Change record status: 
Project: 
Introduced in branch: 
8.0.x
Introduced in version: 
8.0.0-BETA13
Description: 

Previously it was possible to enforce the $base_url from within settings.php. This was required in order to prevent cache poisoning and URL spoofing (see #2221699: HTTP_HOST header cannot be trusted), but that issue has been resolved by introducing the trusted_host_patterns setting (see change record).

The option to enforce $base_url from within settings.php is now removed.

Alternatives are to rewrite the request url with the help of .htaccess files.

To specify where files including CSS/JS are loaded from, use $settings['file_public_base_url'] in settings.php.

Tip: You can define a Drush site alias with the 'uri' option:
drush uli --uri=https://example.org
... or
drush search-api:index --uri=https://example.org

Another notation for 'uli' command:
drush uli -l https://example.org

drushrc.php: To let Drush know the domain, add this in your sites/default/drushrc.php file. (Note: Doesn't seem to work in Drush 10 ...):

$options['uri'] = 'http://example.com';
Impacts: 
Site builders, administrators, editors

Comments

rex.barkdoll’s picture

Hi, I ran into this page because my Drupal 8 site was sending out emails where all the links pointed to http://default or https://default and I was having a hard time understanding how to change that.

After attempting the changes on this page, I finally discovered that, while it's not recommended, sometimes you need to set the drush.yml file's options > uri setting.

The recommended location for the drush.yml file is /web/sites/default/drush.yml but that one seemed to get ignored on my site and I had to set the one here: /vendor/drush/drush/drush.yml

you can check the location of what yml files drush is looking at by running drush status. In the printout from that, it'll list Site URI and Drush configs which will be relevant to what you're changing here.

After I updated the yml file, I cleared cache, retested the emails and things started linking properly pointing to my site instead of default.

I think in the old days, this could all be solved by setting the $base_url, but now it's done using a method similar to the one I explained above. Hope this helps someone down the road.

jweowu’s picture

I'm assuming this was a cron job?

Such tasks ought to specify the correct --uri=URL option as part of the drush command.

In general I recommend arranging (whether by configuration, aliases, or wrapper scripts) that *any* time you run drush, it will be provided with the correct URL -- for whichever site it is being used with on that occasion.

ressa’s picture

Maybe $base_url can be restored? See #3504766: Allow defining a base URL.