Skip to main content

ALLOWED_HOSTS

Constant ALLOWED_HOSTS 

Source
pub const ALLOWED_HOSTS: &str = "ALLOWED_HOSTS";
Expand description

Name of the Worker variable listing the host names the app answers to (Rails’ config.hosts).

Comma-separated; an entry starting with . also allows every subdomain (.example.com allows example.com and www.example.com). When set, requests for any other Host get a plain-text 403 Forbidden before any handler or session code runs; localhost, 127.0.0.1 and [::1] are always allowed so ocre dev keeps working (Cloudflare only routes your own host names to the Worker, so these never reach it in production). Unset or empty: every host is allowed.

On Workers, DNS rebinding cannot reach the app, but the same Worker also answers on <name>.<account>.workers.dev and preview URLs: list your custom domain to keep search engines and users on it. Read once per request by serve; no binding call.

// worker.env in cloudflare.config.ts
ALLOWED_HOSTS: bindings.text("example.com, .example.com"),

§Examples

assert_eq!(ocre::ALLOWED_HOSTS, "ALLOWED_HOSTS");