Commit f8b88f6a authored by Joshua Pereyda's avatar Joshua Pereyda Committed by Tim Graham
Browse files

[1.9.x] Fixed #26419 -- Added a link in ALLOWED_HOSTS docs.

Backport of f8b31dfd from master
parent dd1ab149
Loading
Loading
Loading
Loading
+2 −3
Original line number Diff line number Diff line
@@ -65,9 +65,8 @@ See :doc:`/howto/error-reporting` for more information.
Default: ``[]`` (Empty list)

A list of strings representing the host/domain names that this Django site can
serve. This is a security measure to prevent an attacker from poisoning caches
and triggering password reset emails with links to malicious hosts by submitting
requests with a fake HTTP ``Host`` header, which is possible even under many
serve. This is a security measure to prevent :ref:`HTTP Host header attacks
<host-headers-virtual-hosting>`, which are possible even under many
seemingly-safe web server configurations.

Values in this list can be fully qualified names (e.g. ``'www.example.com'``),