Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

config.hostsの設定を修正 #1722

Merged
merged 1 commit into from
Aug 17, 2022
Merged

config.hostsの設定を修正 #1722

merged 1 commit into from
Aug 17, 2022

Conversation

nabeta
Copy link
Member

@nabeta nabeta commented Aug 17, 2022

Rails 6.1で導入されたDNSリバインディング攻撃の対策を、明示的にdevelopment環境でのみ有効化するように変更するPRです。
https://railsguides.jp/configuring.html#actiondispatch-hostauthorization

既定ではdevelopment環境でのみ有効なのですが、 #1721 でCataloupeからEnju本体にアクセスさせるために設定を変更したところ、development環境以外でもこの設定が有効になってしまい、アプリケーションにアクセスできなくなってしまいました。

@nabeta nabeta added this to the 1.4.0 milestone Aug 17, 2022
@nabeta nabeta merged commit 50591de into main Aug 17, 2022
@nabeta nabeta deleted the fix-config-hosts branch August 17, 2022 09:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Development

Successfully merging this pull request may close these issues.

None yet

1 participant