Mismatched network rules block session creation and updates
Under restricted network access, HTTP 400 is returned if allowed_domains for the enabled web tool contains a host outside allowed_hosts. The check applies both to session creation and to an update that adds such an entry.
Session creation fails with an HTTP 400 error if, under restricted network access, allowed_domains for the enabled web tool contains an entry outside allowed_hosts. A session update that adds such an entry also fails.
An entry in allowed_hosts without the *. prefix matches only the exact hostname. For example, docs.example.com is therefore not permitted by the entry example.com. The stated remedy is to add the relevant host to allowed_hosts or remove the entry from allowed_domains.
Why it matters
A mismatch between domain allowlists can prevent a session from being created or updated. When configuring web tools, subdomains therefore need to be checked too: allowing example.com alone does not cover docs.example.com.
Two audiences, two different impacts
What this means
For individuals
Developers have specific guidance for resolving an HTTP 400 error when configuring a session: check whether the entries in allowed_domains match the hosts permitted by allowed_hosts.
For a business
Business integrations that automatically create or update sessions with restricted network access may fail if the rules are inconsistent. Consistency between these settings therefore directly affects their operation.
DevelopmentCheck the original
Event sources
only one source so far · 1 publisher, 0 independent. We count feeds from the same owner only once.