Is ALLOWED_HOSTS needed on Heroku?

后端 未结 2 1845
渐次进展
渐次进展 2021-01-02 02:53

From what I understand, ALLOWED_HOSTS does a check when DEBUG=False to prevent an attacker from pointing their own domain to your site.

It

2条回答
  •  暗喜
    暗喜 (楼主)
    2021-01-02 03:39

    Note that Heroku removed ['*'] from the getting started guide in December 2017.

    I recommend setting ALLOWED_HOSTS = ['.herokuapp.com'].

    Even though Heroku's domain service is providing this protection, specifying the setting will be a reminder to update the configuration if moved to another hosting service.

提交回复
热议问题