Opened 17 years ago
Closed 17 years ago
#7357 closed (duplicate)
[patch] create_default_site: configurable default domain name
| Reported by: | Etienne Robillard | Owned by: | nobody |
|---|---|---|---|
| Component: | Contrib apps | Version: | dev |
| Severity: | Keywords: | ||
| Cc: | Triage Stage: | Unreviewed | |
| Has patch: | yes | Needs documentation: | no |
| Needs tests: | no | Patch needs improvement: | no |
| Easy pickings: | no | UI/UX: | no |
Description
Hi,
The create_default_site function in the django.contrib.sites.management
module hardcodes example.com as the default site. I think this is potentially
harmful for users because it can be exploited remotely.
A better hardcoded value would be to use 'localhost' or socket.gethostname
as the default domain name. The attached patch implements the later for resolving
the default domain name.
Note:
See TracTickets
for help on using tickets.
Oops.. here's a flying dup...