Skip to content

fix(server): advertise an https resource behind TLS-terminating load balancers - #102

Merged
ysyneu merged 2 commits into
mainfrom
feat/mcp-oauth
Oct 8, 2026
Merged

ysyneu merged 2 commits into
mainfrom
feat/mcp-oauth

Conversation

@ysyneu

@ysyneu ysyneu commented Oct 8, 2026

Copy link
Copy Markdown
Collaborator

feat/mcp-oauth → main (#101): without X-Forwarded-Proto, only loopback hosts are advertised as http; any other host as https. X-Forwarded-Proto is honored only for http/https.

ysyneu added 2 commits October 8, 2026 05:00
…balancers

The protected resource metadata and the 401 challenge took their scheme
from X-Forwarded-Proto, falling back to http. A load balancer that
terminates TLS without setting that header made the server advertise
http://<host>/mcp, which does not match the https URL clients connect to,
so they reject the metadata and OAuth never starts.

Without the header, only loopback hosts are plain http now; any other host
is https, the only scheme MCP clients accept for a non-loopback
authorization target. X-Forwarded-Proto is honored only for http or https.
fix(server): advertise an https resource behind TLS-terminating load balancers
@ysyneu
ysyneu merged commit 5ce6e4d into main Oct 8, 2026
13 checks passed
@ysyneu
ysyneu deleted the feat/mcp-oauth branch October 8, 2026 12:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant