memos/server/router
johnnyjoygh 8fa2ff4423 fix(mcp): allow reverse-proxied instances to serve /mcp
The go-sdk Streamable HTTP handler enables DNS-rebinding protection that
rejects any request whose Host header is non-loopback while the server is
bound to a loopback address. memos is commonly run bound to loopback behind a
reverse proxy (e.g. the public demo), so every /mcp request was rejected with
"403 Forbidden: invalid Host header" before authentication ran.

Disable the SDK's localhost protection and rely on memos' own Origin/Host
allowlist (isAllowedMCPOrigin) for CSRF / DNS-rebinding protection. Add a
regression test covering the proxied shape and confirming disallowed origins
are still rejected.
2026-06-21 22:20:00 +08:00
..
api/v1 fix(instance): add needs_setup so admin-less instances aren't treated as fresh 2026-06-21 22:14:15 +08:00
fileserver fix(fileserver): preserve HDR image metadata in thumbnails 2026-04-29 21:32:10 +08:00
frontend chore: remove MCP server 2026-06-05 08:38:57 +08:00
mcp fix(mcp): allow reverse-proxied instances to serve /mcp 2026-06-21 22:20:00 +08:00
rss fix(memo): enforce parent visibility for comments 2026-05-08 23:22:56 +08:00