From ad5848818b921881b26aecee84b4000b7bd3cdbc Mon Sep 17 00:00:00 2001 From: Morten Kaae <37534541+MortenKaae@users.noreply.github.com> Date: Sun, 2 Apr 2023 10:50:58 +0200 Subject: [PATCH] Remove deprecated security setting Removes the setting SECURE_BROWSER_XSS_FILTER, which was deprecated in Django 4.0 --- {{cookiecutter.project_slug}}/config/settings/base.py | 2 -- 1 file changed, 2 deletions(-) diff --git a/{{cookiecutter.project_slug}}/config/settings/base.py b/{{cookiecutter.project_slug}}/config/settings/base.py index cc77b864a..441fe4a2c 100644 --- a/{{cookiecutter.project_slug}}/config/settings/base.py +++ b/{{cookiecutter.project_slug}}/config/settings/base.py @@ -225,8 +225,6 @@ FIXTURE_DIRS = (str(APPS_DIR / "fixtures"),) SESSION_COOKIE_HTTPONLY = True # https://docs.djangoproject.com/en/dev/ref/settings/#csrf-cookie-httponly CSRF_COOKIE_HTTPONLY = True -# https://docs.djangoproject.com/en/dev/ref/settings/#secure-browser-xss-filter -SECURE_BROWSER_XSS_FILTER = True # https://docs.djangoproject.com/en/dev/ref/settings/#x-frame-options X_FRAME_OPTIONS = "DENY"