fix(mcp): HTTP 模式新增 --allowed-hosts,修 LAN Host 421
Windows 实测:绑 0.0.0.0 后局域网请求被 mcp DNS 重绑定防护 421 拒。 - parse_args 加 --allowed-hosts(逗号分隔 Host 白名单,默认 None 保持 mcp 仅 localhost 族行为) - build_server(manager, allowed_hosts=...) 经 TransportSecuritySettings 传入(mcp 1.29.0 API 与设计一致,无需调整) - main() 逗号拆分(去空白、丢空段) - 回归测试:TestClient 驱动真实 ASGI app(含 lifespan), Host=192.168.61.35:8972 initialize → 200;Host=evil.example.com → 421 Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
1 parent
1f78587bbd
commit
69c4d209c0
2 files changed
+70
-4
No files matched your search
@@ -1,4 +1,4 @@
|
||||
"""mcp_server 测试:参数解析 + 非回环强制 token + ASGI 鉴权中间件。"""
|
||||
"""mcp_server 测试:参数解析 + 非回环强制 token + ASGI 鉴权中间件 + HTTP Host 白名单。"""
|
||||
import asyncio
|
||||
|
||||
import pytest
|
||||
@@ -25,6 +25,13 @@ class TestParseArgs:
|
||||
assert a.port == 9000 and a.mac == "AA:BB:CC:DD:EE:FF"
|
||||
assert a.connect_timeout == 120.0 and a.idle_timeout == 60.0
|
||||
|
||||
def test_allowed_hosts_default_none(self):
|
||||
assert parse_args([]).allowed_hosts is None
|
||||
|
||||
def test_allowed_hosts_flag(self):
|
||||
a = parse_args(["--allowed-hosts", "192.168.61.35:8972,localhost:8972"])
|
||||
assert a.allowed_hosts == "192.168.61.35:8972,localhost:8972"
|
||||
|
||||
|
||||
def run_middleware(token_set, auth_header):
|
||||
"""驱动 TokenAuthMiddleware,返回 (status, app_called)。"""
|
||||
@@ -70,3 +77,45 @@ class TestBindGuard:
|
||||
monkeypatch.delenv(TOKEN_ENV, raising=False)
|
||||
with pytest.raises(SystemExit):
|
||||
main(["--transport", "http", "--host", "0.0.0.0"])
|
||||
|
||||
|
||||
class TestAllowedHosts:
|
||||
"""HTTP 模式 Host 白名单回归(Windows 实测:LAN Host 被 421 拒)。
|
||||
|
||||
用 starlette TestClient 驱动真实 ASGI app(含 lifespan,stateless 会话管理器
|
||||
需要其 task group);manager 只构造不连接,initialize 不触达设备。
|
||||
"""
|
||||
|
||||
LAN_HOST = "192.168.61.35:8972"
|
||||
|
||||
def _make_app(self):
|
||||
from ppclock.device_manager import DeviceManager
|
||||
from ppclock.mcp_server import build_server
|
||||
manager = DeviceManager(mac="AA:BB:CC:DD:EE:FF")
|
||||
mcp = build_server(manager, allowed_hosts=[self.LAN_HOST,
|
||||
"localhost:8972"])
|
||||
return mcp.streamable_http_app()
|
||||
|
||||
def _initialize(self, app, host):
|
||||
from starlette.testclient import TestClient
|
||||
with TestClient(app) as client:
|
||||
return client.post(
|
||||
"/mcp",
|
||||
headers={
|
||||
"Host": host,
|
||||
"Accept": "application/json, text/event-stream",
|
||||
"Content-Type": "application/json",
|
||||
},
|
||||
json={"jsonrpc": "2.0", "id": 1, "method": "initialize",
|
||||
"params": {"protocolVersion": "2025-03-26",
|
||||
"capabilities": {},
|
||||
"clientInfo": {"name": "test", "version": "0"}}},
|
||||
)
|
||||
|
||||
def test_lan_host_not_421(self):
|
||||
r = self._initialize(self._make_app(), self.LAN_HOST)
|
||||
assert r.status_code != 421
|
||||
|
||||
def test_evil_host_421(self):
|
||||
r = self._initialize(self._make_app(), "evil.example.com")
|
||||
assert r.status_code == 421
|
||||
Reference in new issue
Block a user