diff --git a/CHANGELOG b/CHANGELOG index dd6aa44ca7dac81bdc27362452cc42c4ff3a7893..fdaa931b5527a6de7fd1c526a5a5cc71d1e13fb9 100644 --- a/CHANGELOG +++ b/CHANGELOG @@ -5,11 +5,17 @@ Changelog 0.2.5 (unreleased) ------------------ +Features: + - Import: can now specify search template when querying import sources (#45) -- Player: better handling of errors when fetching the audio file (#46) - Login form: now redirect to previous page after login (#2) - 404: a decent 404 template, at least (#48) +Bugfixes: + +- Player: better handling of errors when fetching the audio file (#46) +- Csrf: default CSRF_TRUSTED_ORIGINS to ALLOWED_HOSTS to avoid Csrf issues on admin (#49) + 0.2.4 (2017-12-14) ------------------ diff --git a/api/config/settings/production.py b/api/config/settings/production.py index a132076c72ae90c2d71f2480b9346a34f8873c2a..ba02b5fd5cd4e2009c1b7149e872400867942e25 100644 --- a/api/config/settings/production.py +++ b/api/config/settings/production.py @@ -55,6 +55,8 @@ SECURE_PROXY_SSL_HEADER = ('HTTP_X_FORWARDED_PROTO', 'https') # Hosts/domain names that are valid for this site # See https://docs.djangoproject.com/en/1.6/ref/settings/#allowed-hosts ALLOWED_HOSTS = env.list('DJANGO_ALLOWED_HOSTS') +CSRF_TRUSTED_ORIGINS = ALLOWED_HOSTS + # END SITE CONFIGURATION INSTALLED_APPS += ("gunicorn", )