Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Validate `Host` and `Origin` independently in `DnsRebindingProtectionMiddleware`

Aperta
#522 0 commenti 1 reazione 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
48/100
Tipo di issue
Funzionalità
Chiarezza
Abbastanza chiara
Stato di attività
Attiva
Stack tecnologico
php
Ambito
backend, security

Direzione di ricerca

Start by locating DnsRebindingProtectionMiddleware and reading its current handling of the Host and Origin headers. The issue raises two alternative designs and does not identify files or tests; first determine the project’s existing middleware and test conventions. Done means validating Host on every request and, if present, Origin separately with its own allowlist, including scheme and port.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

bug

The current DnsRebindingProtectionMiddleware handles Host and Origin as alternatives:

  • If an Origin header is present, only its hostname is checked.
  • Otherwise, the Host header is checked.
  • Both values are checked against the same allowedHosts list.

This causes several issues:

  • An invalid Host header is not rejected when an allowed Origin header is present.
  • Host and Origin represent different parties: Host identifies the target MCP server, while Origin identifies the web origin initiating the request. They commonly have different values and therefore require separate allowlists.
  • Origin validation is reduced to the hostname. This makes it impossible to distinguish origins by scheme or port, even though those are part of the web-origin tuple.

Would it make sense to either:

  1. Split this into separate Host and Origin validation middleware; or
  2. Extend DnsRebindingProtectionMiddleware with separate allowedHosts and allowedOrigins options, validating Host on every request and additionally validating Origin whenever it is present?

I would be happy to submit a pull request if this direction is acceptable.

Lingua principale
PHP
Stelle
1.6k
Fork
173
Merge medio
19h 19m
PR unite (30g)
8

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di modelcontextprotocol/php-sdk

Tutte le issue di modelcontextprotocol/php-sdk

Issue simili

Altre issue su PHP

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.