fix: ppclock-mcp --allowed-hosts 空串按 None 处理(空白名单自锁 localhost 421)

空串逗号拆分得空列表,TransportSecuritySettings(allowed_hosts=[]) 启用
DNS 重绑定防护后连 localhost 族一并 421。main() 解析层抽出
_parse_allowed_hosts,空列表以 or None 归一,保持 mcp 默认;含回归测试。

Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
chenweiandClaude committed 2026-07-31 01:02:07 +00:00
1 parent 85e2413947
commit d33a1296ff
2 files changed
+18 -2

No files matched your search

+8
View File
@@ -119,3 +119,11 @@ class TestAllowedHosts:
def test_evil_host_421(self):
r = self._initialize(self._make_app(), "evil.example.com")
assert r.status_code == 421
def test_empty_string_allowed_hosts_to_none(self):
"""回归:`--allowed-hosts ""` 空串自锁——逗号拆分结果为空列表时须按
None 处理(保持 mcp 默认 localhost 族),否则空白名单启用防护后
连 localhost 请求也被 421。"""
from ppclock.mcp_server import _parse_allowed_hosts
a = parse_args(["--allowed-hosts", ""])
assert _parse_allowed_hosts(a.allowed_hosts) is None