how to prevent any host to access api resources in rails code example Example: get and to rails @patient = Patient.find(params[:id])