v1.9.4 — fix 421 host-guard rejection behind reverse proxy
Fixed
- auth/transport: the connector no longer returns 421 Misdirected Request on the OAuth discovery/registration routes behind a reverse proxy. fastmcp 3.4.3 enforces the MCP HTTP transport's Host/Origin DNS-rebinding guard, which rejected every request whose
Hostwas the public domain — so Claude's client registration failed ("Registrierung beim Anmeldedienst fehlgeschlagen"). The server now derives the Host/Origin allow-list fromBASE_URL(already required for OIDC, so it can't drift) and passes it tomcp.run(...);localhost/127.0.0.1stay allowed by the guard's defaults, andMCP_ALLOWED_HOSTS(comma-separated) can add more. Protection stays on — unknown hosts are still rejected. Regression introduced by the 3.4.3 bump in 1.9.3.
Deploy: docker compose pull && docker compose up -d (unpin the image back to :latest if you pinned :v1.9.2 during the incident). Verify: connector reconnects and the logs show no more 421 on the OAuth routes.