Skip to content

v1.9.4 — fix 421 host-guard rejection behind reverse proxy

Choose a tag to compare

@IkarusMK IkarusMK released this 06 Jul 21:18
· 15 commits to main since this release

Fixed

  • auth/transport: the connector no longer returns 421 Misdirected Request on the OAuth discovery/registration routes behind a reverse proxy. fastmcp 3.4.3 enforces the MCP HTTP transport's Host/Origin DNS-rebinding guard, which rejected every request whose Host was the public domain — so Claude's client registration failed ("Registrierung beim Anmeldedienst fehlgeschlagen"). The server now derives the Host/Origin allow-list from BASE_URL (already required for OIDC, so it can't drift) and passes it to mcp.run(...); localhost/127.0.0.1 stay allowed by the guard's defaults, and MCP_ALLOWED_HOSTS (comma-separated) can add more. Protection stays on — unknown hosts are still rejected. Regression introduced by the 3.4.3 bump in 1.9.3.

Deploy: docker compose pull && docker compose up -d (unpin the image back to :latest if you pinned :v1.9.2 during the incident). Verify: connector reconnects and the logs show no more 421 on the OAuth routes.