Description
Staging and production apps on herokuapp.com subdomains should not be accessible, but currently are:
(https://staging-editor-api.raspberrypi.org and https://editor-api.raspberrypi.org should be used instead).
The application can be configured (via config.hosts
) to only respond to requests on specific (sub)domains, eg: https://github.com/RaspberryPiFoundation/experience-cs/blob/main/config/environments/production.rb#L78-L79
Note that review app URLs also need to be explicitly set in this case eg. https://github.com/RaspberryPiFoundation/experience-cs/blob/main/config/environments/production.rb#L82
Settings for this are here:
Metadata
Metadata
Assignees
Labels
No labels