Skip to content

fix(hub)!: close the discovery status oracle and tool name collisions - #19

Merged
TheGreatAxios merged 1 commit into
cl-9454-mcp-support-stateful-streamable-http-servers-and-harden-jsonfrom
cl-9455-mcp-close-the-discovery-status-oracle-and-tool-name
Sep 27, 2026
Merged

TheGreatAxios merged 1 commit into
cl-9454-mcp-support-stateful-streamable-http-servers-and-harden-jsonfrom
cl-9455-mcp-close-the-discovery-status-oracle-and-tool-name

Conversation

@TheGreatAxios

@TheGreatAxios TheGreatAxios commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

The discovery route accepted plain-http loopback URLs and echoed the upstream status in its 422, so a tenant member could use it to probe the hub's local ports. Catalogs could repeat a tool name, and a handle such as srv.read produced tool names covered by server srv's tool:srv.* grant.

Changes

  • New allowLoopback?: boolean on MountMcpDiscoveryOpts, off by default. Without it the route refuses a plain-http (loopback) URL with a 400 before any request.
  • McpError carries status for a non-2xx answer. The route reports that as "the server refused the request", without the status.
  • mcpListTools refuses a tools/list result with duplicate names. mcpTools and mcpServers refuse a catalog that repeats a tool name, or a server name or handle containing ., so <handle>.<tool> can never fall under another server's grant (assertCatalogNames in naming.ts).
  • mcpTools and mcpServers share one server-list check (assertServers in naming.ts): an empty or repeated name, or a URL parseMcpEndpoint rejects, is refused before any request.
  • Tests (each fails before the fix): loopback refused unless allowed, a 403 not echoed, duplicate names refused by tools/list and by the bundle, an overlapping handle refused, and mcpTools refusing an empty or duplicate name and a non-https URL with no request sent.
  • README documents allowLoopback, the naming rule and the upgrade notes.

Breaking

Yes, marked !: plain-http loopback discovery needs allowLoopback, and handles or server names containing . are refused. It is part of the pending 0.2.0 release, so there is no extra version bump.

Checks

bun run check, bun run test:e2e, bun run build and the Node pack smoke pass locally.

Closes CL-9455

@TheGreatAxios
TheGreatAxios added this pull request to stack #12 September 27, 2026 02:23
@TheGreatAxios
TheGreatAxios force-pushed the cl-9455-mcp-close-the-discovery-status-oracle-and-tool-name branch from c568a0a to cfe21d1 Compare September 27, 2026 02:44
@TheGreatAxios
TheGreatAxios force-pushed the cl-9455-mcp-close-the-discovery-status-oracle-and-tool-name branch 2 times, most recently from 8180eae to 02652f0 Compare September 27, 2026 18:35
The discovery route refuses plain-http loopback targets unless the host sets
allowLoopback, and reports an upstream non-2xx as a refusal without its
status. McpError carries that status. A catalog listing a tool name twice is
refused by tools/list, mcpTools and mcpServers, and a handle or server name
containing "." is refused so no tool falls under another server's grant.
mcpTools shares mcpServers' server-list check: an empty or repeated name, or
a non-https URL, is refused before any request.

BREAKING CHANGE: plain-http loopback discovery needs allowLoopback, and
handles or server names containing "." are refused.
@TheGreatAxios
TheGreatAxios force-pushed the cl-9455-mcp-close-the-discovery-status-oracle-and-tool-name branch from 02652f0 to 52c0c87 Compare September 27, 2026 18:49
@TheGreatAxios
TheGreatAxios merged commit 21cd8f0 into main Sep 27, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant