4 ms·
A thought on security - I think #5 should be changed from if socket.gethostname() == 'productionserver.com': DEBUG = False else: DEBUG
by outotrai 17y ago
A thought on security - I think #5 should be changed from
if socket.gethostname() == 'productionserver.com':
DEBUG = False
else:
DEBUG = True
to
if socket.gethostname() == 'developmentcomp':
DEBUG = True
else:
DEBUG = False
It's better practice to whitelist one box than to enable DEBUG on all computers but the production server - what if you deploy to another machine without thinking?
- jonknee 17y agoYou're right. Another handy way to do this is to keep debug as False and use middleware to show the debug error if you're logged in as an admin or from an IP that matches in INTERNAL_IPS: http://ericholscher.com/blog/2008/nov/15/debugging-django-production-environments/ http://ericholscher.com/blog/2008/nov/15/debugging-django-pr... Sort of the best of both worlds.
- jksmith 17y agoPlease, for the love of conciseness, never assign a boolean based on an if statement.
- pvg 17y agoAn odd thing thing about this piece of advice is that it contradicts a lot of the previous advice which is 'don't hardcode stuff' This pattern is questionable for another reason - basing the app's configuration on some other, largely unrelated configuration (in this case, that of the network) can lead to elusive and annoying bugs. Configuration problems are much easier to debug when an application is told what its configuration is rather than trying to magically divine it from its environment.