发布

  • Merge commit from fork

    frostbyte_neo 发布于 2025-12-02 13:23:55 +00:00 | 381 次提交 在此版本后已推送到 main

    • Auto-enable DNS rebinding protection for localhost servers

    When a FastMCP server is created with host="127.0.0.1" or "localhost"
    and no explicit transport_security is provided, automatically enable
    DNS rebinding protection. Both 127.0.0.1 and localhost are allowed
    as valid hosts/origins since clients may use either to connect.

    • Add tests for auto DNS rebinding protection on localhost

    Tests verify that:

    • Protection auto-enables for host=127.0.0.1
    • Protection auto-enables for host=localhost
    • Both 127.0.0.1 and localhost are in allowed hosts/origins
    • Protection does NOT auto-enable for other hosts (e.g., 0.0.0.0)
    • Explicit transport_security settings are not overridden
    • Add IPv6 localhost (::1) support for DNS rebinding protection

    Extend auto-enable DNS rebinding protection to also cover IPv6
    localhost. When host="::1", protection is now auto-enabled with
    appropriate allowed hosts ([::1]:) and origins (http://[::1]:).

    • Fix import ordering in test file
    下载附件