From 5367470daa3f76b06c9aa138c6e36ef0af4f69ad Mon Sep 17 00:00:00 2001 From: Tanner Collin Date: Thu, 7 May 2020 04:12:48 +0000 Subject: [PATCH] Set same-origin referrer policy --- apiserver/apiserver/settings.py | 1 + 1 file changed, 1 insertion(+) diff --git a/apiserver/apiserver/settings.py b/apiserver/apiserver/settings.py index 2d5b6cf..4169aa8 100644 --- a/apiserver/apiserver/settings.py +++ b/apiserver/apiserver/settings.py @@ -53,6 +53,7 @@ if DEBUG: SECURE_PROXY_SSL_HEADER = ('HTTP_X_FORWARDED_PROTO', 'https') SESSION_COOKIE_SECURE = True CSRF_COOKIE_SECURE = True +SECURE_REFERRER_POLICY = 'same-origin' # Application definition