function drupal_valid_http_host

7.x drupal_valid_http_host($host)
5.x drupal_valid_http_host($host)
6.x drupal_valid_http_host($host)

Validates that a hostname (for example $_SERVER['HTTP_HOST']) is safe.

Return value

TRUE if only containing valid characters, or FALSE otherwise.

2 calls to drupal_valid_http_host()
BootstrapIPAddressTestCase::testIPAddressHost in drupal/modules/simpletest/tests/bootstrap.test
test IP Address and hostname
drupal_environment_initialize in drupal/includes/
Initializes the PHP environment.


drupal/includes/, line 711
Functions that need to be loaded on every Drupal request.


function drupal_valid_http_host($host) {
  // Limit the length of the host name to 1000 bytes to prevent DoS attacks with
  // long host names.
  return strlen($host) <= 1000
  // Limit the number of subdomains and port separators to prevent DoS attacks
  // in conf_path().
  && substr_count($host, '.') <= 100 && substr_count($host, ':') <= 100 && preg_match('/^\[?(?:[a-zA-Z0-9-:\]_]+\.?)+$/', $host);