Skip to content

Commit

Permalink
Update hosts for application
Browse files Browse the repository at this point in the history
The previous regex permitted `app-name.dodgygov.uk`. Updating to
disallow this and only permit `*.gov.uk`.
  • Loading branch information
brucebolt committed Oct 18, 2024
1 parent d45ace0 commit 277949c
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion config/environments/production.rb
Original file line number Diff line number Diff line change
Expand Up @@ -80,7 +80,7 @@

# Enable DNS rebinding protection and other `Host` header attacks.
config.hosts = [
/transition\..*gov.uk?/,
/transition\..*\.gov.uk$/,
]

# Skip DNS rebinding protection for the default health check endpoint.
Expand Down

0 comments on commit 277949c

Please sign in to comment.