B
    ©0H[W  ã               @   sÞ  d dl mZ ddlmZmZmZ dZdZeddd�Zed	d
d�Z	eddd�Z
eddd�Zeddd�Zeddd�Zeddd�Zedeedœ dd�Zeddd�Zeddd�Zeddd�Zeddd�Zd d!„ Zd"d#„ Zeejd$d%�d&d'„ ƒZeejd$d%�d(d)„ ƒZeejd$d%�d*d+„ ƒZeejd$d%�d,d-„ ƒZeejd$d%�d.d/„ ƒZeejd$d%�d0d1„ ƒZeejd$d%�d2d3„ ƒZeejd$d%�d4d5„ ƒZeejd$d%�d6d7„ ƒZeejd$d%�d8d9„ ƒZ eejd$d%�d:d;„ ƒZ!eejd$d%�d<d=„ ƒZ"d>S )?é    )Úsettingsé   )ÚTagsÚWarningÚregisteré2   é   zÜYou do not have 'django.middleware.security.SecurityMiddleware' in your MIDDLEWARE so the SECURE_HSTS_SECONDS, SECURE_CONTENT_TYPE_NOSNIFF, SECURE_BROWSER_XSS_FILTER, and SECURE_SSL_REDIRECT settings will have no effect.zsecurity.W001)Úida3  You do not have 'django.middleware.clickjacking.XFrameOptionsMiddleware' in your MIDDLEWARE, so your pages will not be served with an 'x-frame-options' header. Unless there is a good reason for your site to be served in a frame, you should consider enabling this header to help prevent clickjacking attacks.zsecurity.W002a,  You have not set a value for the SECURE_HSTS_SECONDS setting. If your entire site is served only over SSL, you may want to consider setting a value and enabling HTTP Strict Transport Security. Be sure to read the documentation first; enabling HSTS carelessly can cause serious, irreversible problems.zsecurity.W004a  You have not set the SECURE_HSTS_INCLUDE_SUBDOMAINS setting to True. Without this, your site is potentially vulnerable to attack via an insecure connection to a subdomain. Only set this to True if you are certain that all subdomains of your domain should be served exclusively via SSL.zsecurity.W005zûYour SECURE_CONTENT_TYPE_NOSNIFF setting is not set to True, so your pages will not be served with an 'x-content-type-options: nosniff' header. You should consider enabling this header to prevent the browser from identifying content types incorrectly.zsecurity.W006züYour SECURE_BROWSER_XSS_FILTER setting is not set to True, so your pages will not be served with an 'x-xss-protection: 1; mode=block' header. You should consider enabling this header to activate the browser's XSS filtering and help prevent XSS attacks.zsecurity.W007a  Your SECURE_SSL_REDIRECT setting is not set to True. Unless your site should be available over both SSL and non-SSL connections, you may want to either set this setting True or configure a load balancer or reverse-proxy server to redirect all connections to HTTPS.zsecurity.W008zîYour SECRET_KEY has less than %(min_length)s characters or less than %(min_unique_chars)s unique characters. Please generate a long and random SECRET_KEY, otherwise many of Django's security-critical features will be vulnerable to attack.)Z
min_lengthZmin_unique_charszsecurity.W009z4You should not have DEBUG set to True in deployment.zsecurity.W018a  You have 'django.middleware.clickjacking.XFrameOptionsMiddleware' in your MIDDLEWARE, but X_FRAME_OPTIONS is not set to 'DENY'. The default is 'SAMEORIGIN', but unless there is a good reason for your site to serve other parts of itself in a frame, you should change it to 'DENY'.zsecurity.W019z.ALLOWED_HOSTS must not be empty in deployment.zsecurity.W020z‚You have not set the SECURE_HSTS_PRELOAD setting to True. Without this, your site cannot be submitted to the browser preload list.zsecurity.W021c               C   s
   dt jkS )Nz-django.middleware.security.SecurityMiddleware)r   Ú
MIDDLEWARE© r   r   údC:\Users\HIRONO~1\AppData\Local\Temp\pip-install-6bm3nxem\django\django\core\checks\security\base.pyÚ_security_middlewaren   s    r   c               C   s
   dt jkS )Nz6django.middleware.clickjacking.XFrameOptionsMiddleware)r   r
   r   r   r   r   Ú_xframe_middlewarer   s    r   T)Zdeployc             K   s   t ƒ }|rg S tgS )N)r   ÚW001)Úapp_configsÚkwargsÚpassed_checkr   r   r   Úcheck_security_middlewarev   s    r   c             K   s   t ƒ }|rg S tgS )N)r   ÚW002)r   r   r   r   r   r   Úcheck_xframe_options_middleware|   s    r   c             K   s   t ƒ  ptj}|rg S tgS )N)r   r   ÚSECURE_HSTS_SECONDSÚW004)r   r   r   r   r   r   Ú	check_sts‚   s    r   c             K   s(   t ƒ  ptj ptjdk}|r"g S tgS )NT)r   r   r   ZSECURE_HSTS_INCLUDE_SUBDOMAINSÚW005)r   r   r   r   r   r   Úcheck_sts_include_subdomainsˆ   s    
r   c             K   s(   t ƒ  ptj ptjdk}|r"g S tgS )NT)r   r   r   ZSECURE_HSTS_PRELOADÚW021)r   r   r   r   r   r   Úcheck_sts_preload’   s    
r   c             K   s    t ƒ  ptjdk}|rg S tgS )NT)r   r   ZSECURE_CONTENT_TYPE_NOSNIFFÚW006)r   r   r   r   r   r   Úcheck_content_type_nosniffœ   s    
r   c             K   s    t ƒ  ptjdk}|rg S tgS )NT)r   r   ZSECURE_BROWSER_XSS_FILTERÚW007)r   r   r   r   r   r   Úcheck_xss_filter¥   s    
r    c             K   s    t ƒ  ptjdk}|rg S tgS )NT)r   r   ZSECURE_SSL_REDIRECTÚW008)r   r   r   r   r   r   Úcheck_ssl_redirect®   s    
r"   c             K   s:   t tdd ƒo*tttjƒƒtko*ttjƒtk}|r4g S tgS )NÚ
SECRET_KEY)Úgetattrr   ÚlenÚsetr#   Ú SECRET_KEY_MIN_UNIQUE_CHARACTERSÚSECRET_KEY_MIN_LENGTHÚW009)r   r   r   r   r   r   Úcheck_secret_key·   s    r*   c             K   s   t j }|rg S tgS )N)r   ÚDEBUGÚW018)r   r   r   r   r   r   Úcheck_debugÁ   s    r-   c             K   s    t ƒ  ptjdk}|rg S tgS )NZDENY)r   r   ZX_FRAME_OPTIONSÚW019)r   r   r   r   r   r   Úcheck_xframe_denyÇ   s    
r/   c             K   s   t jr
g S tgS )N)r   ZALLOWED_HOSTSÚW020)r   r   r   r   r   Úcheck_allowed_hostsÐ   s    r1   N)#Zdjango.confr   Ú r   r   r   r(   r'   r   r   r   r   r   r   r!   r)   r,   r.   r0   r   r   r   Úsecurityr   r   r   r   r   r   r    r"   r*   r-   r/   r1   r   r   r   r   Ú<module>   sn   

			
	