INNER CODE UNIT · Python
validate_host_header
ohdearquant/lionagi · lionagi/studio/app.py:267
async def validate_host_header(request: Request, call_next):
"""Reject requests whose Host header doesn't match an expected value —
defends against DNS rebinding; see docs/internals/studio.md.
"""
hostname = _parse_host_authority(request.headers.get("host", ""))
bind_host = os.getenv("LIONAGI_STUDIO_HOST", HOST)
allowed_hosts = {"localhost", "127.0.0.1", "::1"}
if bind_host not in ("127.0.0.1", "localhost", "::1", "0.0.0.0", ""): # noqa: S104
allowed_hosts.add(bind_host.lower())
if hostname is None or hostname not in allowed_hosts:
return JSONResponse(
{"detail": f"Invalid Host header: {request.headers.get('host', '')!r}"},
status_code=400,
)
return await call_next(request)
def _mount_studio_routes(application: FastAPI) -> None: