from pathlib import Path import os import re # Build paths inside the project like this: BASE_DIR / 'subdir'. BASE_DIR = Path(__file__).resolve().parent.parent # Quick-start development settings - unsuitable for production # See https://docs.djangoproject.com/en/4.1/howto/deployment/checklist/ # SECURITY WARNING: don't run with debug turned on in production! DEBUG = os.environ.get("DEBUG", "").lower() == "true" # SECURITY WARNING: keep the secret key used in production secret! SECRET_KEY = os.environ.get("SECRET_KEY") if not DEBUG and (not SECRET_KEY or SECRET_KEY == "secret"): from django.core.exceptions import ImproperlyConfigured raise ImproperlyConfigured("SECRET_KEY environment variable is required in production (and must not be 'secret')") if not SECRET_KEY: SECRET_KEY = "insecure-dev-secret-key-change-in-production" ALLOWED_HOSTS = os.environ.get("ALLOWED_HOSTS", "*").split(",") # Application definition INSTALLED_APPS = [ 'django.contrib.admin', 'django.contrib.auth', 'django.contrib.contenttypes', 'django.contrib.sessions', 'django.contrib.messages', 'django.contrib.staticfiles', 'rest_framework', 'rest_framework.authtoken', 'import_export', 'push_notifications', 'corsheaders', 'equipment', 'exercise', 'registered_user', 'workout', 'muscle', 'scripts', 'video', 'superset', 'generator', ] MIDDLEWARE = [ 'django.middleware.security.SecurityMiddleware', "whitenoise.middleware.WhiteNoiseMiddleware", 'corsheaders.middleware.CorsMiddleware', 'django.contrib.sessions.middleware.SessionMiddleware', 'django.middleware.common.CommonMiddleware', 'django.middleware.csrf.CsrfViewMiddleware', 'django.contrib.auth.middleware.AuthenticationMiddleware', 'django.contrib.messages.middleware.MessageMiddleware', 'django.middleware.clickjacking.XFrameOptionsMiddleware', ] if DEBUG: INSTALLED_APPS += ['debug_toolbar'] MIDDLEWARE += ['debug_toolbar.middleware.DebugToolbarMiddleware'] ROOT_URLCONF = 'werkout_api.urls' TEMPLATES = [ { 'BACKEND': 'django.template.backends.django.DjangoTemplates', 'DIRS': ['templates'], 'APP_DIRS': True, 'OPTIONS': { 'context_processors': [ 'django.template.context_processors.debug', 'django.template.context_processors.request', 'django.contrib.auth.context_processors.auth', 'django.contrib.messages.context_processors.messages', ], }, }, ] WSGI_APPLICATION = 'werkout_api.wsgi.application' # Database # https://docs.djangoproject.com/en/4.1/ref/settings/#databases if os.environ.get("DATABASE_URL"): CSRF_TRUSTED_ORIGINS = ['https://*.werkout.fitness', 'https://*.treytartt.com'] # Parse the DATABASE_URL env var. USER, PASSWORD, HOST, PORT, NAME = re.match("^postgres://(?P.*?)\:(?P.*?)\@(?P.*?)\:(?P\d+)\/(?P.*?)$", os.environ.get("DATABASE_URL", "")).groups() DATABASES = { 'default': { 'ENGINE': 'django.db.backends.postgresql', 'NAME': NAME, 'USER': USER, 'PASSWORD': PASSWORD, 'HOST': HOST, 'PORT': int(PORT), } } CACHES = { "default": { "BACKEND": "django_redis.cache.RedisCache", "LOCATION": [os.environ.get('REDIS_URL', 'redis://localhost:6379')], "OPTIONS": { "CLIENT_CLASS": "django_redis.client.DefaultClient" }, } } CELERY_BROKER_URL = os.environ.get("REDIS_URL", "") + "/1" CELERY_RESULT_BACKEND = os.environ.get("REDIS_URL", "") + "/1" INTERNAL_IPS = [ "127.0.0.1", ] else: DATABASES = { 'default': { 'ENGINE': 'django.db.backends.postgresql', 'NAME': os.environ.get('DB_NAME', 'werkout'), 'USER': os.environ.get('DB_USER', 'werkout'), 'PASSWORD': os.environ.get('DB_PASSWORD', 'werkout'), 'HOST': os.environ.get('DB_HOST', 'db'), 'PORT': os.environ.get('DB_PORT', '5432'), } } CACHES = { "default": { "BACKEND": "django.core.cache.backends.locmem.LocMemCache", } } CELERY_BROKER_URL = "redis://redis:6379" CELERY_RESULT_BACKEND = "redis://redis:6379" INTERNAL_IPS = [ "127.0.0.1", ] # Password validation # https://docs.djangoproject.com/en/4.1/ref/settings/#auth-password-validators AUTH_PASSWORD_VALIDATORS = [ { 'NAME': 'django.contrib.auth.password_validation.UserAttributeSimilarityValidator', }, { 'NAME': 'django.contrib.auth.password_validation.MinimumLengthValidator', }, { 'NAME': 'django.contrib.auth.password_validation.CommonPasswordValidator', }, { 'NAME': 'django.contrib.auth.password_validation.NumericPasswordValidator', }, ] # Internationalization # https://docs.djangoproject.com/en/4.1/topics/i18n/ LANGUAGE_CODE = 'en-us' TIME_ZONE = 'UTC' USE_I18N = True USE_TZ = True # Default primary key field type # https://docs.djangoproject.com/en/4.1/ref/settings/#default-auto-field DEFAULT_AUTO_FIELD = 'django.db.models.BigAutoField' STATIC_URL = 'static/' STATIC_ROOT = os.path.join(BASE_DIR, 'static') MEDIA_URL = '/media/' MEDIA_ROOT = os.path.join(BASE_DIR, "media") # CORS settings if DEBUG: CORS_ALLOW_ALL_ORIGINS = True else: CORS_ALLOW_ALL_ORIGINS = False CORS_ALLOWED_ORIGINS = os.environ.get("CORS_ALLOWED_ORIGINS", "").split(",") if os.environ.get("CORS_ALLOWED_ORIGINS") else [ 'http://localhost:3000', 'http://127.0.0.1:3000', ] CORS_ALLOW_CREDENTIALS = True # HTTPS security settings for production if not DEBUG: SECURE_SSL_REDIRECT = os.environ.get("SECURE_SSL_REDIRECT", "true").lower() == "true" SECURE_HSTS_SECONDS = 31536000 SECURE_HSTS_INCLUDE_SUBDOMAINS = True SECURE_HSTS_PRELOAD = True SESSION_COOKIE_SECURE = True CSRF_COOKIE_SECURE = True SECURE_PROXY_SSL_HEADER = ("HTTP_X_FORWARDED_PROTO", "https")