HTTP mode: empty `--listen-host` binds all interfaces while CORS is `*` and SDK CrossOriginProtection is left unset |
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 3/5
- Tiempo estimado
- 1-2 días
- Aptitud para principiantes
- 55/100
Línea de trabajo
Review cmd/github-mcp-server/main.go for the flag definition and pkg/http/server.go for resolveListenAddress. Examine pkg/http/middleware/cors.go for CORS headers and pkg/http/handler.go for cross-origin protection. Understand the interaction of these defaults and propose a change to one or more, ensuring the server still works for browser-based MCP clients. Test by running the server locally and verifying binding and CORS behavior.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Static review of public source at commit 85598ba6e125. No traffic was sent to any GitHub MCP environment.
Three HTTP-mode defaults stack toward a wide browser-reachable surface:
- Empty listen host binds all interfaces:
cmd/github-mcp-server/main.go:
httpCmd.Flags().String("listen-host", "", "Host the HTTP server binds to (e.g. 127.0.0.1). Empty binds to all interfaces.")
pkg/http/server.go (resolveListenAddress): empty host → ":%d".
- CORS always reflects any origin and explicitly allows
Authorization:
pkg/http/middleware/cors.go:
w.Header().Set("Access-Control-Allow-Origin", "*")
// ...
// corsAllowedRequestHeaders includes headers.AuthorizationHeader
Comment notes bearer tokens (not cookies). That is fair for ambient-cookie CSRF; it still means any origin can drive credentialed MCP calls if a token is available to page JS.
- Streamable HTTP leaves go-sdk cross-origin protection unset (nil = disabled as of go-sdk v1.6.0):
pkg/http/handler.go:
// Cross-origin protection is intentionally left unset: this server
// authenticates via bearer tokens (not cookies), so Sec-Fetch-Site CSRF
// checks are unnecessary and would block browser-based MCP clients.
Suggested change (pick a least-surprise default):
- Default
--listen-hostto127.0.0.1for local/dev; require an explicit empty/0.0.0.0for all-interfaces. - Or keep all-interfaces for “remote” installs but document/require a non-empty listen host in the HTTP quickstart.
- Optionally allow configuring ACAO allowlists for non-public deployments; keep
*only when intentionally public.
Severity: low–medium / defense-in-depth and insecure default for local HTTP mode. Bearer auth remains the primary control; this is about reducing accidental exposure. No proof-of-concept.
Happy to send a focused PR if this direction is useful.
- Lenguaje dominante
- Go
- Estrellas
- 33.1k
- Forks
- 5k
- Merge medio
- 2 d 1 h
- PR fusionados (30 d)
- 25
Guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de github/github-mcp-server
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
github/github-mcp-server#3235 ·
-
enhancement
Dificultad 1/5 Menos de una hora Aptitud para principiantes 88/100
github/github-mcp-server#3042 · 2 comentarios ·
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
github/github-mcp-server#3032 · 1 reacción ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100
github/github-mcp-server#2803 · 1 comentario ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
github/github-mcp-server#2740 ·
Todos los issues de github/github-mcp-server
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 65/100
-
bug group: validation priority: low
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
codecheckers/chekhov#51 ·
-
Creating worktree from an existing remote branch with a slash in it, has unexpected behaviour Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100