fix(hub)!: close the discovery status oracle and tool name collisions - #19
Merged
TheGreatAxios merged 1 commit intoSep 27, 2026
Conversation
TheGreatAxios
added this pull request to stack #12
September 27, 2026 02:23
TheGreatAxios
force-pushed
the
cl-9455-mcp-close-the-discovery-status-oracle-and-tool-name
branch
from
September 27, 2026 02:44
c568a0a to
cfe21d1
Compare
TheGreatAxios
force-pushed
the
cl-9455-mcp-close-the-discovery-status-oracle-and-tool-name
branch
2 times, most recently
from
September 27, 2026 18:35
8180eae to
02652f0
Compare
The discovery route refuses plain-http loopback targets unless the host sets allowLoopback, and reports an upstream non-2xx as a refusal without its status. McpError carries that status. A catalog listing a tool name twice is refused by tools/list, mcpTools and mcpServers, and a handle or server name containing "." is refused so no tool falls under another server's grant. mcpTools shares mcpServers' server-list check: an empty or repeated name, or a non-https URL, is refused before any request. BREAKING CHANGE: plain-http loopback discovery needs allowLoopback, and handles or server names containing "." are refused.
TheGreatAxios
force-pushed
the
cl-9455-mcp-close-the-discovery-status-oracle-and-tool-name
branch
from
September 27, 2026 18:49
02652f0 to
52c0c87
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The discovery route accepted plain-http loopback URLs and echoed the upstream status in its 422, so a tenant member could use it to probe the hub's local ports. Catalogs could repeat a tool name, and a handle such as
srv.readproduced tool names covered by serversrv'stool:srv.*grant.Changes
allowLoopback?: booleanonMountMcpDiscoveryOpts, off by default. Without it the route refuses a plain-http (loopback) URL with a 400 before any request.McpErrorcarriesstatusfor a non-2xx answer. The route reports that as "the server refused the request", without the status.mcpListToolsrefuses atools/listresult with duplicate names.mcpToolsandmcpServersrefuse a catalog that repeats a tool name, or a server name or handle containing., so<handle>.<tool>can never fall under another server's grant (assertCatalogNamesinnaming.ts).mcpToolsandmcpServersshare one server-list check (assertServersinnaming.ts): an empty or repeated name, or a URLparseMcpEndpointrejects, is refused before any request.tools/listand by the bundle, an overlapping handle refused, andmcpToolsrefusing an empty or duplicate name and a non-https URL with no request sent.allowLoopback, the naming rule and the upgrade notes.Breaking
Yes, marked
!: plain-http loopback discovery needsallowLoopback, and handles or server names containing.are refused. It is part of the pending 0.2.0 release, so there is no extra version bump.Checks
bun run check,bun run test:e2e,bun run buildand the Node pack smoke pass locally.Closes CL-9455