INNER CODE UNIT · Python

validate_host_header

ohdearquant/lionagi · lionagi/studio/app.py:267

async def validate_host_header(request: Request, call_next):
    """Reject requests whose Host header doesn't match an expected value —
    defends against DNS rebinding; see docs/internals/studio.md.
    """
    hostname = _parse_host_authority(request.headers.get("host", ""))
    bind_host = os.getenv("LIONAGI_STUDIO_HOST", HOST)
    allowed_hosts = {"localhost", "127.0.0.1", "::1"}
    if bind_host not in ("127.0.0.1", "localhost", "::1", "0.0.0.0", ""):  # noqa: S104
        allowed_hosts.add(bind_host.lower())
    if hostname is None or hostname not in allowed_hosts:
        return JSONResponse(
            {"detail": f"Invalid Host header: {request.headers.get('host', '')!r}"},
            status_code=400,
        )
    return await call_next(request)


def _mount_studio_routes(application: FastAPI) -> None:

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…