Skip to main content

2026 年 4 月 20 日

Host Checking

To frustrate host injection attacks, the Host header in each incoming request is checked against a list of expected host names.

Note: This topic applies to Horizon 8 versions 2306 and later, 2212.1 and later, 2209.1 and later, and 2111.2 and later.

In earlier releases of Horizon 8, this protection was deactivated by default. To manually deactivate Host Checking, add the entry allowUnexpectedHost=true tolocked.properties.

The list of expected host names includes the External URL (also known as the Secure Tunnel External URL), therefore direct connections to that name, as well as connections through a gateway configured to forward to that name, require no further configuration.

For additional expected names, as well as how to extend the list to load balancers, non-rewriting gateways and alternative canonical names, see see Origin Checking.

此页面对您有帮助吗?

对本主题提供反馈

本主题对您有帮助吗?

请勿填写任何个人信息或机密信息。

正在生成链接…