Spaces:
Running
Running
| """ | |
| Django settings for core project. | |
| """ | |
| from pathlib import Path | |
| import os | |
| from dotenv import load_dotenv | |
| load_dotenv() | |
| # Build paths inside the project like this: BASE_DIR / 'subdir'. | |
| BASE_DIR = Path(__file__).resolve().parent.parent | |
| # SECURITY WARNING: keep the secret key used in production secret! | |
| SECRET_KEY = os.getenv('SECRET_KEY', 'django-insecure-yfg#m4w$m&#igix9$bx87f#*gxsd=(l#y_i@ig16-5ug^g3a-k') | |
| # SECURITY WARNING: don't run with debug turned on in production! | |
| # Forzamos DEBUG a True para que si hay un error, nos diga exactamente qué es en vez de Bad Request | |
| DEBUG = True | |
| # --- CONFIGURACIÓN DE HOSTS --- | |
| # El '*' es vital para que el proxy de Hugging Face no bloquee la petición | |
| ALLOWED_HOSTS = ['*'] | |
| # --- CONFIGURACIÓN DE PROXY (Esto quita el Bad Request en Hugging Face) --- | |
| USE_X_FORWARDED_HOST = True | |
| SECURE_PROXY_SSL_HEADER = ('HTTP_X_FORWARDED_PROTO', 'https') | |
| USE_X_FORWARDED_PORT = True | |
| # Application definition | |
| INSTALLED_APPS = [ | |
| 'whitenoise.runserver_nostatic', | |
| 'django.contrib.admin', | |
| 'django.contrib.auth', | |
| 'django.contrib.contenttypes', | |
| 'django.contrib.sessions', | |
| 'django.contrib.messages', | |
| 'django.contrib.staticfiles', | |
| 'rest_framework', | |
| 'corsheaders', | |
| 'api', | |
| ] | |
| MIDDLEWARE = [ | |
| 'corsheaders.middleware.CorsMiddleware', # Debe ser el primero | |
| 'django.middleware.security.SecurityMiddleware', | |
| 'whitenoise.middleware.WhiteNoiseMiddleware', | |
| 'django.contrib.sessions.middleware.SessionMiddleware', | |
| 'django.middleware.common.CommonMiddleware', | |
| 'django.middleware.csrf.CsrfViewMiddleware', | |
| 'django.contrib.auth.middleware.AuthenticationMiddleware', | |
| 'django.contrib.messages.middleware.MessageMiddleware', | |
| 'django.middleware.clickjacking.XFrameOptionsMiddleware', | |
| ] | |
| ROOT_URLCONF = 'core.urls' | |
| TEMPLATES = [ | |
| { | |
| 'BACKEND': 'django.template.backends.django.DjangoTemplates', | |
| 'DIRS': [], | |
| 'APP_DIRS': True, | |
| 'OPTIONS': { | |
| 'context_processors': [ | |
| 'django.template.context_processors.request', | |
| 'django.contrib.auth.context_processors.auth', | |
| 'django.contrib.messages.context_processors.messages', | |
| ], | |
| }, | |
| }, | |
| ] | |
| WSGI_APPLICATION = 'core.wsgi.application' | |
| # Database | |
| DATABASES = { | |
| 'default': { | |
| 'ENGINE': 'django.db.backends.sqlite3', | |
| 'NAME': BASE_DIR / 'db.sqlite3', | |
| } | |
| } | |
| # Password validation | |
| AUTH_PASSWORD_VALIDATORS = [ | |
| {'NAME': 'django.contrib.auth.password_validation.UserAttributeSimilarityValidator'}, | |
| {'NAME': 'django.contrib.auth.password_validation.MinimumLengthValidator'}, | |
| {'NAME': 'django.contrib.auth.password_validation.CommonPasswordValidator'}, | |
| {'NAME': 'django.contrib.auth.password_validation.NumericPasswordValidator'}, | |
| ] | |
| # Internationalization | |
| LANGUAGE_CODE = 'en-us' | |
| TIME_ZONE = 'UTC' | |
| USE_I18N = True | |
| USE_TZ = True | |
| # Static files | |
| STATIC_URL = 'static/' | |
| STATIC_ROOT = os.path.join(BASE_DIR, 'staticfiles') | |
| # Simplificamos esto para evitar errores de directorio inexistente | |
| STATICFILES_STORAGE = 'whitenoise.storage.CompressedStaticFilesStorage' | |
| DEFAULT_AUTO_FIELD = 'django.db.models.BigAutoField' | |
| # --- CONFIGURACIÓN DE CORS --- | |
| CORS_ALLOW_ALL_ORIGINS = True | |
| CORS_ALLOW_CREDENTIALS = True | |
| CORS_ALLOW_HEADERS = ["*"] | |
| # --- CONFIGURACIÓN DE CSRF --- | |
| CSRF_TRUSTED_ORIGINS = [ | |
| "https://fintech-coop-ai.vercel.app", | |
| "https://fintech-coop-or6mski9z-tomasgonzalezpy-4881s-projects.vercel.app", | |
| "https://*.hf.space" | |
| ] | |
| # Evitar que Django fuerce barras diagonales si el cliente no las envía | |
| APPEND_SLASH = True |