Domain whitelisting
Allow fetching images only from a pre-defined list of origins
Last updated
Allow fetching images only from a pre-defined list of origins
Last updated
Copyright © 2023 Scaleflex
As a reminder, a Cloudimage URL looks like this:
//token.cloudimg.io/original_image_url?operations&filters
By default, images from any origin domains can be resized by Cloudimage and the storage and traffic consumption generated by the images will count toward your plan's allowance. In the Cloudimage admin console, you can restrict the list of origin server URLs your token can transform images from.
If you are using Aliases and you have Domain whitelisting enabled, you have to include all aliases in the whitelisted domain list.
Log in to your Cloudimage admin console and navigate to Image settings / scroll down to Whitelisted domains: Configure your original image domains / S3 buckets.
Please note that when you whitelist eg. sample.li
, this will also whitelist all its subdomains sub1.sample.li
, www.sample.li
, etc.
By default, when delivering Static content, the domain whitelist is not respected. If you would like to restrict delivering static content to whitelisted domains only, you can enable the Honor whitelist when delivering static content option in the Admin console.
This Cloudimage URL works (the sample.li domain is whitelisted):
//doc.cloudimg.io/http://sample.li/boat.jpg?width=500
While this one does not:
//doc.cloudimg.io/pbs.twimg.com/profile_images/839721704163155970/LI_TRk1z_400x400.jpg?w=500