diff --git a/config/settings/production.py b/config/settings/production.py index 632c9d6..15f90b0 100644 --- a/config/settings/production.py +++ b/config/settings/production.py @@ -23,6 +23,13 @@ SECRET_KEY = env("DJANGO_SECRET_KEY") # properly on Heroku. SECURE_PROXY_SSL_HEADER = ('HTTP_X_FORWARDED_PROTO', 'https') +# django-secure +# ------------------------------------------------------------------------------ +INSTALLED_APPS += ("djangosecure", ) + +SECURITY_MIDDLEWARE = ( + 'djangosecure.middleware.SecurityMiddleware', +) # Make sure djangosecure.middleware.SecurityMiddleware is listed first MIDDLEWARE_CLASSES = SECURITY_MIDDLEWARE + MIDDLEWARE_CLASSES