From: Takeshi Umeda Date: Wed, 21 Apr 2021 15:45:58 +0000 (+0900) Subject: Add guard against DNS rebinding attacks (#16087) X-Git-Url: https://git.xn--scling-oua.cat.family/?a=commitdiff_plain;h=83230234643bb53ba563e42d73fb91a0dcfbff64;p=mastodon.git Add guard against DNS rebinding attacks (#16087) * Add guard against DNS rebinding attacks * Fix not to apply to test environment --- diff --git a/config/initializers/1_hosts.rb b/config/initializers/1_hosts.rb index 757f1f735..0ce4320b7 100644 --- a/config/initializers/1_hosts.rb +++ b/config/initializers/1_hosts.rb @@ -26,4 +26,10 @@ Rails.application.configure do "ws://#{ENV['REMOTE_DEV'] == 'true' ? host.split(':').first : 'localhost'}:4000" end end + + unless Rails.env.test? + config.hosts << host if host.present? + config.hosts << web_host if web_host.present? + config.hosts << alternate_domains if alternate_domains.present? + end end