Hacktoberfest 2026: as issues que os mantenedores marcaram para outubro, abertas e boas para iniciantes. Ver issues do Hacktoberfest

Validate `Host` and `Origin` independently in `DnsRebindingProtectionMiddleware`

Aberta
#522 0 comentários 1 reação 0 responsáveis Ver no GitHub

Mantenedores costumam responder em até 1 dia

Ninguém assumiu esta issue ainda.

Avaliação

Dificuldade
4/5
Tempo estimado
3-5 dias
Facilidade para iniciantes
48/100
Tipo de issue
Funcionalidade
Clareza
Razoavelmente clara
Status de atividade
Ativa
Stack de tecnologia
php
Domínio
backend, security

Direção de pesquisa

Start by locating DnsRebindingProtectionMiddleware and reading its current handling of the Host and Origin headers. The issue raises two alternative designs and does not identify files or tests; first determine the project’s existing middleware and test conventions. Done means validating Host on every request and, if present, Origin separately with its own allowlist, including scheme and port.

Escrita pelo modelo de indexação a partir do texto da issue.

Descrição

bug

The current DnsRebindingProtectionMiddleware handles Host and Origin as alternatives:

  • If an Origin header is present, only its hostname is checked.
  • Otherwise, the Host header is checked.
  • Both values are checked against the same allowedHosts list.

This causes several issues:

  • An invalid Host header is not rejected when an allowed Origin header is present.
  • Host and Origin represent different parties: Host identifies the target MCP server, while Origin identifies the web origin initiating the request. They commonly have different values and therefore require separate allowlists.
  • Origin validation is reduced to the hostname. This makes it impossible to distinguish origins by scheme or port, even though those are part of the web-origin tuple.

Would it make sense to either:

  1. Split this into separate Host and Origin validation middleware; or
  2. Extend DnsRebindingProtectionMiddleware with separate allowedHosts and allowedOrigins options, validating Host on every request and additionally validating Origin whenever it is present?

I would be happy to submit a pull request if this direction is acceptable.

Linguagem predominante
PHP
Estrelas
1.6k
Forks
173
Merge médio
19h 19min
PRs com merge (30d)
8

Preparar o ambiente

Primeiros passos

  1. Leia a issue inteira e depois o guia de contribuição do projeto.
  2. Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
  3. Faça um fork do repositório e trabalhe em uma branch.
  4. Abra um pull request que referencie o número da issue.

Mais de modelcontextprotocol/php-sdk

Todas as issues de modelcontextprotocol/php-sdk

Issues semelhantes

Mais issues de PHP

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.