Hacktoberfest 2026: die Issues, die Maintainer für den Oktober markiert haben – offen und einsteigerfreundlich. Hacktoberfest-Issues durchsuchen

Validate `Host` and `Origin` independently in `DnsRebindingProtectionMiddleware`

Offen
#522 0 Kommentare 1 Reaktion 0 zugewiesene Personen Auf GitHub ansehen

Maintainer antworten meist innerhalb von 1 Tag

Dieses Issue hat noch niemand übernommen.

Bewertung

Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Anfängerfreundlichkeit
48/100
Issue-Typ
Feature
Klarheit
Größtenteils klar
Aktivitätsstatus
Aktiv
Tech-Stack
php
Bereich
backend, security

Rechercherichtung

Start by locating DnsRebindingProtectionMiddleware and reading its current handling of the Host and Origin headers. The issue raises two alternative designs and does not identify files or tests; first determine the project’s existing middleware and test conventions. Done means validating Host on every request and, if present, Origin separately with its own allowlist, including scheme and port.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Beschreibung

bug

The current DnsRebindingProtectionMiddleware handles Host and Origin as alternatives:

  • If an Origin header is present, only its hostname is checked.
  • Otherwise, the Host header is checked.
  • Both values are checked against the same allowedHosts list.

This causes several issues:

  • An invalid Host header is not rejected when an allowed Origin header is present.
  • Host and Origin represent different parties: Host identifies the target MCP server, while Origin identifies the web origin initiating the request. They commonly have different values and therefore require separate allowlists.
  • Origin validation is reduced to the hostname. This makes it impossible to distinguish origins by scheme or port, even though those are part of the web-origin tuple.

Would it make sense to either:

  1. Split this into separate Host and Origin validation middleware; or
  2. Extend DnsRebindingProtectionMiddleware with separate allowedHosts and allowedOrigins options, validating Host on every request and additionally validating Origin whenever it is present?

I would be happy to submit a pull request if this direction is acceptable.

Vorherrschende Sprache
PHP
Sterne
1.6k
Forks
173
Ø Merge
19 Std. 19 Min.
Gemergte PRs (30 T.)
8

Entwicklungsumgebung

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus modelcontextprotocol/php-sdk

Alle Issues in modelcontextprotocol/php-sdk

Ähnliche Issues

Weitere Issues zu PHP

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.