{"version":"2.1.290","anchor":"url-permission-patterns-reject-punycode-wildcard-hosts","canonical_anchor":"url-permission-patterns-reject-punycode-wildcard-hosts","heading":"Wildcard URL rules handle international domain names more safely","tier":"notice","area":"Permissions","scope":"both","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290\/e\/url-permission-patterns-reject-punycode-wildcard-hosts","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290","markdown":"### Wildcard URL rules handle international domain names more safely\n\nWildcard web address rules now protect punycode host names, and a rule with the wildcard inside part of a host name is refused\n\n**Unclear.** It is not clear whether every rule with a wildcard inside a host name part is refused, or only ones involving punycode.\n\n**What**\n\nPermission rules can allow or block web addresses using a wildcard, a placeholder that matches anything. Matching has changed:\n\n- Host name parts written in punycode are protected during matching. Punycode is how domain names with non-English letters are stored, as text starting with `xn--`.\n\n- A rule whose wildcard sits inside a single part of a host name is refused and matches nothing.\n\n**Why**\n\nThis tightens domain allow and deny rules so a wildcard cannot slip into a lookalike or international domain name it was not meant to cover.\n\n- Area: Permissions\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5\n- Scope: both\n- Heads-up: no"}