Skip to the page

Share a Rails dev server and fix Blocked hosts

Rails checks X-Forwarded-Host as well as Host, so a shared dev server says Blocked hosts. One line fixes it, and forms and Action Cable work.

Updated

Of the dev servers in these guides, Rails is the one that needs a setting before its first page through a link: its host check reads X-Forwarded-Host as well as Host, and turns the public name away. Add .ouicu.app to config.hosts and the rest works through the link: forms, redirects and Action Cable.

Rails at a glance
Rails
Dev server port3000
On your Wi-Fibin/rails server -b 0.0.0.0
Host checkconfig.hosts

Blocked hosts

Open the app through a ouicu link and every page is 403 Forbidden, headed and followed by:

What the browser shows
Blocked hosts: calm-otter-4821.ouicu.appTo allow requests to these hosts, make sure they are valid hostnames (containing only numbers, letters, dashes and dots), then add the following to your environment configuration:

The check came in Rails 6.0, whose release notes say: “Add ActionDispatch::HostAuthorization middleware that guards against DNS rebinding attacks.” In development it lets in any IPv4 or IPv6 address, and localhost. ouicu sets Host to localhost:3000, which passes, but also sends the public name in X-Forwarded-Host, and Rails checks the last X-Forwarded-Host too. The host checks in Vite, Next.js and Django read only Host, so theirs pass as they come.

Rails through a ouicu link
Through the linkWhat it takes
The pageNeeds config.hosts << ".ouicu.app"
Hot reloadNothing to test
A form POSTWorks, nothing to change

Allow the name in config.hosts

Add one line to config/environments/development.rb and restart the server:

Rails.application.configure do  # ...  config.hosts << ".ouicu.app"end

The leading dot allows every name under ouicu.app; with a reserved name, list just yours, like "studiolund.ouicu.app". Or leave the file alone and set the variable Rails reads in development, RAILS_DEVELOPMENT_HOSTS:

RAILS_DEVELOPMENT_HOSTS=.ouicu.app bin/rails server

Forms, redirects and Action Cable

With the name allowed, a scaffold's form posts, its authenticity token passes, and the redirect after it lands on https://calm-otter-4821.ouicu.app/posts/1 with “Post was successfully created.” Nothing else to set.

Action Cable's socket at /cable connects too. Its guide says:

“By default, Action Cable allows all requests from localhost:3000 when running in the development environment.”

Rails Guides, Action Cable Overview

ouicu hands each WebSocket the origin http://localhost:3000, so it passes. Through a tunnel that keeps the browser's origin, the socket is refused and the log says:

In the server's log
Request origin not allowed: https://calm-otter-4821.ouicu.app

There the fix is Action Cable's own list, allowed_request_origins under config.action_cable.

Share bin/rails server with ouicu

Start the server, then share its port in a second terminal. Getting started has the install.

bin/rails server# in a second terminalouicu share 3000

In development Rails listens on localhost only (Listening on http://127.0.0.1:3000), which is all ouicu needs. With another app on port 3000 already, start this one with -p 3001 and share 3001 instead. On Free, a share runs for up to 2 hours.

For a phone on the same Wi-Fi without a link, start it with bin/rails server -b 0.0.0.0; development already allows IP addresses. The QR code ouicu prints works on any network (QR codes, how to open localhost on your phone).

Privacy, and what the link won't carry

Everyone with the link reaches every route your app has, and in development Rails shows them its full error pages, your code included. To keep a preview to one client, ask for a password, on Hobby and Pro:

ouicu share 3000 --password

On Pro you can name the people allowed in instead, with --allow. Both stop visitors at ouicu, before Rails sees the request, so config.hosts has nothing to do with it.

The link carries web pages and WebSockets. Active Storage videos and PDFs, send_file downloads and anything over 50 MB are kept back, and your terminal says what was (what isn't passed on). Images, styles, scripts and Turbo's page loads pass as usual.

Reloading, and why not upload

A new Rails app has no hot reload: Rails reloads your code on the next request, and you reload the page. ouicu deploy uploads static files only, and a Rails app renders on the server (Uploading a built site). To show a client, share the server while you talk it through; see show a client a website before it goes live.

Tested with Rails 8.1.4 on , with Ruby 4.0.7: rails new with a scaffold, served by bin/rails server and shared with ouicu share through ouicu's edge: the page before and after each fix, a form post, and Action Cable's socket, in Chromium at the https link, with Ruby in the official ruby Docker image.

Sources

Prices, defaults and quotes about other products, and the day each was last checked at its source.

  1. The Rails Command Line, Rails Guides. Checked .
  2. Configuring Rails Applications, Rails Guides. Checked .
  3. host_authorization.rb, Rails on GitHub. Checked .
  4. blocked_host.html.erb, Rails on GitHub. Checked .
  5. Ruby on Rails 6.0 Release Notes, Rails Guides. Checked .
  6. Action Cable Overview, Rails Guides. Checked .
  7. action_cable/server/base.rb, Rails on GitHub. Checked .