Skip to content

fix(server): advertise an https resource behind TLS-terminating load balancers - #101

Merged
ysyneu merged 1 commit into
feat/mcp-oauthfrom
fix/oauth-resource-https
Oct 8, 2026
Merged

ysyneu merged 1 commit into
feat/mcp-oauthfrom
fix/oauth-resource-https

Conversation

@ysyneu

@ysyneu ysyneu commented Oct 8, 2026

Copy link
Copy Markdown
Collaborator

Protected resource metadata and the 401 challenge took their scheme from X-Forwarded-Proto, defaulting to http. Behind a load balancer that terminates TLS without setting that header, the server advertised http://<host>/mcp, which does not match the https URL clients connect to, so OAuth discovery fails.

  • Without the header: loopback hosts stay http; any other host is https (the only scheme MCP clients accept for a non-loopback authorization target).
  • X-Forwarded-Proto is honored only when it is http or https.

Tests cover: no forwarded proto, loopback, unknown proto, forwarded http, proxy with comma-separated proto. make check passes.

…balancers

The protected resource metadata and the 401 challenge took their scheme
from X-Forwarded-Proto, falling back to http. A load balancer that
terminates TLS without setting that header made the server advertise
http://<host>/mcp, which does not match the https URL clients connect to,
so they reject the metadata and OAuth never starts.

Without the header, only loopback hosts are plain http now; any other host
is https, the only scheme MCP clients accept for a non-loopback
authorization target. X-Forwarded-Proto is honored only for http or https.
@ysyneu
ysyneu merged commit eca73c6 into feat/mcp-oauth Oct 8, 2026
12 checks passed
@ysyneu
ysyneu deleted the fix/oauth-resource-https branch October 8, 2026 12:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant