Skip to content

Commit

Permalink
Merge pull request #1284 from alphagov/add-hosts
Browse files Browse the repository at this point in the history
Configure hosts for application
  • Loading branch information
ChrisBAshton authored Oct 10, 2024
2 parents 8e712d3 + 36c94bc commit 35864ef
Showing 1 changed file with 8 additions and 0 deletions.
8 changes: 8 additions & 0 deletions config/environments/production.rb
Original file line number Diff line number Diff line change
Expand Up @@ -90,4 +90,12 @@
logger.formatter = config.log_formatter
config.logger = ActiveSupport::TaggedLogging.new(logger)
end

# Enable DNS rebinding protection and other `Host` header attacks.
config.hosts = [
/maslow\..*gov.uk?/,
]

# Skip DNS rebinding protection for the default health check endpoint.
config.host_authorization = { exclude: ->(request) { request.path.match?("^\/healthcheck") } }
end

0 comments on commit 35864ef

Please sign in to comment.