Conversation
|
Do we need to do any of the items in https://modelcontextprotocol.io/docs/concepts/transports#security-warning%3A-dns-rebinding-attacks to protect the security of this mode? |
|
@eapache-opslevel we should probably do
The first 2 we should cut as future tickets - the 3rd one i'll fix in this PR |
3997770 to
03f0c90
Compare
|
We are going to let this linger a bit. We don't understand the security implications fully, and all anybody needs right now is the STDIO version which has no security concerns. |
|
Additional reason to wait on this - |
|
Won't Do. We've decided to switch libraries so this will have to be slightly re-written. going to close for now but keep the branch for when we want SSE with |
Resolves #
Problem
MCP servers can run in 2 modes - stdio and http
Solution
Expose commandline arguments to configure the mode and the port for
httpmodeChecklist
Make a changie entry that explains the customer facing outcome of this change