pub const ALLOWED_HOSTS: &str = "ALLOWED_HOSTS";Expand description
Name of the Worker variable listing the host names the app answers to (Rails’ config.hosts).
Comma-separated; an entry starting with . also allows every subdomain
(.example.com allows example.com and www.example.com). When set,
requests for any other Host get a plain-text 403 Forbidden before any
handler or session code runs; localhost, 127.0.0.1 and [::1] are
always allowed so ocre dev keeps working (Cloudflare only routes your
own host names to the Worker, so these never reach it in production).
Unset or empty: every host is allowed.
On Workers, DNS rebinding cannot reach the app, but the same Worker also
answers on <name>.<account>.workers.dev and preview URLs: list your
custom domain to keep search engines and users on it. Read once per
request by serve; no binding call.
// worker.env in cloudflare.config.ts
ALLOWED_HOSTS: bindings.text("example.com, .example.com"),§Examples
assert_eq!(ocre::ALLOWED_HOSTS, "ALLOWED_HOSTS");