lms/envs/production.py +++ b/lms/envs/production.py @@ -422,6 +422,9 @@ NOTIFICATION_EMAIL_EDX_LOGO = ENV_TOKENS.get('NOTIFICATION_EMAIL_EDX_LOGO', NOTI # by end users. CSRF_COOKIE_SECURE = ENV_TOKENS.get('CSRF_COOKIE_SECURE', False) +# Whitelist of domains to which the login/logout pages will redirect. +LOGIN_REDIRECT_WHITELIST = ENV_TOKENS.get('LOGIN_REDIRECT_WHITELIST', LOGIN_REDIRECT_WHITELIST) + ############# CORS headers for cross-domain requests ################# if FEATURES.get('ENABLE_CORS_HEADERS') or FEATURES.get('ENABLE_CROSS_DOMAIN_CSRF_COOKIE'):