Open amirtds opened 10 months ago
Checking git merge conflicts against https://github.com/edx/edx-platform.git
Comparing with | open-release/nutmeg.master |
---|---|
Benchmark conflicts with main |
299 |
Current conflicts | 301 |
Summary | Adds 2 new conflicts. How can we do better? |
Comparing with | master |
---|---|
Benchmark conflicts with main |
320 |
Current conflicts | 322 |
Summary | Adds 2 new conflicts. How can we do better? |
Checking git merge conflicts against https://github.com/edx/edx-platform.git
Comparing with | open-release/nutmeg.master |
---|---|
Benchmark conflicts with main |
299 |
Current conflicts | 301 |
Summary | Adds 2 new conflicts. How can we do better? |
Comparing with | master |
---|---|
Benchmark conflicts with main |
320 |
Current conflicts | 322 |
Summary | Adds 2 new conflicts. How can we do better? |
Checking git merge conflicts against https://github.com/edx/edx-platform.git
Comparing with | open-release/nutmeg.master |
---|---|
Benchmark conflicts with main |
299 |
Current conflicts | 299 |
Summary | Good work! No added conflicts. |
Comparing with | master |
---|---|
Benchmark conflicts with main |
320 |
Current conflicts | 320 |
Summary | Good work! No added conflicts. |
Checking git merge conflicts against https://github.com/edx/edx-platform.git
Comparing with | open-release/nutmeg.master |
---|---|
Benchmark conflicts with main |
299 |
Current conflicts | 299 |
Summary | Good work! No added conflicts. |
Comparing with | master |
---|---|
Benchmark conflicts with main |
320 |
Current conflicts | 320 |
Summary | Good work! No added conflicts. |
Checking git merge conflicts against https://github.com/edx/edx-platform.git
Comparing with | open-release/nutmeg.master |
---|---|
Benchmark conflicts with main |
299 |
Current conflicts | 299 |
Summary | Good work! No added conflicts. |
Comparing with | master |
---|---|
Benchmark conflicts with main |
320 |
Current conflicts | 320 |
Summary | Good work! No added conflicts. |
Checking git merge conflicts against https://github.com/edx/edx-platform.git
Comparing with | open-release/nutmeg.master |
---|---|
Benchmark conflicts with main |
299 |
Current conflicts | 299 |
Summary | Good work! No added conflicts. |
Comparing with | master |
---|---|
Benchmark conflicts with main |
320 |
Current conflicts | 320 |
Summary | Good work! No added conflicts. |
Checking git merge conflicts against https://github.com/edx/edx-platform.git
Comparing with | open-release/nutmeg.master |
---|---|
Benchmark conflicts with main |
299 |
Current conflicts | 299 |
Summary | Good work! No added conflicts. |
Comparing with | master |
---|---|
Benchmark conflicts with main |
320 |
Current conflicts | 320 |
Summary | Good work! No added conflicts. |
Checking git merge conflicts against https://github.com/edx/edx-platform.git
Comparing with | open-release/nutmeg.master |
---|---|
Benchmark conflicts with main |
299 |
Current conflicts | 299 |
Summary | Good work! No added conflicts. |
Comparing with | master |
---|---|
Benchmark conflicts with main |
319 |
Current conflicts | 319 |
Summary | Good work! No added conflicts. |
Checking git merge conflicts against https://github.com/edx/edx-platform.git
Comparing with | open-release/nutmeg.master |
---|---|
Benchmark conflicts with main |
299 |
Current conflicts | 299 |
Summary | Good work! No added conflicts. |
Comparing with | master |
---|---|
Benchmark conflicts with main |
319 |
Current conflicts | 319 |
Summary | Good work! No added conflicts. |
@amirtds
Looks like the Docker build for checks is failing because py2neo is now End of Life and there are no longer any releases in GitHub for https://github.com/technige/py2neo
We'll need to update in another PR first. Maybe been fixed upstream so will check
Waiting on merge to main of https://github.com/appsembler/edx-platform/pull/1387
Checking git merge conflicts against https://github.com/edx/edx-platform.git
Comparing with | open-release/nutmeg.master |
---|---|
Benchmark conflicts with main |
299 |
Current conflicts | 299 |
Summary | Good work! No added conflicts. |
Comparing with | master |
---|---|
Benchmark conflicts with main |
318 |
Current conflicts | 318 |
Summary | Good work! No added conflicts. |
Hi @bryanlandia I added same settings for CMS as well, could you please take a look when you have some time
Checking git merge conflicts against https://github.com/edx/edx-platform.git
Comparing with | open-release/nutmeg.master |
---|---|
Benchmark conflicts with main |
299 |
Current conflicts | 299 |
Summary | Good work! No added conflicts. |
Comparing with | master |
---|---|
Benchmark conflicts with main |
318 |
Current conflicts | 318 |
Summary | Good work! No added conflicts. |
Checking git merge conflicts against https://github.com/edx/edx-platform.git
Comparing with | open-release/nutmeg.master |
---|---|
Benchmark conflicts with main |
299 |
Current conflicts | 299 |
Summary | Good work! No added conflicts. |
Comparing with | master |
---|---|
Benchmark conflicts with main |
318 |
Current conflicts | 318 |
Summary | Good work! No added conflicts. |
Change description
We received a security report highlighting a Host Header Injection vulnerability due to the use of a wildcard '*' in our ALLOWED_HOSTS setting. This configuration could lead to open redirects and other security risks.
I have modified
settings.py
to dynamically construct theALLOWED_HOSTS
list using domain names from our Django sites to ensures that only valid domains are served.Changes:
ALLOWED_HOSTS
.ALLOWED_HOSTS
with domain names fetched from theSite
model.ENV_TOKENS['LMS_BASE']
andFEATURES['PREVIEW_LMS_BASE']
are included inALLOWED_HOSTS
if they are valid.ALLOWED_HOSTS
.Type of change
Related issues
Checklists
Development
Security
Code review