mirror of
https://github.com/pi-hole/web.git
synced 2024-12-06 19:36:21 +01:00
Since the Host header is easily manipulated, we can only check if it's wrong and can't use it to validate that the client is authorized, only unauthorized. There's no need for the strict flag anymore because of this.