Browse Source

Fixed #26419 -- Added a link in ALLOWED_HOSTS docs.

Joshua Pereyda 9 years ago
parent
commit
f8b31dfdfc
1 changed files with 2 additions and 3 deletions
  1. 2 3
      docs/ref/settings.txt

+ 2 - 3
docs/ref/settings.txt

@@ -65,9 +65,8 @@ See :doc:`/howto/error-reporting` for more information.
 Default: ``[]`` (Empty list)
 
 A list of strings representing the host/domain names that this Django site can
-serve. This is a security measure to prevent an attacker from poisoning caches
-and triggering password reset emails with links to malicious hosts by submitting
-requests with a fake HTTP ``Host`` header, which is possible even under many
+serve. This is a security measure to prevent :ref:`HTTP Host header attacks
+<host-headers-virtual-hosting>`, which are possible even under many
 seemingly-safe web server configurations.
 
 Values in this list can be fully qualified names (e.g. ``'www.example.com'``),