From 7399fee6c3bb7eded1ecf5855d71520db299d79d Mon Sep 17 00:00:00 2001 From: Ed Morley Date: Tue, 26 Jul 2016 13:05:27 +0100 Subject: Refs #26947 -- Added a deployment system check for SECURE_HSTS_PRELOAD. --- django/core/checks/security/base.py | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) (limited to 'django') diff --git a/django/core/checks/security/base.py b/django/core/checks/security/base.py index eee7f854c8..f482f77153 100644 --- a/django/core/checks/security/base.py +++ b/django/core/checks/security/base.py @@ -101,6 +101,12 @@ W020 = Warning( id='security.W020', ) +W021 = Warning( + "You have not set the SECURE_HSTS_PRELOAD setting to True. Without this, " + "your site cannot be submitted to the browser preload list.", + id='security.W021', +) + def _security_middleware(): return ("django.middleware.security.SecurityMiddleware" in settings.MIDDLEWARE_CLASSES or @@ -140,6 +146,16 @@ def check_sts_include_subdomains(app_configs, **kwargs): return [] if passed_check else [W005] +@register(Tags.security, deploy=True) +def check_sts_preload(app_configs, **kwargs): + passed_check = ( + not _security_middleware() or + not settings.SECURE_HSTS_SECONDS or + settings.SECURE_HSTS_PRELOAD is True + ) + return [] if passed_check else [W021] + + @register(Tags.security, deploy=True) def check_content_type_nosniff(app_configs, **kwargs): passed_check = ( -- cgit v1.3