HTTP mode: empty `--listen-host` binds all interfaces while CORS is `*` and SDK CrossOriginProtection is left unset |
まだ誰も着手していません。
評価
- 難易度
- 3/5
- 見積もり時間
- 1〜2日
- 初心者へのやさしさ
- 55/100
調査の方向性
Review cmd/github-mcp-server/main.go for the flag definition and pkg/http/server.go for resolveListenAddress. Examine pkg/http/middleware/cors.go for CORS headers and pkg/http/handler.go for cross-origin protection. Understand the interaction of these defaults and propose a change to one or more, ensuring the server still works for browser-based MCP clients. Test by running the server locally and verifying binding and CORS behavior.
索引モデルが issue の本文から書いたものです。
説明
Static review of public source at commit 85598ba6e125. No traffic was sent to any GitHub MCP environment.
Three HTTP-mode defaults stack toward a wide browser-reachable surface:
- Empty listen host binds all interfaces:
cmd/github-mcp-server/main.go:
httpCmd.Flags().String("listen-host", "", "Host the HTTP server binds to (e.g. 127.0.0.1). Empty binds to all interfaces.")
pkg/http/server.go (resolveListenAddress): empty host → ":%d".
- CORS always reflects any origin and explicitly allows
Authorization:
pkg/http/middleware/cors.go:
w.Header().Set("Access-Control-Allow-Origin", "*")
// ...
// corsAllowedRequestHeaders includes headers.AuthorizationHeader
Comment notes bearer tokens (not cookies). That is fair for ambient-cookie CSRF; it still means any origin can drive credentialed MCP calls if a token is available to page JS.
- Streamable HTTP leaves go-sdk cross-origin protection unset (nil = disabled as of go-sdk v1.6.0):
pkg/http/handler.go:
// Cross-origin protection is intentionally left unset: this server
// authenticates via bearer tokens (not cookies), so Sec-Fetch-Site CSRF
// checks are unnecessary and would block browser-based MCP clients.
Suggested change (pick a least-surprise default):
- Default
--listen-hostto127.0.0.1for local/dev; require an explicit empty/0.0.0.0for all-interfaces. - Or keep all-interfaces for “remote” installs but document/require a non-empty listen host in the HTTP quickstart.
- Optionally allow configuring ACAO allowlists for non-public deployments; keep
*only when intentionally public.
Severity: low–medium / defense-in-depth and insecure default for local HTTP mode. Bearer auth remains the primary control; this is about reducing accidental exposure. No proof-of-concept.
Happy to send a focused PR if this direction is useful.
- 主要言語
- Go
- スター
- 33.1k
- フォーク
- 5k
- 平均マージ
- 2日 1時間
- マージ済み PR(30日)
- 25
コントリビューションガイド
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
github/github-mcp-server のほかの issue
-
bug
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
github/github-mcp-server#3235 ·
-
enhancement
難易度 1/5 1時間未満 初心者へのやさしさ 88/100
github/github-mcp-server#3042 · コメント 2 件 ·
-
bug
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
github/github-mcp-server#3032 · リアクション 1 件 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 74/100
github/github-mcp-server#2803 · コメント 1 件 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
github/github-mcp-server#2740 ·
github/github-mcp-server の issue をすべて見る
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 65/100
-
bug group: validation priority: low
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
codecheckers/chekhov#51 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100