Allow trusted hosts to be configured with the installer

Created on 8 January 2015, almost 10 years ago
Updated 7 September 2023, over 1 year ago

#2221699: HTTP_HOST header cannot be trusted β†’ will enable the Symfony trusted host mechanism as an opt-in protection, configured from settings.php. If the setting is empty, the trusted host mechanism is not enabled.

The initial trusted host settings should be set in the installer, either automatically, or through an additional setting on the CONFIGURE SITE step of the process.

πŸ“Œ Task
Status

Needs work

Version

11.0 πŸ”₯

Component
InstallΒ  β†’

Last updated 2 days ago

No maintainer
Created by

πŸ‡ΊπŸ‡ΈUnited States mpdonadio Philadelphia/PA/USA (UTC-5)

Live updates comments and jobs are added and updated live.
  • Security improvements

    It makes Drupal less vulnerable to abuse or misuse. Note, this is the preferred tag, though the Security tag has a large body of issues tagged to it. Do NOT publicly disclose security vulnerabilities; contact the security team instead. Anyone (whether security team or not) can apply this tag to security improvements that do not directly present a vulnerability e.g. hardening an API to add filtering to reduce a common mistake in contributed modules.

  • Needs tests

    The change is currently missing an automated test that fails when run with the original code, and succeeds when the bug has been fixed.

  • Triaged core major

    There is consensus among core maintainers that this is a major issue. Only core committers should add this tag.

Sign in to follow issues

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

Production build 0.71.5 2024