Rails 'unsafe redirect' from strange curl request

Viewed 18

I am getting occasional errors of this type in production and staging:

Unsafe redirect to "https://${ip}:${port}/businesses/new", pass allow_other_host: true to redirect anyway.

It is being caused by Curl requests from a random IP:

User-Agent: "curl/7.64.1"
Accept: "*/*"
Host: "${ip}:${port}"
Version: "HTTP/1.1"

I do not get it with any other URLs processed within the app.

When I try the same curl request in development I get this (which is correct):

Rails - [ActionDispatch::HostAuthorization::DefaultResponseApp] Blocked host: "${ip}:${port}"

I cannot find where the difference is that makes this throw an exception in production.

Any insights on this issue would be appreciated.

0 Answers
Related