Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
I've been fighting with CORS and CSRF (amongst other things) while trying to get an API call with ajax to work. As such, I found that
CORS_ORIGIN_ALLOW_ALL
was fixed asTrue
. I feel that it should be configurable by the user, so I added anos.getenv
call for it with a default toTrue
for no breaking changes. I also updated it per https://github.com/adamchainz/django-cors-headers toCORS_ALLOW_ALL_ORIGINS
.I added that and
CSRF_TRUSTED_ORIGINS
to the template .env file for better discoverability, though they're both commented out.I didn't do a discussion on this first, but I can start one if that would be preferred.