diff --git a/backend/.env.example b/backend/.env.example index 73597ec..419bc9a 100644 --- a/backend/.env.example +++ b/backend/.env.example @@ -1,6 +1,6 @@ DEBUG=True SECRET_KEY=change-me-in-production -ALLOWED_HOSTS=localhost,127.0.0.1,api +ALLOWED_HOSTS=localhost,127.0.0.1,api,dashboard.local CSRF_TRUSTED_ORIGINS=http://localhost:8000,http://127.0.0.1:8000,http://localhost:3001,http://127.0.0.1:3001 CORS_ALLOWED_ORIGINS=http://localhost:3000,http://127.0.0.1:3000,http://localhost:3001,http://127.0.0.1:3001 CORS_ALLOW_CREDENTIALS=True diff --git a/backend/config/settings.py b/backend/config/settings.py index e0985ab..7cccc22 100644 --- a/backend/config/settings.py +++ b/backend/config/settings.py @@ -38,10 +38,10 @@ def env_json_dict(key: str, default: str = "") -> dict[str, int]: SECRET_KEY = env("SECRET_KEY", "insecure-dev-key") DEBUG = env_bool("DEBUG", True) -ALLOWED_HOSTS = env_list("ALLOWED_HOSTS", "localhost,127.0.0.1") +ALLOWED_HOSTS = env_list("ALLOWED_HOSTS", "localhost,127.0.0.1,dashboard.local") CSRF_TRUSTED_ORIGINS = env_list( "CSRF_TRUSTED_ORIGINS", - "http://localhost:3001,http://127.0.0.1:3001,http://localhost,http://127.0.0.1", + "http://localhost:3001,http://127.0.0.1:3001,http://localhost,http://127.0.0.1,http://dashboard.local", ) if DEBUG: # Dev/LAN: allow Vite (:3001) and Docker UI (:80) from private networks. @@ -140,7 +140,7 @@ DEFAULT_AUTO_FIELD = "django.db.models.BigAutoField" CORS_ALLOWED_ORIGINS = env_list( "CORS_ALLOWED_ORIGINS", - "http://localhost:3001,http://127.0.0.1:3001,http://localhost,http://127.0.0.1", + "http://localhost:3001,http://127.0.0.1:3001,http://localhost,http://127.0.0.1,http://dashboard.local", ) CORS_ALLOW_CREDENTIALS = env_bool("CORS_ALLOW_CREDENTIALS", True) diff --git a/docker-compose.yml b/docker-compose.yml index 4773535..ae148f5 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -41,9 +41,9 @@ services: environment: DEBUG: ${DEBUG:-false} SECRET_KEY: ${SECRET_KEY:-test-secret-key} - ALLOWED_HOSTS: ${ALLOWED_HOSTS:-localhost,127.0.0.1,api,frontend,192.168.192.106} - CSRF_TRUSTED_ORIGINS: ${CSRF_TRUSTED_ORIGINS:-http://localhost,http://127.0.0.1,http://192.168.192.106} - CORS_ALLOWED_ORIGINS: ${CORS_ALLOWED_ORIGINS:-http://localhost,http://127.0.0.1,http://192.168.192.106} + ALLOWED_HOSTS: ${ALLOWED_HOSTS:-localhost,127.0.0.1,api,frontend,192.168.192.106,dashboard.local} + CSRF_TRUSTED_ORIGINS: ${CSRF_TRUSTED_ORIGINS:-http://localhost,http://127.0.0.1,http://192.168.192.106,http://dashboard.local} + CORS_ALLOWED_ORIGINS: ${CORS_ALLOWED_ORIGINS:-http://localhost,http://127.0.0.1,http://192.168.192.106,http://dashboard.local} CORS_ALLOW_CREDENTIALS: "true" DB_ENGINE: django.db.backends.postgresql DB_NAME: ${DB_NAME:-dashboard} @@ -99,7 +99,7 @@ services: environment: DEBUG: ${DEBUG:-false} SECRET_KEY: ${SECRET_KEY:-test-secret-key} - ALLOWED_HOSTS: ${ALLOWED_HOSTS:-localhost,127.0.0.1,api,frontend} + ALLOWED_HOSTS: ${ALLOWED_HOSTS:-localhost,127.0.0.1,api,frontend,dashboard.local} DB_ENGINE: django.db.backends.postgresql DB_NAME: ${DB_NAME:-dashboard} DB_USER: ${DB_USER:-dashboard} diff --git a/docker/.env.example b/docker/.env.example index 9dab40b..cb3597f 100644 --- a/docker/.env.example +++ b/docker/.env.example @@ -9,9 +9,9 @@ DB_NAME=newdashboard # --- Django --- SECRET_KEY=change-me-in-production-use-a-long-random-string DEBUG=false -ALLOWED_HOSTS=localhost,127.0.0.1,api,frontend -CSRF_TRUSTED_ORIGINS=http://localhost,http://127.0.0.1 -CORS_ALLOWED_ORIGINS=http://localhost,http://127.0.0.1 +ALLOWED_HOSTS=localhost,127.0.0.1,api,frontend,dashboard.local +CSRF_TRUSTED_ORIGINS=http://localhost,http://127.0.0.1,http://dashboard.local +CORS_ALLOWED_ORIGINS=http://localhost,http://127.0.0.1,http://dashboard.local # Production admin (bootstrap_admin — no demo data) BOOTSTRAP_ADMIN_USER=admin