From 7b8f855616d371f1f3a3374568518265b42046b3 Mon Sep 17 00:00:00 2001 From: dongsk Date: Wed, 2 Sep 2026 18:38:46 +0800 Subject: [PATCH] fix: allow public host in MCP transport security --- src/server.py | 27 ++++++++++++++++++++++++--- 1 file changed, 24 insertions(+), 3 deletions(-) diff --git a/src/server.py b/src/server.py index 18e4a67..77df6a9 100644 --- a/src/server.py +++ b/src/server.py @@ -16,8 +16,11 @@ MCP Server Demo — 单服务实例,三 MCP 模组 from contextlib import asynccontextmanager import uvicorn +import os +from urllib.parse import urlparse from starlette.applications import Starlette from starlette.routing import Mount +from mcp.server.transport_security import TransportSecuritySettings from auth import close_auth_client from modules.crm.tools import crm_server @@ -27,11 +30,29 @@ from modules.crm.db import close_pool as close_crm_pool from modules.erp.db import close_pool as close_erp_pool from modules.bexell.db import close_engine as close_bexell_engine +# 允许通过反向代理访问时的公网 Host;保留 DNS rebinding protection。 +_public_url = os.getenv("MCP_PUBLIC_URL", "http://localhost:8001") +_public_host = urlparse(_public_url).hostname or "localhost" +_transport_security = TransportSecuritySettings( + enable_dns_rebinding_protection=True, + allowed_hosts=[_public_host, "127.0.0.1:*", "localhost:*", "[::1]:*"], + allowed_origins=[f"https://{_public_host}", "http://127.0.0.1:*", "http://localhost:*", "http://[::1]:*"], +) + # 获取各模组的 Starlette ASGI app(streamable_http_path 设为 /mcp, # Mount("/xxx") 会剥离前缀,子 app 看到的路径就是 /mcp) -erp_app = erp_server.streamable_http_app(streamable_http_path="/mcp") -crm_app = crm_server.streamable_http_app(streamable_http_path="/mcp") -bexell_app = bexell_server.streamable_http_app(streamable_http_path="/mcp") +erp_app = erp_server.streamable_http_app( + streamable_http_path="/mcp", + transport_security=_transport_security, +) +crm_app = crm_server.streamable_http_app( + streamable_http_path="/mcp", + transport_security=_transport_security, +) +bexell_app = bexell_server.streamable_http_app( + streamable_http_path="/mcp", + transport_security=_transport_security, +) @asynccontextmanager