settings.py 4.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172
  1. """
  2. Django settings for desecapi project.
  3. For more information on this file, see
  4. https://docs.djangoproject.com/en/1.7/topics/settings/
  5. For the full list of settings and their values, see
  6. https://docs.djangoproject.com/en/1.7/ref/settings/
  7. """
  8. # Build paths inside the project like this: os.path.join(BASE_DIR, ...)
  9. import os
  10. BASE_DIR = os.path.dirname(os.path.dirname(__file__))
  11. # Quick-start development settings - unsuitable for production
  12. # See https://docs.djangoproject.com/en/1.7/howto/deployment/checklist/
  13. # SECURITY WARNING: keep the secret key used in production secret!
  14. SECRET_KEY = os.environ['DESECSTACK_API_SECRETKEY']
  15. # SECURITY WARNING: don't run with debug turned on in production!
  16. DEBUG = False
  17. if os.environ.get('DESECSTACK_API_DEBUG', "").upper() == "TRUE":
  18. DEBUG = True
  19. ALLOWED_HOSTS = [
  20. 'desec.%s' % os.environ['DESECSTACK_DOMAIN'],
  21. 'update.dedyn.%s' % os.environ['DESECSTACK_DOMAIN'],
  22. 'update6.dedyn.%s' % os.environ['DESECSTACK_DOMAIN'],
  23. ]
  24. # Application definition
  25. INSTALLED_APPS = (
  26. 'django.contrib.admin',
  27. 'django.contrib.auth',
  28. 'django.contrib.contenttypes',
  29. 'django.contrib.sessions',
  30. 'django.contrib.messages',
  31. 'django.contrib.staticfiles',
  32. 'rest_framework',
  33. 'rest_framework.authtoken',
  34. 'djoser',
  35. 'desecapi',
  36. )
  37. MIDDLEWARE_CLASSES = (
  38. 'django.contrib.sessions.middleware.SessionMiddleware',
  39. 'django.middleware.common.CommonMiddleware',
  40. 'django.middleware.csrf.CsrfViewMiddleware',
  41. 'django.contrib.auth.middleware.AuthenticationMiddleware',
  42. 'django.contrib.auth.middleware.SessionAuthenticationMiddleware',
  43. 'django.contrib.messages.middleware.MessageMiddleware',
  44. 'django.middleware.clickjacking.XFrameOptionsMiddleware',
  45. )
  46. ROOT_URLCONF = 'desecapi.urls'
  47. WSGI_APPLICATION = 'desecapi.wsgi.application'
  48. # Database
  49. # https://docs.djangoproject.com/en/1.7/ref/settings/#databases
  50. DATABASES = {
  51. 'default': {
  52. 'ENGINE': 'django.db.backends.mysql',
  53. 'NAME': 'desec',
  54. 'USER': 'desec',
  55. 'PASSWORD': os.environ['DESECSTACK_DBAPI_PASSWORD_desec'],
  56. 'HOST': 'dbapi',
  57. 'CHARSET': 'utf8mb4',
  58. 'TEST': {
  59. 'CHARSET': 'utf8mb4',
  60. },
  61. 'OPTIONS': {
  62. 'init_command': "SET sql_mode='STRICT_TRANS_TABLES'",
  63. }
  64. },
  65. }
  66. # Internationalization
  67. # https://docs.djangoproject.com/en/1.7/topics/i18n/
  68. LANGUAGE_CODE = 'en-us'
  69. TIME_ZONE = 'UTC'
  70. USE_I18N = True
  71. USE_L10N = True
  72. USE_TZ = True
  73. # Static files (CSS, JavaScript, Images)
  74. # https://docs.djangoproject.com/en/1.7/howto/static-files/
  75. STATIC_URL = '/api/static/'
  76. REST_FRAMEWORK = {
  77. 'DEFAULT_AUTHENTICATION_CLASSES': (
  78. 'rest_framework.authentication.TokenAuthentication',
  79. ),
  80. }
  81. # user management configuration
  82. DJOSER = {
  83. 'DOMAIN': 'desec.io',
  84. 'SITE_NAME': 'deSEC',
  85. 'PASSWORD_RESET_CONFIRM_URL': '#/password/reset/confirm/{uid}/{token}',
  86. 'ACTIVATION_URL': '#/activate/{uid}/{token}',
  87. 'LOGIN_AFTER_ACTIVATION': True,
  88. 'SEND_ACTIVATION_EMAIL': False,
  89. 'SERIALIZERS': {
  90. 'user': 'desecapi.serializers.UserSerializer',
  91. 'user_registration': 'desecapi.serializers.UserRegistrationSerializer',
  92. },
  93. }
  94. TEMPLATES = [
  95. {
  96. 'BACKEND': 'django.template.backends.django.DjangoTemplates',
  97. 'DIRS': [],
  98. 'APP_DIRS': True,
  99. 'OPTIONS': {
  100. 'context_processors': [
  101. 'django.template.context_processors.debug',
  102. 'django.template.context_processors.request',
  103. 'django.contrib.auth.context_processors.auth',
  104. 'django.contrib.messages.context_processors.messages',
  105. ],
  106. },
  107. },
  108. ]
  109. # How and where to send mail
  110. EMAIL_HOST = os.environ['DESECSTACK_API_EMAIL_HOST']
  111. EMAIL_HOST_USER = os.environ['DESECSTACK_API_EMAIL_HOST_USER']
  112. EMAIL_HOST_PASSWORD = os.environ['DESECSTACK_API_EMAIL_HOST_PASSWORD']
  113. EMAIL_PORT = os.environ['DESECSTACK_API_EMAIL_PORT']
  114. DEFAULT_FROM_EMAIL = 'deSEC <support@desec.io>'
  115. ADMINS = [(address.split("@")[0], address) for address in os.environ['DESECSTACK_API_ADMIN'].split()]
  116. # use our own user model
  117. AUTH_USER_MODEL = 'desecapi.User'
  118. # PowerDNS API access
  119. NSLORD_PDNS_API = 'http://nslord:8081/api/v1/servers/localhost'
  120. NSLORD_PDNS_API_TOKEN = os.environ['DESECSTACK_NSLORD_APIKEY']
  121. NSMASTER_PDNS_API = 'http://nsmaster:8081/api/v1/servers/localhost'
  122. NSMASTER_PDNS_API_TOKEN = os.environ['DESECSTACK_NSMASTER_APIKEY']
  123. # SEPA direct debit settings
  124. SEPA = {
  125. 'CREDITOR_ID': os.environ['DESECSTACK_API_SEPA_CREDITOR_ID'],
  126. }
  127. # recaptcha
  128. NORECAPTCHA_SITE_KEY = os.environ['DESECSTACK_NORECAPTCHA_SITE_KEY']
  129. NORECAPTCHA_SECRET_KEY = os.environ['DESECSTACK_NORECAPTCHA_SECRET_KEY']
  130. NORECAPTCHA_WIDGET_TEMPLATE = 'captcha-widget.html'
  131. # abuse protection
  132. ABUSE_BY_REMOTE_IP_LIMIT = 1
  133. ABUSE_BY_REMOTE_IP_PERIOD_HRS = 48
  134. ABUSE_BY_EMAIL_HOSTNAME_LIMIT = 1
  135. ABUSE_BY_EMAIL_HOSTNAME_PERIOD_HRS = 24
  136. LIMIT_USER_DOMAIN_COUNT_DEFAULT = 5