Block Malicious URL Entry
Block the destination hostname, not zws.im. Production defaults to Railway environment production, service API.
Procedure
- Provide the known hostname, destination URL, or
zws.imshort URL. Stop if the hostname is ambiguous or belongs to a shared platform. - Run
railway statusand confirm projectzws, environmentproduction, and serviceAPI. - From
apps/api, runrailway run --service API --environment production -- node scripts/block-malicious-url.ts --dry-run --hostname '<hostname>'(or pass--url/--target-url). Review the resolved hostname and whether it is already blocked. - After approval, repeat with
--apply. The script inserts the hostname, refreshes Redis, and verifies the supplied short URL when--urlis used.
The script intentionally does not bulk-update urls.blocked: retrieval checks the hostname block and lazily marks each matching row. Never print connection strings, credentials, or full environment output. Confirm the resolved hostname before applying.