from django.core.exceptions import ImproperlyConfigured

from .base import *  # noqa: F403
from .base import SECRET_KEY, env_bool, env_choice, env_list

DEBUG = False
COMMUNICATIONS_PRODUCTION = True
if len(SECRET_KEY) < 50 or len(set(SECRET_KEY)) < 5 or SECRET_KEY.startswith("django-insecure-"):
    raise ImproperlyConfigured("Production requires a strong, independently generated DJANGO_SECRET_KEY.")
ALLOWED_HOSTS = env_list("DJANGO_ALLOWED_HOSTS")
if not ALLOWED_HOSTS or "*" in ALLOWED_HOSTS:
    raise ImproperlyConfigured("Production requires explicit DJANGO_ALLOWED_HOSTS; wildcard is forbidden.")
CSRF_TRUSTED_ORIGINS = env_list("DJANGO_CSRF_TRUSTED_ORIGINS")
SECURE_SSL_REDIRECT = True
SESSION_COOKIE_SECURE = True
SESSION_COOKIE_HTTPONLY = True
CSRF_COOKIE_SECURE = True
SECURE_CONTENT_TYPE_NOSNIFF = True
SECURE_REFERRER_POLICY = env_choice("DJANGO_SECURE_REFERRER_POLICY",
    {"no-referrer", "no-referrer-when-downgrade", "origin", "origin-when-cross-origin", "same-origin", "strict-origin",
     "strict-origin-when-cross-origin", "unsafe-url"}, "same-origin")
SECURE_HSTS_SECONDS = 31536000
# Subdomain and preload coverage are whole-domain commitments that C-CARE cannot
# verify. They stay off unless the operator asserts every subdomain is HTTPS-only.
SECURE_HSTS_INCLUDE_SUBDOMAINS = env_bool("DJANGO_HSTS_INCLUDE_SUBDOMAINS")
SECURE_HSTS_PRELOAD = env_bool("DJANGO_HSTS_PRELOAD")
X_FRAME_OPTIONS = "DENY"

# A TLS-terminating reverse proxy must not be able to spoof the forwarded
# protocol unless the operator declares exactly one trusted hop. Enabling this
# without that hop stripped at the proxy would let a client forge the scheme.
PROXY_HOP = env_choice("DJANGO_TRUSTED_PROXY_HEADER",
    {"NONE", "X-FORWARDED-PROTO", "X-FORWARDED-PROTOCOL", "X-FORWARDED-SSL"}, "NONE")
if PROXY_HOP != "NONE":
    SECURE_PROXY_SSL_HEADER = ("HTTP_X_FORWARDED_PROTO", "https") if PROXY_HOP == "X-FORWARDED-PROTO" \
        else ("HTTP_X_FORWARDED_PROTOCOL", "https") if PROXY_HOP == "X-FORWARDED-PROTOCOL" \
        else ("HTTP_X_FORWARDED_SSL", "on")

# A readiness probe may spend at most this long inside the database.
READY_STATEMENT_TIMEOUT_MS = 2000
