Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

HTTP mode: empty `--listen-host` binds all interfaces while CORS is `*` and SDK CrossOriginProtection is left unset |

Abierto
#3,327 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
3/5
Tiempo estimado
1-2 días
Aptitud para principiantes
55/100
Tipo de issue
Error
Claridad
Bien especificado
Estado de actividad
Activo
Stack tecnológico
go
Área
api, backend, security

Línea de trabajo

Review cmd/github-mcp-server/main.go for the flag definition and pkg/http/server.go for resolveListenAddress. Examine pkg/http/middleware/cors.go for CORS headers and pkg/http/handler.go for cross-origin protection. Understand the interaction of these defaults and propose a change to one or more, ensuring the server still works for browser-based MCP clients. Test by running the server locally and verifying binding and CORS behavior.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

Static review of public source at commit 85598ba6e125. No traffic was sent to any GitHub MCP environment.

Three HTTP-mode defaults stack toward a wide browser-reachable surface:

  1. Empty listen host binds all interfaces:

cmd/github-mcp-server/main.go:

httpCmd.Flags().String("listen-host", "", "Host the HTTP server binds to (e.g. 127.0.0.1). Empty binds to all interfaces.")

pkg/http/server.go (resolveListenAddress): empty host → ":%d".

  1. CORS always reflects any origin and explicitly allows Authorization:

pkg/http/middleware/cors.go:

w.Header().Set("Access-Control-Allow-Origin", "*")
// ...
// corsAllowedRequestHeaders includes headers.AuthorizationHeader

Comment notes bearer tokens (not cookies). That is fair for ambient-cookie CSRF; it still means any origin can drive credentialed MCP calls if a token is available to page JS.

  1. Streamable HTTP leaves go-sdk cross-origin protection unset (nil = disabled as of go-sdk v1.6.0):

pkg/http/handler.go:

// Cross-origin protection is intentionally left unset: this server
// authenticates via bearer tokens (not cookies), so Sec-Fetch-Site CSRF
// checks are unnecessary and would block browser-based MCP clients.

Suggested change (pick a least-surprise default):

  • Default --listen-host to 127.0.0.1 for local/dev; require an explicit empty/0.0.0.0 for all-interfaces.
  • Or keep all-interfaces for “remote” installs but document/require a non-empty listen host in the HTTP quickstart.
  • Optionally allow configuring ACAO allowlists for non-public deployments; keep * only when intentionally public.

Severity: low–medium / defense-in-depth and insecure default for local HTTP mode. Bearer auth remains the primary control; this is about reducing accidental exposure. No proof-of-concept.

Happy to send a focused PR if this direction is useful.

Lenguaje dominante
Go
Estrellas
33.1k
Forks
5k
Merge medio
2 d 1 h
PR fusionados (30 d)
25

Guía de contribución

Abrir la guía de contribución

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de github/github-mcp-server

Todos los issues de github/github-mcp-server

Issues similares

Más issues de Go

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.