memos/server
johnnyjoygh 8fa2ff4423 fix(mcp): allow reverse-proxied instances to serve /mcp
The go-sdk Streamable HTTP handler enables DNS-rebinding protection that
rejects any request whose Host header is non-loopback while the server is
bound to a loopback address. memos is commonly run bound to loopback behind a
reverse proxy (e.g. the public demo), so every /mcp request was rejected with
"403 Forbidden: invalid Host header" before authentication ran.

Disable the SDK's localhost protection and rely on memos' own Origin/Host
allowlist (isAllowedMCPOrigin) for CSRF / DNS-rebinding protection. Add a
regression test covering the proxied shape and confirming disallowed origins
are still rejected.
2026-06-21 22:20:00 +08:00
..
auth fix(auth): harden authorization and username validation (#5890) 2026-04-25 21:24:16 +08:00
notification feat(notification): add smtp email settings 2026-05-01 18:48:21 +08:00
router fix(mcp): allow reverse-proxied instances to serve /mcp 2026-06-21 22:20:00 +08:00
runner fix(s3presign): preserve motion media payload 2026-05-09 22:51:56 +08:00
cors.go fix(cors): open API to any origin for token auth, keep cookies same-origin 2026-06-14 23:20:34 +08:00
cors_test.go fix(cors): open API to any origin for token auth, keep cookies same-origin 2026-06-14 23:20:34 +08:00
server.go feat: add OpenAPI-driven MCP support (#6026) 2026-06-09 09:16:50 +08:00