diff --git a/config/nginx.conf b/config/nginx.conf index afef435..0e3f4b4 100644 --- a/config/nginx.conf +++ b/config/nginx.conf @@ -20,7 +20,7 @@ http { location / { proxy_pass http://web:8000; proxy_set_header HOST $host; - proxy_set_header X-Forwarded-Proto $scheme; + proxy_set_header X-Forwarded-Proto $http_x_forwarded_proto; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; } diff --git a/src/teamable/settings.py b/src/teamable/settings.py index 60fec46..79b4038 100644 --- a/src/teamable/settings.py +++ b/src/teamable/settings.py @@ -30,6 +30,9 @@ # SECURITY WARNING: don't run with debug turned on in production! DEBUG = os.environ.get("DEBUG", "FALSE") == "TRUE" +# Needed so that the LTI -> Canvas OAuth redirect doesn't get switched to http via the server's nginx config +SECURE_PROXY_SSL_HEADER = ("HTTP_X_FORWARDED_PROTO", "https") + if DEBUG: ALLOWED_HOSTS = ["*"] CSRF_TRUSTED_ORIGINS = ["http://localhost:8002"] @@ -39,7 +42,6 @@ map(lambda x: f"https://{x}", os.environ["SERVER_NAME"].split()) ) - # Application definition INSTALLED_APPS = [ @@ -119,7 +121,6 @@ } } - # Password validation # https://docs.djangoproject.com/en/5.0/ref/settings/#auth-password-validators @@ -138,7 +139,6 @@ }, ] - # Internationalization # https://docs.djangoproject.com/en/5.0/topics/i18n/ @@ -150,7 +150,6 @@ USE_TZ = True - # Static files (CSS, JavaScript, Images) # https://docs.djangoproject.com/en/3.0/howto/static-files/