Skip to content

Commit

Permalink
Configure hosts for application
Browse files Browse the repository at this point in the history
Note: the healthcheck endpoints are requested by IP, not domain, so we
need to specifically exclude them from the protection.
  • Loading branch information
brucebolt committed Oct 8, 2024
1 parent e3110e3 commit a2a3f7b
Showing 1 changed file with 8 additions and 0 deletions.
8 changes: 8 additions & 0 deletions config/environments/production.rb
Original file line number Diff line number Diff line change
Expand Up @@ -83,4 +83,12 @@

# Do not dump schema after migrations.
config.active_record.dump_schema_after_migration = false

# Enable DNS rebinding protection and other `Host` header attacks.
config.hosts = [
/content-tagger\..*gov.uk?/,
]

# Skip DNS rebinding protection for the default health check endpoint.
config.host_authorization = { exclude: ->(request) { request.path.match?("^\/healthcheck") } }
end

0 comments on commit a2a3f7b

Please sign in to comment.