@stux @i3x No, that header says "It's OK to access from X" and X should be the hostname where your users see the web interface
@Gargron @i3x Aha, but shouldn't localhost be always allowed? the hostname is simply mstdn.social
@Gargron @i3x Aha, but shouldn't localhost be always allowed? the hostname is simply mstdn.social