Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Origin validation is disabled unless allowedOrigins is configured

Open
#209 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
3/5
Estimated time
1-2 days
Newbie friendliness
58/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
typescript
Domain
security

Research direction

Start by reading src/security.ts and src/routes/mcp.ts, then find the tests covering isOriginAllowed and the POST /mcp 403 path. Verify the existing behavior when allowedOrigins is configured before implementing the proposed default checks. Done means disallowed origins are rejected by default, localhost and the server's own host are accepted, requests without an Origin are unaffected, and the explicit opt-outs still work; include the release-note change.

Written by the indexing model from the issue text.

Description

transports-streamable-http.md says servers MUST validate the Origin header on all incoming connections to prevent DNS rebinding.

isOriginAllowed in src/security.ts returns true when allowedOrigins is undefined, and src/routes/mcp.ts only logs a warning in that case. A default deployment therefore accepts POST /mcp from Origin: https://evil.example. When allowedOrigins is set, the 403 path works correctly.

Proposal: secure by default. When allowedOrigins is unset, reject requests whose Origin is present and not localhost or the server's own host, and keep allowedOrigins: true / '*' as the explicit opt-out. Requests without an Origin header (non-browser clients) are unaffected. This changes behaviour for browser clients on other origins, so it should be called out in the release notes.

Found while reviewing #170. Already present on main.

Dominant language
TypeScript
Stars
58
Forks
13
Avg merge
4h 50m
Merged PRs (30d)
10

Getting set up

  • Ships a Dockerfile or Docker Compose file
  • No pull request template
  • No contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from platformatic/mcp

All issues in platformatic/mcp

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.