Origin validation is disabled unless allowedOrigins is configured
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 58/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- typescript
- Domain
- security
Research direction
Start by reading src/security.ts and src/routes/mcp.ts, then find the tests covering isOriginAllowed and the POST /mcp 403 path. Verify the existing behavior when allowedOrigins is configured before implementing the proposed default checks. Done means disallowed origins are rejected by default, localhost and the server's own host are accepted, requests without an Origin are unaffected, and the explicit opt-outs still work; include the release-note change.
Written by the indexing model from the issue text.
Description
transports-streamable-http.md says servers MUST validate the Origin header on all incoming connections to prevent DNS rebinding.
isOriginAllowed in src/security.ts returns true when allowedOrigins is undefined, and src/routes/mcp.ts only logs a warning in that case. A default deployment therefore accepts POST /mcp from Origin: https://evil.example. When allowedOrigins is set, the 403 path works correctly.
Proposal: secure by default. When allowedOrigins is unset, reject requests whose Origin is present and not localhost or the server's own host, and keep allowedOrigins: true / '*' as the explicit opt-out. Requests without an Origin header (non-browser clients) are unaffected. This changes behaviour for browser clients on other origins, so it should be called out in the release notes.
Found while reviewing #170. Already present on main.
- Dominant language
- TypeScript
- Stars
- 58
- Forks
- 13
- Avg merge
- 4h 50m
- Merged PRs (30d)
- 10
Getting set up
- Ships a Dockerfile or Docker Compose file
- No pull request template
- No contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from platformatic/mcp
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
platformatic/mcp#216 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
platformatic/mcp#214 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
platformatic/mcp#213 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
platformatic/mcp#208 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
platformatic/mcp#207 ·
Maintainers usually reply within 1 day
All issues in platformatic/mcp
Similar issues
-
Difficulty 1/5 Under an hour Newbie friendliness 85/100
lukilabs/beautiful-mermaid#160 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 66/100
rescript-lang/rescript-lang.org#1420 ·
Maintainers usually reply within 2 days
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
chthollyphile/folia-major#520 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
databuddy-analytics/Databuddy#1106 ·
Maintainers usually reply within 1 day