fix(transport-security): compare Host and Origin case-insensitively (#3437) - #3455
Conversation
…odelcontextprotocol#3437) Normalize host and origin headers and allowed entries to lowercase per RFC 9110 and RFC 6454 so uppercase host configurations (e.g. %COMPUTERNAME% on Windows) correctly match fetch-based lowercase clients.
|
This PR has been closed automatically. This repo only keeps pull requests open when they come from a maintainer, or from a contributor a maintainer has assigned to the linked issue, and you aren't currently assigned to #3437. If a maintainer assigns you to #3437, this PR reopens on its own and there's nothing more you need to do here. Assignment is a maintainer call based on capacity; comments that only ask to be assigned don't factor in. What does help is engaging on the issue itself by confirming the repro, explaining why it matters for your use case, or describing the approach you'd take. You're welcome to keep pushing commits here (just avoid force-pushing, since GitHub can't reopen a rewritten branch), but that on its own won't get the PR reviewed or the issue assigned, and realistically most auto-closed PRs stay closed. There's no need to open a new PR either way. CONTRIBUTING.md has the full reasoning, but in short:
Maintainers: reopen, remove |
Summary
Fixes #3437.
TransportSecurityMiddleware._validate_host()and_validate_origin()previously compared incomingHostandOriginheaders againstallowed_hostsandallowed_originscase-sensitively.Per RFC 9110 §4.2.3 and RFC 6454 §4:
Every WHATWG URL-based HTTP client (browsers, Node
fetch,undici, andmcp-remote) automatically lowercases hostnames before transmitting them. On Windows, where%COMPUTERNAME%is uppercase by default, configuringallowed_hosts=["MYHOST:*"]caused all incoming requests from standard fetch clients (e.g.Host: myhost:8000) to be rejected with421 Misdirected Request.Changes
src/mcp/server/transport_security.py:_validate_host(): Lowercases both the incomingHostheader andallowed_hostsitems before exact and wildcard-port comparisons._validate_origin(): Lowercases both the incomingOriginheader andallowed_originsitems before exact and wildcard-port comparisons.tests/server/test_transport_security.py:HostandOriginvalues against lowercase allowlists.test_validate_request_case_insensitive_uppercase_settingsasserting that uppercase allowlist configurations (such as Windows%COMPUTERNAME%) correctly permit lowercase client requests.Verification
uv run pytest tests/server/test_transport_security.py: 31/31 passed in 0.11s.uv run ruff checkanduv run ruff format --check: 100% clean.