Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

security: reconsider auth/CORS posture for state-changing /altimate/mcp/reload-datamate

Open
#956 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
35/100
Issue type
Feature
Clarity
Needs clarification
Activity status
Quiet
Tech stack
typescript

Research direction

Start with the /altimate/mcp/reload-datamate endpoint added in #893, then trace the shared auth and CORS handling for existing routes, including the OPENCODE_SERVER_PASSWORD behavior. Review both proposed directions with maintainers; done requires an agreed design, implementation scope, and tests covering state-changing requests.

Written by the indexing model from the issue text.

Description

Found during the v0.8.8 release review (CTO, P2 deferred).

POST /altimate/mcp/reload-datamate (added in #893) is a state-changing endpoint that re-reads IDE mcp.json from disk and calls MCP.add() to (re)connect MCP clients with whatever command/url those files contain. With no OPENCODE_SERVER_PASSWORD set (the default, loopback bind + startup warning only), any local process — including a browser page the CORS policy reflects http://localhost:* / http://127.0.0.1:* for — can POST to it and trigger a reconnect.

This is the same auth posture as all existing routes (not a new exposure class), but reload-datamate is more side-effectful (spawns/reconnects transports) than the read routes, so it warrants a closer look.

Possible directions: require auth for state-changing /altimate/* routes even when the global password is unset, or tighten the CORS reflection for those routes. Deferred — design decision, not an in-diff edit, and default bind is loopback.

Dominant language
TypeScript
Stars
813
Forks
134
Avg merge
2d 3h
Merged PRs (30d)
65

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from AltimateAI/altimate-code

All issues in AltimateAI/altimate-code

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.