settings.py 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467
  1. """
  2. Django settings for glitchtip project.
  3. Generated by 'django-admin startproject' using Django 3.0rc1.
  4. For more information on this file, see
  5. https://docs.djangoproject.com/en/dev/topics/settings/
  6. For the full list of settings and their values, see
  7. https://docs.djangoproject.com/en/dev/ref/settings/
  8. """
  9. import os
  10. import sys
  11. import warnings
  12. import environ
  13. import sentry_sdk
  14. from django.core.exceptions import ImproperlyConfigured
  15. from sentry_sdk.integrations.django import DjangoIntegration
  16. from celery.schedules import crontab
  17. env = environ.Env(
  18. ALLOWED_HOSTS=(list, ["*"]),
  19. AWS_ACCESS_KEY_ID=(str, None),
  20. AWS_SECRET_ACCESS_KEY=(str, None),
  21. AWS_STORAGE_BUCKET_NAME=(str, None),
  22. AWS_S3_ENDPOINT_URL=(str, None),
  23. AWS_LOCATION=(str, None),
  24. DEBUG=(bool, False),
  25. DEBUG_TOOLBAR=(bool, False),
  26. STATIC_URL=(str, "/"),
  27. STATICFILES_STORAGE=(
  28. str,
  29. "whitenoise.storage.CompressedManifestStaticFilesStorage",
  30. ),
  31. )
  32. path = environ.Path()
  33. # Build paths inside the project like this: os.path.join(BASE_DIR, ...)
  34. BASE_DIR = os.path.dirname(os.path.dirname(os.path.abspath(__file__)))
  35. # Quick-start development settings - unsuitable for production
  36. # See https://docs.djangoproject.com/en/dev/howto/deployment/checklist/
  37. # SECURITY WARNING: keep the secret key used in production secret!
  38. SECRET_KEY = env("SECRET_KEY")
  39. # SECURITY WARNING: don't run with debug turned on in production!
  40. DEBUG = env("DEBUG")
  41. # Enable only for running end to end testing. Debug must be True to use.
  42. ENABLE_TEST_API = env.bool("ENABLE_TEST_API", False)
  43. if DEBUG is False:
  44. ENABLE_TEST_API = False
  45. ALLOWED_HOSTS = env("ALLOWED_HOSTS")
  46. # Necessary for kubernetes health checks
  47. POD_IP = env.str("POD_IP", default=None)
  48. if POD_IP:
  49. ALLOWED_HOSTS.append(POD_IP)
  50. ENVIRONMENT = env.str("ENVIRONMENT", None)
  51. GLITCHTIP_VERSION = env.str("GLITCHTIP_VERSION", None)
  52. # Used in email and DSN generation. Set to full domain such as https://glitchtip.example.com
  53. default_url = env.str(
  54. "APP_URL", "http://localhost:8000"
  55. ) # DigitalOcean App Platform uses APP_URL
  56. GLITCHTIP_DOMAIN = env.url("GLITCHTIP_DOMAIN", default_url)
  57. if GLITCHTIP_DOMAIN.scheme not in ["http", "https"]:
  58. raise ImproperlyConfigured("GLITCHTIP_DOMAIN must start with http or https")
  59. # Events and associated data older than this will be deleted from the database
  60. GLITCHTIP_MAX_EVENT_LIFE_DAYS = env.int("GLITCHTIP_MAX_EVENT_LIFE_DAYS", default=90)
  61. # For development purposes only, prints out inbound event store json
  62. EVENT_STORE_DEBUG = env.bool("EVENT_STORE_DEBUG", False)
  63. # Throttle % of all transaction events. Not intended for general use. May change without warning.
  64. THROTTLE_TRANSACTION_EVENTS = env.float("THROTTLE_TRANSACTION_EVENTS", None)
  65. # GlitchTip can track GlitchTip's own errors.
  66. # If enabling this, use a different server to avoid infinite loops.
  67. def before_send(event, hint):
  68. """Don't log django.DisallowedHost errors in Sentry."""
  69. if "log_record" in hint:
  70. if hint["log_record"].name == "django.security.DisallowedHost":
  71. return None
  72. return event
  73. SENTRY_DSN = env.str("SENTRY_DSN", None)
  74. # Optionally allow a different DSN for the frontend
  75. SENTRY_FRONTEND_DSN = env.str("SENTRY_FRONTEND_DSN", SENTRY_DSN)
  76. # Set traces_sample_rate to 1.0 to capture 100%. Recommended to keep this value low.
  77. # Disabled by default
  78. SENTRY_TRACES_SAMPLE_RATE = env.float("SENTRY_TRACES_SAMPLE_RATE", None)
  79. if SENTRY_DSN:
  80. release = "glitchtip@" + GLITCHTIP_VERSION if GLITCHTIP_VERSION else None
  81. sentry_sdk.init(
  82. dsn=SENTRY_DSN,
  83. integrations=[DjangoIntegration()],
  84. before_send=before_send,
  85. release=release,
  86. environment=ENVIRONMENT,
  87. auto_session_tracking=False,
  88. traces_sample_rate=SENTRY_TRACES_SAMPLE_RATE,
  89. )
  90. def show_toolbar(request):
  91. return env("DEBUG_TOOLBAR")
  92. DEBUG_TOOLBAR_CONFIG = {"SHOW_TOOLBAR_CALLBACK": show_toolbar}
  93. DEBUG_TOOLBAR_PANELS = [
  94. "debug_toolbar.panels.versions.VersionsPanel",
  95. "debug_toolbar.panels.timer.TimerPanel",
  96. "debug_toolbar.panels.settings.SettingsPanel",
  97. "debug_toolbar.panels.headers.HeadersPanel",
  98. "debug_toolbar.panels.request.RequestPanel",
  99. "debug_toolbar.panels.sql.SQLPanel",
  100. ]
  101. # Application definition
  102. INSTALLED_APPS = [
  103. "django.contrib.admin",
  104. "django.contrib.auth",
  105. "django.contrib.contenttypes",
  106. "django.contrib.sessions",
  107. "django.contrib.messages",
  108. "django.contrib.staticfiles",
  109. "django.contrib.sites",
  110. "django.contrib.postgres",
  111. "allauth",
  112. "allauth.account",
  113. "allauth.socialaccount",
  114. "allauth.socialaccount.providers.gitlab",
  115. "allauth.socialaccount.providers.github",
  116. "allauth.socialaccount.providers.google",
  117. "allauth.socialaccount.providers.microsoft",
  118. "anymail",
  119. "corsheaders",
  120. "django_celery_results",
  121. "django_filters",
  122. "django_extensions",
  123. "debug_toolbar",
  124. "rest_framework",
  125. "drf_yasg",
  126. "dj_rest_auth",
  127. "dj_rest_auth.registration",
  128. "storages",
  129. "glitchtip",
  130. "alerts",
  131. "api_tokens",
  132. "environments",
  133. "organizations_ext",
  134. "events",
  135. "issues",
  136. "users",
  137. "user_reports",
  138. "performance",
  139. "projects",
  140. "teams",
  141. "releases",
  142. ]
  143. MIDDLEWARE = [
  144. "django.middleware.security.SecurityMiddleware",
  145. "django.contrib.sessions.middleware.SessionMiddleware",
  146. "corsheaders.middleware.CorsMiddleware",
  147. "csp.middleware.CSPMiddleware",
  148. "django.middleware.clickjacking.XFrameOptionsMiddleware",
  149. "whitenoise.middleware.WhiteNoiseMiddleware",
  150. "debug_toolbar.middleware.DebugToolbarMiddleware",
  151. "django.middleware.common.CommonMiddleware",
  152. "django.middleware.csrf.CsrfViewMiddleware",
  153. "django.contrib.auth.middleware.AuthenticationMiddleware",
  154. "django.contrib.messages.middleware.MessageMiddleware",
  155. "django.middleware.clickjacking.XFrameOptionsMiddleware",
  156. "sentry.middleware.proxy.DecompressBodyMiddleware",
  157. ]
  158. ROOT_URLCONF = "glitchtip.urls"
  159. TEMPLATES = [
  160. {
  161. "BACKEND": "django.template.backends.django.DjangoTemplates",
  162. "DIRS": [path("dist"), path("templates")],
  163. "APP_DIRS": True,
  164. "OPTIONS": {
  165. "context_processors": [
  166. "django.template.context_processors.debug",
  167. "django.template.context_processors.request",
  168. "django.contrib.auth.context_processors.auth",
  169. "django.contrib.messages.context_processors.messages",
  170. ],
  171. },
  172. },
  173. ]
  174. WSGI_APPLICATION = "glitchtip.wsgi.application"
  175. CORS_ORIGIN_ALLOW_ALL = env.bool("CORS_ORIGIN_ALLOW_ALL", True)
  176. CORS_ORIGIN_WHITELIST = env.tuple("CORS_ORIGIN_WHITELIST", str, default=())
  177. SECURE_BROWSER_XSS_FILTER = True
  178. CSP_DEFAULT_SRC = env.list("CSP_DEFAULT_SRC", str, ["'self'"])
  179. CSP_STYLE_SRC = env.list(
  180. "CSP_STYLE_SRC", str, ["'self'", "'unsafe-inline'", "https://fonts.googleapis.com"]
  181. )
  182. CSP_STYLE_SRC_ELEM = env.list(
  183. "CSP_STYLE_SRC_ELEM",
  184. str,
  185. ["'self'", "'unsafe-inline'", "https://fonts.googleapis.com"],
  186. )
  187. CSP_FONT_SRC = env.list("CSP_FONT_SRC", str, ["'self'", "https://fonts.gstatic.com"])
  188. # Redoc requires blob
  189. CSP_WORKER_SRC = env.list("CSP_WORKER_SRC", str, ["'self'", "blob:"])
  190. # GlitchTip can record it's own errors
  191. CSP_CONNECT_SRC = env.list(
  192. "CSP_CONNECT_SRC", str, ["'self'", "https://app.glitchtip.com"]
  193. )
  194. # Needed for Matomo and Stripe for SaaS use cases. Both are disabled by default.
  195. CSP_SCRIPT_SRC = env.list(
  196. "CSP_SCRIPT_SRC",
  197. str,
  198. ["'self'", "https://matomo.glitchtip.com", "https://js.stripe.com"],
  199. )
  200. CSP_IMG_SRC = env.list("CSP_IMG_SRC", str, ["'self'", "https://matomo.glitchtip.com"])
  201. CSP_FRAME_SRC = env.list("CSP_FRAME_SRC", str, ["'self'", "https://js.stripe.com"])
  202. # Consider tracking CSP reports with GlitchTip itself
  203. CSP_REPORT_URI = env.tuple("CSP_REPORT_URI", str, None)
  204. CSP_REPORT_ONLY = env.bool("CSP_REPORT_ONLY", False)
  205. SECURE_HSTS_SECONDS = env.int("SECURE_HSTS_SECONDS", 0)
  206. SECURE_HSTS_PRELOAD = env.bool("SECURE_HSTS_PRELOAD", False)
  207. SECURE_HSTS_INCLUDE_SUBDOMAINS = env.bool("SECURE_HSTS_INCLUDE_SUBDOMAINS", False)
  208. SESSION_COOKIE_SECURE = env.bool("SESSION_COOKIE_SECURE", False)
  209. SESSION_COOKIE_SAMESITE = env.str("SESSION_COOKIE_SAMESITE", "Lax")
  210. DEFAULT_FROM_EMAIL = env.str("DEFAULT_FROM_EMAIL", "webmaster@localhost")
  211. ANYMAIL = {
  212. "MAILGUN_API_KEY": env.str("MAILGUN_API_KEY", None),
  213. "MAILGUN_SENDER_DOMAIN": env.str("MAILGUN_SENDER_DOMAIN", None),
  214. }
  215. ACCOUNT_EMAIL_SUBJECT_PREFIX = ""
  216. # Database
  217. # https://docs.djangoproject.com/en/dev/ref/settings/#databases
  218. DATABASES = {
  219. "default": env.db(default="postgres://postgres:postgres@postgres:5432/postgres")
  220. }
  221. # We need to support both url and broken out host to support helm redis chart
  222. REDIS_HOST = env.str("REDIS_HOST", None)
  223. if REDIS_HOST:
  224. REDIS_PORT = env.str("REDIS_PORT", "6379")
  225. REDIS_DATABASE = env.str("REDIS_DATABASE", "0")
  226. REDIS_PASSWORD = env.str("REDIS_PASSWORD", None)
  227. if REDIS_PASSWORD:
  228. REDIS_URL = (
  229. f"redis://:{REDIS_PASSWORD}@{REDIS_HOST}:{REDIS_PORT}/{REDIS_DATABASE}"
  230. )
  231. else:
  232. REDIS_URL = f"redis://{REDIS_HOST}:{REDIS_PORT}/{REDIS_DATABASE}"
  233. else:
  234. REDIS_URL = env.str("REDIS_URL", "redis://redis:6379/0")
  235. CELERY_BROKER_URL = REDIS_URL
  236. CELERY_BROKER_TRANSPORT_OPTIONS = {
  237. "fanout_prefix": True,
  238. "fanout_patterns": True,
  239. }
  240. CELERY_RESULT_BACKEND = "django-db"
  241. CELERY_CACHE_BACKEND = "django-cache"
  242. CELERY_BEAT_SCHEDULE = {
  243. "send-alert-notifications": {
  244. "task": "alerts.tasks.process_alerts",
  245. "schedule": 60,
  246. },
  247. "cleanup-old-events": {
  248. "task": "issues.tasks.cleanup_old_events",
  249. "schedule": crontab(hour=6, minute=1),
  250. },
  251. "set-organization-throttle": {
  252. "task": "organizations_ext.tasks.set_organization_throttle",
  253. "schedule": crontab(hour=7, minute=1),
  254. },
  255. }
  256. CACHES = {"default": {"BACKEND": "redis_cache.RedisCache", "LOCATION": REDIS_URL}}
  257. # Password validation
  258. # https://docs.djangoproject.com/en/dev/ref/settings/#auth-password-validators
  259. AUTH_PASSWORD_VALIDATORS = [
  260. {
  261. "NAME": "django.contrib.auth.password_validation.UserAttributeSimilarityValidator",
  262. },
  263. {"NAME": "django.contrib.auth.password_validation.MinimumLengthValidator",},
  264. {"NAME": "django.contrib.auth.password_validation.CommonPasswordValidator",},
  265. {"NAME": "django.contrib.auth.password_validation.NumericPasswordValidator",},
  266. ]
  267. # Internationalization
  268. # https://docs.djangoproject.com/en/dev/topics/i18n/
  269. LANGUAGE_CODE = "en-us"
  270. TIME_ZONE = "UTC"
  271. USE_I18N = True
  272. USE_L10N = True
  273. USE_TZ = True
  274. SITE_ID = 1
  275. # Static files (CSS, JavaScript, Images)
  276. # https://docs.djangoproject.com/en/dev/howto/static-files/
  277. STATIC_URL = "/static/"
  278. MEDIA_URL = "media/" # Not used, can be anything except the STATIC_URL. Cannot be "" nor "/", but must end with a slash
  279. AWS_ACCESS_KEY_ID = env("AWS_ACCESS_KEY_ID")
  280. AWS_SECRET_ACCESS_KEY = env("AWS_SECRET_ACCESS_KEY")
  281. AWS_STORAGE_BUCKET_NAME = env("AWS_STORAGE_BUCKET_NAME")
  282. AWS_S3_ENDPOINT_URL = env("AWS_S3_ENDPOINT_URL")
  283. AWS_LOCATION = env("AWS_LOCATION")
  284. STATICFILES_DIRS = [
  285. "assets",
  286. "dist",
  287. ]
  288. STATIC_ROOT = path("static/")
  289. STATICFILES_STORAGE = env("STATICFILES_STORAGE")
  290. EMAIL_BACKEND = env.str(
  291. "EMAIL_BACKEND", default="django.core.mail.backends.smtp.EmailBackend"
  292. )
  293. if os.getenv("EMAIL_URL"):
  294. EMAIL_CONFIG = env.email_url("EMAIL_URL")
  295. vars().update(EMAIL_CONFIG)
  296. AUTH_USER_MODEL = "users.User"
  297. ACCOUNT_AUTHENTICATION_METHOD = "email"
  298. ACCOUNT_EMAIL_REQUIRED = True
  299. ACCOUNT_USERNAME_REQUIRED = False
  300. ACCOUNT_USER_MODEL_USERNAME_FIELD = None
  301. INVITATION_BACKEND = "organizations_ext.invitation_backend.InvitationBackend"
  302. OLD_PASSWORD_FIELD_ENABLED = True
  303. LOGOUT_ON_PASSWORD_CHANGE = False
  304. REST_AUTH_SERIALIZERS = {
  305. "USER_DETAILS_SERIALIZER": "users.serializers.UserSerializer",
  306. "TOKEN_SERIALIZER": "users.serializers.NoopTokenSerializer",
  307. "PASSWORD_RESET_SERIALIZER": "users.serializers.PasswordSetResetSerializer",
  308. }
  309. REST_AUTH_TOKEN_MODEL = "users.utils.NoopModel"
  310. REST_AUTH_TOKEN_CREATOR = "users.utils.noop_token_creator"
  311. # By default (False) only the first user may register and create an organization
  312. # Other users must be invited. Intended for private instances
  313. ENABLE_OPEN_USER_REGISTRATION = env.bool("ENABLE_OPEN_USER_REGISTRATION", False)
  314. AUTHENTICATION_BACKENDS = (
  315. # Needed to login by username in Django admin, regardless of `allauth`
  316. "django.contrib.auth.backends.ModelBackend",
  317. # `allauth` specific authentication methods, such as login by e-mail
  318. "allauth.account.auth_backends.AuthenticationBackend",
  319. )
  320. DEFAULT_RENDERER_CLASSES = ("rest_framework.renderers.JSONRenderer",)
  321. if DEBUG:
  322. DEFAULT_RENDERER_CLASSES = DEFAULT_RENDERER_CLASSES + (
  323. "rest_framework.renderers.BrowsableAPIRenderer",
  324. )
  325. REST_FRAMEWORK = {
  326. "DEFAULT_PERMISSION_CLASSES": ["rest_framework.permissions.IsAuthenticated"],
  327. "DEFAULT_PAGINATION_CLASS": "glitchtip.pagination.LinkHeaderPagination",
  328. "PAGE_SIZE": 50,
  329. "ORDERING_PARAM": "sort",
  330. "DEFAULT_FILTER_BACKENDS": ("django_filters.rest_framework.DjangoFilterBackend",),
  331. "DEFAULT_RENDERER_CLASSES": DEFAULT_RENDERER_CLASSES,
  332. "DEFAULT_AUTHENTICATION_CLASSES": [
  333. "rest_framework.authentication.SessionAuthentication",
  334. "glitchtip.authentication.BearerTokenAuthentication",
  335. ],
  336. }
  337. DRF_YASG_EXCLUDE_VIEWS = [
  338. "users.views.SocialAccountDisconnectView",
  339. ]
  340. SWAGGER_SETTINGS = {
  341. "DEFAULT_AUTO_SCHEMA_CLASS": "glitchtip.yasg.SquadSwaggerAutoSchema",
  342. }
  343. LOGGING = {
  344. "version": 1,
  345. "disable_existing_loggers": False,
  346. "handlers": {"null": {"class": "logging.NullHandler",},},
  347. "loggers": {
  348. "django.security.DisallowedHost": {"handlers": ["null"], "propagate": False,},
  349. },
  350. }
  351. def organization_request_callback(request):
  352. """ Gets an organization instance from the id passed through ``request``"""
  353. user = request.user
  354. if user:
  355. return user.organizations_ext_organization.filter(
  356. owner__organization_user__user=user
  357. ).first()
  358. # Set to track activity with Matomo
  359. MATOMO_URL = env.str("MATOMO_URL", default=None)
  360. MATOMO_SITE_ID = env.str("MATOMO_SITE_ID", default=None)
  361. # Set to Rocket Chat domain to enable live help widget. Example `https://example.rocket.chat`
  362. ROCKET_CHAT_DOMAIN = env.str("ROCKET_CHAT_DOMAIN", None)
  363. # Is running unit test
  364. TESTING = len(sys.argv) > 1 and sys.argv[1] == "test"
  365. # Max events per month for free tier
  366. BILLING_FREE_TIER_EVENTS = env.int("BILLING_FREE_TIER_EVENTS", 1000)
  367. DJSTRIPE_SUBSCRIBER_MODEL = "organizations_ext.Organization"
  368. DJSTRIPE_SUBSCRIBER_MODEL_REQUEST_CALLBACK = organization_request_callback
  369. DJSTRIPE_USE_NATIVE_JSONFIELD = True
  370. DJSTRIPE_FOREIGN_KEY_TO_FIELD = "djstripe_id"
  371. BILLING_ENABLED = False
  372. STRIPE_LIVE_MODE = env.bool("STRIPE_LIVE_MODE", False)
  373. if env.str("STRIPE_TEST_PUBLIC_KEY", None) or env.str("STRIPE_LIVE_PUBLIC_KEY", None):
  374. BILLING_ENABLED = True
  375. INSTALLED_APPS.append("djstripe")
  376. INSTALLED_APPS.append("djstripe_ext")
  377. STRIPE_TEST_PUBLIC_KEY = env.str("STRIPE_TEST_PUBLIC_KEY", None)
  378. STRIPE_TEST_SECRET_KEY = env.str("STRIPE_TEST_SECRET_KEY", None)
  379. STRIPE_LIVE_PUBLIC_KEY = env.str("STRIPE_LIVE_PUBLIC_KEY", None)
  380. STRIPE_LIVE_SECRET_KEY = env.str("STRIPE_LIVE_SECRET_KEY", None)
  381. DJSTRIPE_WEBHOOK_SECRET = env.str("DJSTRIPE_WEBHOOK_SECRET", None)
  382. elif TESTING:
  383. # Must run tests with djstripe enabled
  384. BILLING_ENABLED = True
  385. INSTALLED_APPS.append("djstripe")
  386. INSTALLED_APPS.append("djstripe_ext")
  387. STRIPE_TEST_PUBLIC_KEY = "fake"
  388. STRIPE_TEST_SECRET_KEY = "sk_test_fake" # nosec
  389. DJSTRIPE_WEBHOOK_SECRET = "whsec_fake" # nosec
  390. if TESTING:
  391. CELERY_TASK_ALWAYS_EAGER = True
  392. STATICFILES_STORAGE = None
  393. # https://github.com/evansd/whitenoise/issues/215
  394. warnings.filterwarnings(
  395. "ignore", message="No directory at", module="whitenoise.base"
  396. )