Hacktoberfest 2026: die Issues, die Maintainer für den Oktober markiert haben – offen und einsteigerfreundlich. Hacktoberfest-Issues durchsuchen

HTTP mode: empty `--listen-host` binds all interfaces while CORS is `*` and SDK CrossOriginProtection is left unset |

Offen
#3,327 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Dieses Issue hat noch niemand übernommen.

Bewertung

Schwierigkeit
3/5
Geschätzter Aufwand
1-2 Tage
Anfängerfreundlichkeit
55/100
Issue-Typ
Bug
Klarheit
Klar beschrieben
Aktivitätsstatus
Aktiv
Tech-Stack
go
Bereich
api, backend, security

Rechercherichtung

Review cmd/github-mcp-server/main.go for the flag definition and pkg/http/server.go for resolveListenAddress. Examine pkg/http/middleware/cors.go for CORS headers and pkg/http/handler.go for cross-origin protection. Understand the interaction of these defaults and propose a change to one or more, ensuring the server still works for browser-based MCP clients. Test by running the server locally and verifying binding and CORS behavior.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Beschreibung

Static review of public source at commit 85598ba6e125. No traffic was sent to any GitHub MCP environment.

Three HTTP-mode defaults stack toward a wide browser-reachable surface:

  1. Empty listen host binds all interfaces:

cmd/github-mcp-server/main.go:

httpCmd.Flags().String("listen-host", "", "Host the HTTP server binds to (e.g. 127.0.0.1). Empty binds to all interfaces.")

pkg/http/server.go (resolveListenAddress): empty host → ":%d".

  1. CORS always reflects any origin and explicitly allows Authorization:

pkg/http/middleware/cors.go:

w.Header().Set("Access-Control-Allow-Origin", "*")
// ...
// corsAllowedRequestHeaders includes headers.AuthorizationHeader

Comment notes bearer tokens (not cookies). That is fair for ambient-cookie CSRF; it still means any origin can drive credentialed MCP calls if a token is available to page JS.

  1. Streamable HTTP leaves go-sdk cross-origin protection unset (nil = disabled as of go-sdk v1.6.0):

pkg/http/handler.go:

// Cross-origin protection is intentionally left unset: this server
// authenticates via bearer tokens (not cookies), so Sec-Fetch-Site CSRF
// checks are unnecessary and would block browser-based MCP clients.

Suggested change (pick a least-surprise default):

  • Default --listen-host to 127.0.0.1 for local/dev; require an explicit empty/0.0.0.0 for all-interfaces.
  • Or keep all-interfaces for “remote” installs but document/require a non-empty listen host in the HTTP quickstart.
  • Optionally allow configuring ACAO allowlists for non-public deployments; keep * only when intentionally public.

Severity: low–medium / defense-in-depth and insecure default for local HTTP mode. Bearer auth remains the primary control; this is about reducing accidental exposure. No proof-of-concept.

Happy to send a focused PR if this direction is useful.

Vorherrschende Sprache
Go
Sterne
33.1k
Forks
5k
Ø Merge
2 T. 1 Std.
Gemergte PRs (30 T.)
25

Beitragsleitfaden

Beitragsleitfaden öffnen

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus github/github-mcp-server

Alle Issues in github/github-mcp-server

Ähnliche Issues

Weitere Issues zu Go

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.