authorbrian avery <>2016-11-23 18:55:20 (GMT)
committerRichard Purdie <>2016-11-28 14:23:48 (GMT)
commitae9b341ecfcc60e970f29cfe04306411ad26c0cf (patch)
parent3bf928a3b6354bc09c87fcbf9e3972c8d368aaa3 (diff)
bitbake: bitbake: toaster: settings set ALLOWED_HOSTS to * in debug mode
This is a backport of 7c3a47ed8965c3a3eb90a9a4678d5caedbba6337 >From the commit to master: As of Django 1.8.16, Django is rejecting any HTTP_HOST header that is not on the ALLOWED_HOST list. We often need to reference the toaster server via a fqdn, if we start it via webport= for instance, and are hitting the server from a laptop. This change does reduce the protection from a DNS rebinding attack, however, if you are running the toaster server outside a protected network, you should be using the production instance. [YOCTO #10586] (Bitbake rev: 449dc9b955dfbe048e380f5ab9fd61c3d1489dad) Signed-off-by: brian avery <> Signed-off-by: Richard Purdie <>
# Update as of django 1.8.16 release, the '*' is needed to allow us to connect while running
# on hosts without explicitly setting the fqdn for the toaster server.
# See for info on ALLOWED_HOSTS
113# Previously this setting was not enforced if DEBUG was set but it is now.
114# The previous behavior was such that ALLOWED_HOSTS defaulted to ['localhost','','::1']
115# and if you bound to<port #> then accessing toaster as localhost or fqdn would both work.
116# To have that same behavior, with a fqdn explicitly enabled you would set
117# ALLOWED_HOSTS= ['localhost','','::1',''] for
118# Django >= 1.8.16. By default, we are not enforcing this restriction in
119# DEBUG mode.
120if DEBUG is True:
121 # this will allow connection via localhost,hostname, or fqdn
122 ALLOWED_HOSTS = ['*']
113 123
# Local time zone for this installation. Choices can be found here:
#