"""Shared production settings.

Not selected directly — use config.settings.caridu or config.settings.nocthink.
This module holds the hardening that must hold on every deployed host, so a new
deployment inherits it by importing from here rather than by remembering to
re-specify it.
"""

from .base import *  # noqa: F401,F403
from .base import _env_bool, os

# Never negotiable in production, whatever the env file says.
DEBUG = False

# SECRET_KEY is already required by base.py, which raises if it is unset — no
# weaker fallback exists to guard against here.
#
# Note for anyone adding checks below: base.py calls load_dotenv(BASE_DIR/'.env'),
# so probing os.environ from this module is unreliable — a developer's .env
# repopulates variables the deploy environment never set, and the check passes
# for the wrong reason. Assert on the resolved setting instead.

# Refuse the wildcard: with ALLOWED_HOSTS=['*'] a Host-header attack can poison
# password-reset and activation links to point at an attacker's domain.
if not ALLOWED_HOSTS or '*' in ALLOWED_HOSTS:  # noqa: F405
    raise RuntimeError(
        'DJANGO_ALLOWED_HOSTS must name this deployment\'s hostname explicitly.'
    )

# HTTPS everywhere. Cookie SameSite/Domain stay env-driven because the two
# deployments genuinely differ: nocthink is same-site (Lax + shared parent
# domain), caridu is cross-site (None) because its SPA is on another domain.
SESSION_COOKIE_SECURE = True
CSRF_COOKIE_SECURE = True
SECURE_HSTS_SECONDS = int(os.environ.get('SECURE_HSTS_SECONDS', 31536000))
SECURE_HSTS_INCLUDE_SUBDOMAINS = _env_bool('SECURE_HSTS_INCLUDE_SUBDOMAINS', True)
SECURE_HSTS_PRELOAD = _env_bool('SECURE_HSTS_PRELOAD', True)
SECURE_PROXY_SSL_HEADER = ('HTTP_X_FORWARDED_PROTO', 'https')
USE_X_FORWARDED_HOST = True
USE_X_FORWARDED_PORT = True

# Real workers exist in production, so background work must not run inline in
# the request/response cycle.
BACKGROUND_TASKS_EAGER = False
CELERY_TASK_ALWAYS_EAGER = _env_bool('CELERY_TASK_ALWAYS_EAGER', False)

# Apache/nginx serves /media/ directly on both hosts, so the per-request disk
# rescan is wasted work.
WHITENOISE_AUTOREFRESH = _env_bool('WHITENOISE_AUTOREFRESH', False)
