LAN admin on 10.0.0.128 plus quick campaign mint form (#12)
Closes #11. ## Summary - Serve Django admin on LAN IP `10.0.0.128` (not `piha.li`). Compose now publishes `0.0.0.0:8005` and passes `SHORT_ADMIN_HOSTS` into the container. - Admin index has a campaign mint form: domain, campaign, source, metric. Save builds `https://{domain}/?utm_campaign=&utm_source=&utm_medium=` (metric) and shows a copyable short URL. - Public `/admin/` on `piha.lc` / `piha.li` stays 404. ## Test plan - [ ] `cd site && uv run python manage.py test` - [ ] Recreate compose (`docker compose up --build`) so `WEB_BIND` / `SHORT_ADMIN_HOSTS` take effect - [ ] From another LAN machine: `http://10.0.0.128:8005/admin/` (staff login) shows the mint form - [ ] Save a link for an allowlisted domain, copy the short URL, confirm it 302s - [ ] `https://piha.li/admin` still 404 Reviewed-on: #12
This commit was merged in pull request #12.
This commit is contained in:
+5
-3
@@ -4,7 +4,7 @@
|
||||
DJANGO_ENV=dev
|
||||
DJANGO_DEBUG=true
|
||||
DJANGO_SECRET_KEY=dev-only-change-me
|
||||
DJANGO_ALLOWED_HOSTS=localhost,127.0.0.1,0.0.0.0,web,url-shortener
|
||||
DJANGO_ALLOWED_HOSTS=localhost,127.0.0.1,0.0.0.0,web,url-shortener,10.0.0.128
|
||||
|
||||
# Leave empty for SQLite when running manage.py on the host.
|
||||
# Compose ignores this and uses the bundled Postgres via COMPOSE_DATABASE_URL.
|
||||
@@ -22,8 +22,10 @@ PUBLIC_SHORT_URL=http://127.0.0.1:8005
|
||||
SHORT_PUBLIC_HOSTS=piha.lc
|
||||
# Extra Host values that also serve /api/ (localhost / docker).
|
||||
SHORT_API_HOSTS=localhost,127.0.0.1,0.0.0.0,web,url-shortener
|
||||
# Django admin — keep local. Do not add the public short hostname.
|
||||
SHORT_ADMIN_HOSTS=localhost,127.0.0.1
|
||||
# Django admin — keep off the public short hostname. LAN IP is for local compose.
|
||||
SHORT_ADMIN_HOSTS=localhost,127.0.0.1,10.0.0.128
|
||||
# Compose publish address. 0.0.0.0 so another machine can hit 10.0.0.128:8005.
|
||||
WEB_BIND=0.0.0.0
|
||||
# Named, rotatable tokens. This is what keeps /api/ closed on a public hostname.
|
||||
# Generate: python -c "import secrets; print(secrets.token_urlsafe(32))"
|
||||
# Format: name:secret,name:secret — never reuse DJANGO_SECRET_KEY.
|
||||
|
||||
Reference in New Issue
Block a user