"""api.nocthink.com production settings.

    DJANGO_SETTINGS_MODULE=config.settings.nocthink

Paired with backend/.env.nocthink. SPA (nocthink.com) and API
(api.nocthink.com) share the registrable domain nocthink.com, so this deployment
is same-site and can use stricter cookies than caridu.
"""

from .prod import *  # noqa: F401,F403
from .prod import os

# This host has Redis (cPanel per-account unix socket), so base.py's
# ResilientRedisCache selection is correct and inherited as-is.
#
# Assert on the resolved backend rather than on os.environ['REDIS_URL']: base.py
# calls load_dotenv(), so an env probe here can be satisfied by a developer's
# .env and pass even when the deploy environment never set it. A silent
# downgrade to LocMemCache would make DRF throttle counters per-worker.
if 'locmem' in CACHES['default']['BACKEND'].lower():  # noqa: F405
    raise RuntimeError(
        'REDIS_URL is required for the nocthink deployment: the cache resolved '
        'to LocMemCache, which makes DRF throttle counters per-worker and '
        'disables cross-process caching.'
    )

# Same-site, so Lax works and is a real CSRF improvement over None: the cookie
# still rides the SPA's XHRs to api.nocthink.com but is withheld from genuine
# third-party requests. Shared parent domain lets both hosts see one cookie.
SESSION_COOKIE_SAMESITE = os.environ.get('SESSION_COOKIE_SAMESITE', 'Lax')
CSRF_COOKIE_SAMESITE = os.environ.get('CSRF_COOKIE_SAMESITE', 'Lax')
SESSION_COOKIE_DOMAIN = os.environ.get('SESSION_COOKIE_DOMAIN', '.nocthink.com')
CSRF_COOKIE_DOMAIN = os.environ.get('CSRF_COOKIE_DOMAIN', '.nocthink.com')

# Email via Cloudflare Email Sending; media via R2 when credentials are present.
# Both stay env-driven (base.py) so a missing token degrades visibly rather than
# being hardcoded here.

# Uploads are read only through /api/media/<path>, which resolves each file's
# owning organization. This deployment is the SaaS one — multiple tenants share
# the database, so unauthenticated media serving would let any tenant read
# another's HR contracts and bank statements. caridu keeps the historical
# behavior until its frontend is migrated.
MEDIA_SERVE_UNAUTHENTICATED = False
