Share a Rails dev server and fix Blocked hosts
Rails checks X-Forwarded-Host as well as Host, so a shared dev server says Blocked hosts. One line fixes it, and forms and Action Cable work.
Updated
Of the dev servers in these guides, Rails is the one that needs a setting before its first page through a link: its host check reads X-Forwarded-Host as well as Host, and turns the public name away. Add .ouicu.app to config.hosts and the rest works through the link: forms, redirects and Action Cable.
| Rails | |
|---|---|
| Dev server port | 3000 |
| On your Wi-Fi | bin/rails server -b 0.0.0.0 |
| Host check | config.hosts |
Blocked hosts
Open the app through a ouicu link and every page is 403 Forbidden, headed and followed by:
Blocked hosts: calm-otter-4821.ouicu.appTo allow requests to these hosts, make sure they are valid hostnames (containing only numbers, letters, dashes and dots), then add the following to your environment configuration:The check came in Rails 6.0, whose release notes say: “Add ActionDispatch::HostAuthorization middleware that guards against DNS rebinding attacks.” In development it lets in any IPv4 or IPv6 address, and localhost. ouicu sets Host to localhost:3000, which passes, but also sends the public name in X-Forwarded-Host, and Rails checks the last X-Forwarded-Host too. The host checks in Vite, Next.js and Django read only Host, so theirs pass as they come.
| Through the link | What it takes |
|---|---|
| The page | Needs config.hosts << ".ouicu.app" |
| Hot reload | Nothing to test |
| A form POST | Works, nothing to change |
Allow the name in config.hosts
Add one line to config/environments/development.rb and restart the server:
Rails.application.configure do # ... config.hosts << ".ouicu.app"endThe leading dot allows every name under ouicu.app; with a reserved name, list just yours, like "studiolund.ouicu.app". Or leave the file alone and set the variable Rails reads in development, RAILS_DEVELOPMENT_HOSTS:
RAILS_DEVELOPMENT_HOSTS=.ouicu.app bin/rails serverForms, redirects and Action Cable
With the name allowed, a scaffold's form posts, its authenticity token passes, and the redirect after it lands on https://calm-otter-4821.ouicu.app/posts/1 with “Post was successfully created.” Nothing else to set.
Action Cable's socket at /cable connects too. Its guide says:
“By default, Action Cable allows all requests from localhost:3000 when running in the development environment.”
ouicu hands each WebSocket the origin http://localhost:3000, so it passes. Through a tunnel that keeps the browser's origin, the socket is refused and the log says:
Request origin not allowed: https://calm-otter-4821.ouicu.appThere the fix is Action Cable's own list, allowed_request_origins under config.action_cable.
Share bin/rails server with ouicu
Start the server, then share its port in a second terminal. Getting started has the install.
bin/rails server# in a second terminalouicu share 3000In development Rails listens on localhost only (Listening on http://127.0.0.1:3000), which is all ouicu needs. With another app on port 3000 already, start this one with -p 3001 and share 3001 instead. On Free, a share runs for up to 2 hours.
For a phone on the same Wi-Fi without a link, start it with bin/rails server -b 0.0.0.0; development already allows IP addresses. The QR code ouicu prints works on any network (QR codes, how to open localhost on your phone).
Privacy, and what the link won't carry
Everyone with the link reaches every route your app has, and in development Rails shows them its full error pages, your code included. To keep a preview to one client, ask for a password, on Hobby and Pro:
ouicu share 3000 --passwordOn Pro you can name the people allowed in instead, with --allow. Both stop visitors at ouicu, before Rails sees the request, so config.hosts has nothing to do with it.
The link carries web pages and WebSockets. Active Storage videos and PDFs, send_file downloads and anything over 50 MB are kept back, and your terminal says what was (what isn't passed on). Images, styles, scripts and Turbo's page loads pass as usual.
Reloading, and why not upload
A new Rails app has no hot reload: Rails reloads your code on the next request, and you reload the page. ouicu deploy uploads static files only, and a Rails app renders on the server (Uploading a built site). To show a client, share the server while you talk it through; see show a client a website before it goes live.
Tested with Rails 8.1.4 on , with Ruby 4.0.7: rails new with a scaffold, served by bin/rails server and shared with ouicu share through ouicu's edge: the page before and after each fix, a form post, and Action Cable's socket, in Chromium at the https link, with Ruby in the official ruby Docker image.
Sources
Prices, defaults and quotes about other products, and the day each was last checked at its source.
- The Rails Command Line, Rails Guides. Checked .
- Configuring Rails Applications, Rails Guides. Checked .
- host_authorization.rb, Rails on GitHub. Checked .
- blocked_host.html.erb, Rails on GitHub. Checked .
- Ruby on Rails 6.0 Release Notes, Rails Guides. Checked .
- Action Cable Overview, Rails Guides. Checked .
- action_cable/server/base.rb, Rails on GitHub. Checked .