a
    Lcòf´#  ã                   @   s�  d dl mZ d dlmZ ddlmZmZmZmZ h d£Z	h d£Z
dZdZd	Zd
e› de› de› d�Zeddd�Zeddd�Zeddd�Zeddd�Zeddd�Zeddd�Zeed dd�Zeddd�Zedd d�Zed!d"d�Zed#d$d�Zed%d&d�Zed'd( d) ee
ƒ¡¡d*d+�Zed,d( d) ee	ƒ¡¡d-d+�Zeed.d�Z d/d0„ Z!d1d2„ Z"eej#d3d4�d5d6„ ƒZ$eej#d3d4�d7d8„ ƒZ%eej#d3d4�d9d:„ ƒZ&eej#d3d4�d;d<„ ƒZ'eej#d3d4�d=d>„ ƒZ(eej#d3d4�d?d@„ ƒZ)eej#d3d4�dAdB„ ƒZ*dCdD„ Z+eej#d3d4�dEdF„ ƒZ,eej#d3d4�dGdH„ ƒZ-eej#d3d4�dIdJ„ ƒZ.eej#d3d4�dKdL„ ƒZ/eej#d3d4�dMdN„ ƒZ0eej#d3d4�dOdP„ ƒZ1eej#d3d4�dQdR„ ƒZ2dSS )Té    )Úsettings)ÚImproperlyConfiguredé   )ÚErrorÚTagsÚWarningÚregister>   úsame-originzunsafe-nonezsame-origin-allow-popups>   zorigin-when-cross-originz
unsafe-urlÚoriginzstrict-originzno-referrer-when-downgradezstrict-origin-when-cross-originzno-referrerr	   zdjango-insecure-é2   é   zYour %s has less than z characters, less than z+ unique characters, or it's prefixed with 'z¸' indicating that it was generated automatically by Django. Please generate a long and random value, otherwise many of Django's security-critical features will be vulnerable to attack.züYou do not have 'django.middleware.security.SecurityMiddleware' in your MIDDLEWARE so the SECURE_HSTS_SECONDS, SECURE_CONTENT_TYPE_NOSNIFF, SECURE_REFERRER_POLICY, SECURE_CROSS_ORIGIN_OPENER_POLICY, and SECURE_SSL_REDIRECT settings will have no effect.zsecurity.W001©Úida3  You do not have 'django.middleware.clickjacking.XFrameOptionsMiddleware' in your MIDDLEWARE, so your pages will not be served with an 'x-frame-options' header. Unless there is a good reason for your site to be served in a frame, you should consider enabling this header to help prevent clickjacking attacks.zsecurity.W002a,  You have not set a value for the SECURE_HSTS_SECONDS setting. If your entire site is served only over SSL, you may want to consider setting a value and enabling HTTP Strict Transport Security. Be sure to read the documentation first; enabling HSTS carelessly can cause serious, irreversible problems.zsecurity.W004a  You have not set the SECURE_HSTS_INCLUDE_SUBDOMAINS setting to True. Without this, your site is potentially vulnerable to attack via an insecure connection to a subdomain. Only set this to True if you are certain that all subdomains of your domain should be served exclusively via SSL.zsecurity.W005zûYour SECURE_CONTENT_TYPE_NOSNIFF setting is not set to True, so your pages will not be served with an 'X-Content-Type-Options: nosniff' header. You should consider enabling this header to prevent the browser from identifying content types incorrectly.zsecurity.W006a  Your SECURE_SSL_REDIRECT setting is not set to True. Unless your site should be available over both SSL and non-SSL connections, you may want to either set this setting True or configure a load balancer or reverse-proxy server to redirect all connections to HTTPS.zsecurity.W008Ú
SECRET_KEYzsecurity.W009z4You should not have DEBUG set to True in deployment.zsecurity.W018zöYou have 'django.middleware.clickjacking.XFrameOptionsMiddleware' in your MIDDLEWARE, but X_FRAME_OPTIONS is not set to 'DENY'. Unless there is a good reason for your site to serve other parts of itself in a frame, you should change it to 'DENY'.zsecurity.W019z.ALLOWED_HOSTS must not be empty in deployment.zsecurity.W020z‚You have not set the SECURE_HSTS_PRELOAD setting to True. Without this, your site cannot be submitted to the browser preload list.zsecurity.W021z¶You have not set the SECURE_REFERRER_POLICY setting. Without this, your site will not send a Referrer-Policy header. You should consider enabling this header to protect user privacy.zsecurity.W022zDYou have set the SECURE_REFERRER_POLICY setting to an invalid value.zValid values are: {}.z, zsecurity.E023)Úhintr   zOYou have set the SECURE_CROSS_ORIGIN_OPENER_POLICY setting to an invalid value.zsecurity.E024zsecurity.W025c                   C   s
   dt jv S )Nz-django.middleware.security.SecurityMiddleware©r   Z
MIDDLEWARE© r   r   ú]/home/httpd/docs/test/DocsMgr/lib/python3.9/site-packages/django/core/checks/security/base.pyÚ_security_middleware‘   s    r   c                   C   s
   dt jv S )Nz6django.middleware.clickjacking.XFrameOptionsMiddlewarer   r   r   r   r   Ú_xframe_middleware•   s    ÿr   T)Zdeployc                 K   s   t ƒ }|rg S tgS ©N)r   ÚW001©Úapp_configsÚkwargsÚpassed_checkr   r   r   Úcheck_security_middleware›   s    r   c                 K   s   t ƒ }|rg S tgS r   )r   ÚW002r   r   r   r   Úcheck_xframe_options_middleware¡   s    r   c                 K   s   t ƒ  ptj}|rg S tgS r   )r   r   ÚSECURE_HSTS_SECONDSÚW004r   r   r   r   Ú	check_sts§   s    r!   c                 K   s(   t ƒ  ptj ptjdu }|r"g S tgS ©NT)r   r   r   ZSECURE_HSTS_INCLUDE_SUBDOMAINSÚW005r   r   r   r   Úcheck_sts_include_subdomains­   s    ÿýr$   c                 K   s(   t ƒ  ptj ptjdu }|r"g S tgS r"   )r   r   r   ZSECURE_HSTS_PRELOADÚW021r   r   r   r   Úcheck_sts_preload·   s    ÿýr&   c                 K   s    t ƒ  ptjdu }|rg S tgS r"   )r   r   ZSECURE_CONTENT_TYPE_NOSNIFFÚW006r   r   r   r   Úcheck_content_type_nosniffÁ   s    ÿr(   c                 K   s    t ƒ  ptjdu }|rg S tgS r"   )r   r   ZSECURE_SSL_REDIRECTÚW008r   r   r   r   Úcheck_ssl_redirectÉ   s    r*   c                 C   s(   t t| ƒƒtko&t | ƒtko&|  t¡ S r   )ÚlenÚsetÚ SECRET_KEY_MIN_UNIQUE_CHARACTERSÚSECRET_KEY_MIN_LENGTHÚ
startswithÚSECRET_KEY_INSECURE_PREFIX)Ú
secret_keyr   r   r   Ú_check_secret_keyÏ   s
    
ÿ
ýr2   c              	   K   s<   z
t j}W n ttfy$   d}Y n
0 t|ƒ}|r6g S tgS )NF)r   r   r   ÚAttributeErrorr2   ÚW009)r   r   r1   r   r   r   r   Úcheck_secret_key×   s    

r5   c              	   K   s€   g }z
t j}W n0 ttfy>   | ttjd tjd�¡ Y n>0 t	|ƒD ]2\}}t
|ƒsH| ttjd|› d� tjd�¡ qH|S )NÚSECRET_KEY_FALLBACKSr   zSECRET_KEY_FALLBACKS[ú])r   r6   r   r3   Úappendr   ÚW025Úmsgr   Ú	enumerater2   )r   r   ÚwarningsZ	fallbacksÚindexÚkeyr   r   r   Úcheck_secret_key_fallbacksâ   s    
 ÿr?   c                 K   s   t j }|rg S tgS r   )r   ÚDEBUGÚW018r   r   r   r   Úcheck_debugò   s    rB   c                 K   s    t ƒ  ptjdk}|rg S tgS )NZDENY)r   r   ZX_FRAME_OPTIONSÚW019r   r   r   r   Úcheck_xframe_denyø   s    rD   c                 K   s   t jr
g S tgS r   )r   ZALLOWED_HOSTSÚW020©r   r   r   r   r   Úcheck_allowed_hostsþ   s    rG   c                 K   sV   t ƒ rRtjd u rtgS ttjtƒr:dd„ tj d¡D ƒ}n
ttjƒ}|tksRt	gS g S )Nc                 S   s   h | ]}|  ¡ ’qS r   )Ústrip)Ú.0Úvr   r   r   Ú	<setcomp>
  ó    z(check_referrer_policy.<locals>.<setcomp>ú,)
r   r   ZSECURE_REFERRER_POLICYÚW022Ú
isinstanceÚstrÚsplitr,   ÚREFERRER_POLICY_VALUESÚE023)r   r   Úvaluesr   r   r   Úcheck_referrer_policy  s    

rU   c                 K   s$   t ƒ r tjd ur tjtvr tgS g S r   )r   r   Z!SECURE_CROSS_ORIGIN_OPENER_POLICYÚ!CROSS_ORIGIN_OPENER_POLICY_VALUESÚE024rF   r   r   r   Ú check_cross_origin_opener_policy  s    ÿþÿýrX   N)3Zdjango.confr   Zdjango.core.exceptionsr   Ú r   r   r   r   rV   rR   r0   r.   r-   ZSECRET_KEY_WARNING_MSGr   r   r    r#   r'   r)   r4   rA   rC   rE   r%   rN   ÚformatÚjoinÚsortedrS   rW   r9   r   r   Úsecurityr   r   r!   r$   r&   r(   r*   r2   r5   r?   rB   rD   rG   rU   rX   r   r   r   r   Ú<module>   sÒ   ÿþÿ	ú	ù
ú	ú	ú	ú	þþú	þýüýÿú	



	
	








