diff --git a/rowers/views/workoutviews.py b/rowers/views/workoutviews.py index 2ac31c68..bb405313 100644 --- a/rowers/views/workoutviews.py +++ b/rowers/views/workoutviews.py @@ -4406,7 +4406,7 @@ def workout_upload_api(request): # only allow local host hostt = request.get_host().split(':') - if hostt[0] not in ['localhost','127.0.0.1']: + if hostt[0] not in ['localhost','127.0.0.1','dev.rowsandall.com','rowsandall.com']: message = {'status':'false','message':'permission denied for host '+hostt[0]} return JSONResponse(status=403,data=message)