settings.py 4.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164
  1. """
  2. Django settings for desecapi project.
  3. For more information on this file, see
  4. https://docs.djangoproject.com/en/1.7/topics/settings/
  5. For the full list of settings and their values, see
  6. https://docs.djangoproject.com/en/1.7/ref/settings/
  7. """
  8. # Build paths inside the project like this: os.path.join(BASE_DIR, ...)
  9. import os
  10. BASE_DIR = os.path.dirname(os.path.dirname(__file__))
  11. # Quick-start development settings - unsuitable for production
  12. # See https://docs.djangoproject.com/en/1.7/howto/deployment/checklist/
  13. # SECURITY WARNING: keep the secret key used in production secret!
  14. SECRET_KEY = os.environ['DESECSTACK_API_SECRETKEY']
  15. # SECURITY WARNING: don't run with debug turned on in production!
  16. DEBUG = False
  17. if os.environ.get('DESECSTACK_API_DEBUG', "").upper() == "TRUE":
  18. DEBUG = True
  19. ALLOWED_HOSTS = os.environ['DESECSTACK_API_ALLOWED_HOSTS'].split()
  20. # Application definition
  21. INSTALLED_APPS = (
  22. 'django.contrib.admin',
  23. 'django.contrib.auth',
  24. 'django.contrib.contenttypes',
  25. 'django.contrib.sessions',
  26. 'django.contrib.messages',
  27. 'django.contrib.staticfiles',
  28. 'rest_framework',
  29. 'rest_framework.authtoken',
  30. 'djoser',
  31. 'desecapi',
  32. )
  33. MIDDLEWARE_CLASSES = (
  34. 'django.contrib.sessions.middleware.SessionMiddleware',
  35. 'django.middleware.common.CommonMiddleware',
  36. 'django.middleware.csrf.CsrfViewMiddleware',
  37. 'django.contrib.auth.middleware.AuthenticationMiddleware',
  38. 'django.contrib.auth.middleware.SessionAuthenticationMiddleware',
  39. 'django.contrib.messages.middleware.MessageMiddleware',
  40. 'django.middleware.clickjacking.XFrameOptionsMiddleware',
  41. )
  42. ROOT_URLCONF = 'desecapi.urls'
  43. WSGI_APPLICATION = 'desecapi.wsgi.application'
  44. # Database
  45. # https://docs.djangoproject.com/en/1.7/ref/settings/#databases
  46. DATABASES = {
  47. 'default': {
  48. 'ENGINE': 'django.db.backends.mysql',
  49. 'NAME': 'desec',
  50. 'USER': 'desec',
  51. 'PASSWORD': os.environ['DESECSTACK_DBAPI_PASSWORD_desec'],
  52. 'HOST': 'dbapi',
  53. 'CHARSET': 'utf8mb4',
  54. 'TEST': {
  55. 'CHARSET': 'utf8mb4',
  56. },
  57. 'OPTIONS': {
  58. 'init_command': "SET sql_mode='STRICT_TRANS_TABLES'",
  59. }
  60. },
  61. }
  62. # Internationalization
  63. # https://docs.djangoproject.com/en/1.7/topics/i18n/
  64. LANGUAGE_CODE = 'en-us'
  65. TIME_ZONE = 'UTC'
  66. USE_I18N = True
  67. USE_L10N = True
  68. USE_TZ = True
  69. # Static files (CSS, JavaScript, Images)
  70. # https://docs.djangoproject.com/en/1.7/howto/static-files/
  71. STATIC_URL = '/api/static/'
  72. REST_FRAMEWORK = {
  73. 'DEFAULT_AUTHENTICATION_CLASSES': (
  74. 'rest_framework.authentication.TokenAuthentication',
  75. ),
  76. }
  77. # user management configuration
  78. DJOSER = {
  79. 'DOMAIN': 'desec.io',
  80. 'SITE_NAME': 'deSEC',
  81. 'PASSWORD_RESET_CONFIRM_URL': '#/password/reset/confirm/{uid}/{token}',
  82. 'ACTIVATION_URL': '#/activate/{uid}/{token}',
  83. 'LOGIN_AFTER_ACTIVATION': True,
  84. 'SEND_ACTIVATION_EMAIL': False,
  85. }
  86. TEMPLATES = [
  87. {
  88. 'BACKEND': 'django.template.backends.django.DjangoTemplates',
  89. 'DIRS': [],
  90. 'APP_DIRS': True,
  91. 'OPTIONS': {
  92. 'context_processors': [
  93. 'django.template.context_processors.debug',
  94. 'django.template.context_processors.request',
  95. 'django.contrib.auth.context_processors.auth',
  96. 'django.contrib.messages.context_processors.messages',
  97. ],
  98. },
  99. },
  100. ]
  101. # How and where to send mail
  102. EMAIL_HOST = os.environ['DESECSTACK_API_EMAIL_HOST']
  103. EMAIL_HOST_USER = os.environ['DESECSTACK_API_EMAIL_HOST_USER']
  104. EMAIL_HOST_PASSWORD = os.environ['DESECSTACK_API_EMAIL_HOST_PASSWORD']
  105. EMAIL_PORT = os.environ['DESECSTACK_API_EMAIL_PORT']
  106. DEFAULT_FROM_EMAIL = 'deSEC <support@desec.io>'
  107. ADMINS = [(address.split("@")[0], address) for address in os.environ['DESECSTACK_API_ADMIN'].split()]
  108. # use our own user model
  109. AUTH_USER_MODEL = 'desecapi.User'
  110. # PowerDNS API access
  111. NSLORD_PDNS_API = 'http://nslord:8081/api/v1/servers/localhost'
  112. NSLORD_PDNS_API_TOKEN = os.environ['DESECSTACK_NSLORD_APIKEY']
  113. NSMASTER_PDNS_API = 'http://nsmaster:8081/api/v1/servers/localhost'
  114. NSMASTER_PDNS_API_TOKEN = os.environ['DESECSTACK_NSMASTER_APIKEY']
  115. # SEPA direct debit settings
  116. SEPA = {
  117. 'CREDITOR_ID': os.environ['DESECSTACK_API_SEPA_CREDITOR_ID'],
  118. }
  119. # recaptcha
  120. NORECAPTCHA_SITE_KEY = os.environ['DESECSTACK_NORECAPTCHA_SITE_KEY']
  121. NORECAPTCHA_SECRET_KEY = os.environ['DESECSTACK_NORECAPTCHA_SECRET_KEY']
  122. NORECAPTCHA_WIDGET_TEMPLATE = 'captcha-widget.html'
  123. # abuse protection
  124. ABUSE_BY_REMOTE_IP_LIMIT = 1
  125. ABUSE_BY_REMOTE_IP_PERIOD_HRS = 48
  126. ABUSE_BY_EMAIL_HOSTNAME_LIMIT = 1
  127. ABUSE_BY_EMAIL_HOSTNAME_PERIOD_HRS = 24
  128. LIMIT_USER_DOMAIN_COUNT_DEFAULT = 5