fix(security): allow host headers with and without explicit port
This commit is contained in:
@@ -25,10 +25,15 @@ mcp = FastMCP(
|
|||||||
transport_security=TransportSecuritySettings(
|
transport_security=TransportSecuritySettings(
|
||||||
enable_dns_rebinding_protection=True,
|
enable_dns_rebinding_protection=True,
|
||||||
allowed_hosts=[
|
allowed_hosts=[
|
||||||
|
"localhost",
|
||||||
"localhost:*",
|
"localhost:*",
|
||||||
|
"127.0.0.1",
|
||||||
"127.0.0.1:*",
|
"127.0.0.1:*",
|
||||||
|
"knowledge-mcp",
|
||||||
"knowledge-mcp:*",
|
"knowledge-mcp:*",
|
||||||
|
"knowledge-mcp.knowledge-mcp.svc",
|
||||||
"knowledge-mcp.knowledge-mcp.svc:*",
|
"knowledge-mcp.knowledge-mcp.svc:*",
|
||||||
|
"knowledge-mcp.knowledge-mcp.svc.cluster.local",
|
||||||
"knowledge-mcp.knowledge-mcp.svc.cluster.local:*",
|
"knowledge-mcp.knowledge-mcp.svc.cluster.local:*",
|
||||||
],
|
],
|
||||||
allowed_origins=[],
|
allowed_origins=[],
|
||||||
|
|||||||
Reference in New Issue
Block a user