The internal_view decorator makes a view accessible only from INTERNAL_IPS. Handy for exposing internal APIs.
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 | import functools
from django.conf import settings
from django.http import HttpResponseForbidden
from django.views.decorators.csrf import csrf_exempt
def internal_view(view):
'''Decorates a view as accessible from INTERNAL_IPS only.
As a convenience, the view is also decorated with ``csrf_exempt``.
'''
@functools.wraps(view)
def wrapper_view(request, *args, **kwds):
remote_addr = request.META.get('HTTP_X_REAL_IP',
request.META.get('REMOTE_ADDR', None))
if not (settings.DEBUG or remote_addr in settings.INTERNAL_IPS):
return HttpResponseForbidden('Internal view')
return view(request, *args, **kwds)
return csrf_exempt(wrapper_view)
|
More like this
- Form field with fixed value by roam 1 week, 5 days ago
- New Snippet! by Antoliny0919 2 weeks, 4 days ago
- Add Toggle Switch Widget to Django Forms by OgliariNatan 3 months, 1 week ago
- get_object_or_none by azwdevops 6 months, 4 weeks ago
- Mask sensitive data from logger by agusmakmun 8 months, 3 weeks ago
Comments
Please login first before commenting.