"""api.caridu.id production settings.

    DJANGO_SETTINGS_MODULE=config.settings.caridu

Paired with backend/.env.production. SPA is served from orm.csis.or.id, which is
a different registrable domain from caridu.id — hence the cross-site cookie
configuration below.
"""

from .prod import *  # noqa: F401,F403
from .prod import _env_bool, os

# No Redis on this host. base.py already falls back to LocMemCache when
# REDIS_URL is unset, but pin it explicitly so a stray REDIS_URL in the
# environment cannot silently point this deployment at someone else's Redis.
CACHES = {
    'default': {
        'BACKEND': 'django.core.cache.backends.locmem.LocMemCache',
        'LOCATION': 'khub-locmem',
    }
}

# Per-process cache, so the consequences are worth stating: DRF throttle counters
# are per-worker (effective rate = configured rate x worker count) and cached
# values are not shared between workers. Acceptable at this host's traffic; the
# fix is a real Redis, not a bigger LocMem.

# WSGI-only host: no ASGI server, so WebSocket fan-out cannot work regardless of
# the layer. In-memory keeps consumers importable without pretending otherwise.
CHANNEL_LAYERS = {
    'default': {'BACKEND': 'channels.layers.InMemoryChannelLayer'},
}

# Cross-site: the SPA on orm.csis.or.id sends credentialed XHR to api.caridu.id.
# SameSite=None is required for the browser to attach the cookie at all, and
# None demands Secure. No cookie Domain — the two hosts share no parent domain.
SESSION_COOKIE_SAMESITE = os.environ.get('SESSION_COOKIE_SAMESITE', 'None')
CSRF_COOKIE_SAMESITE = os.environ.get('CSRF_COOKIE_SAMESITE', 'None')

# Media on local disk (no R2 configured for this deployment). Left env-driven so
# enabling R2 later is a .env change, not a code change.
