westfarn 139f375f73
Unit Tests / test (push) Successful in 11s
Fix logout 403 CSRF verification failed (#18) (#19)
## Summary
- Closes #18
- Logout POST was failing CSRF Origin checks on HTTPS because `CSRF_TRUSTED_ORIGINS` was unset (Django 5)
- Derive trusted origins from `DJANGO_ALLOWED_HOSTS` (override via `DJANGO_CSRF_TRUSTED_ORIGINS`)
- Trust reverse-proxy TLS headers in prod/beta (`SECURE_PROXY_SSL_HEADER`, secure cookies)

## Test plan
- [x] `python manage.py test public.tests.CsrfTrustedOriginsTests public.tests.LogoutCsrfTests`
- [ ] Deploy, log in on aimloperations.com, click Log Out → redirect home, no 403
- [ ] Confirm login still works after deploy

Reviewed-on: #19
2026-07-10 17:39:29 -07:00
2026-03-20 13:07:28 -05:00
2026-06-27 12:19:54 -05:00
2025-03-24 13:06:45 -05:00
2026-07-08 06:12:21 -05:00

company_site

Django site for AIML Operations.

Local development (uv)

uv sync
cp .env.example .env
cd company_site
DJANGO_ENV=dev uv run python manage.py migrate
DJANGO_ENV=dev uv run python manage.py runserver

Docker (dev + Postgres)

cp .env.example .env
docker compose up --build

App: http://localhost:8000

Environments

Set DJANGO_ENV to one of:

Value DEBUG default Logging level
dev true DEBUG
beta false INFO
prod false WARNING

Secrets and service config come from environment variables. See .env.example.

CI / deploy workflows

Workflow Trigger What runs
.gitea/workflows/ci.yml Pull requests to master Unit tests only
.gitea/workflows/deploy.yml Push to master Unit tests → Docker build/test → deploy

Deploy never runs on pull requests. Uses separate workflow files (not job if conditions) so Gitea runners handle it reliably.

Production deploy

Server keeps its own .env at the live site path. Deploy rsyncs code but never overwrites .env.

  1. On the server, copy .env.prod.example to .env and fill in production values.
  2. Run bash scripts/validate-env.sh /path/to/.env to verify required variables.
  3. Push to master — the deploy workflow runs scripts/deploy.sh, which:
    • rsyncs checkout to live site (preserving .env)
    • validates environment variables
    • docker compose -f docker-compose.prod.yml build
    • docker compose up -d
    • runs migrations in the web container

Legacy venv/systemd deploy: DEPLOY_MODE=legacy bash scripts/deploy.sh <checkout>.

S
Description
Django site for company
Readme
47 MiB
Languages
CSS 42.7%
JavaScript 24.3%
HTML 16.7%
Python 16%
Shell 0.3%