MCP server has no authentication and is exposed publicly #30
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Critical
The MCP server (`mcp-server/server.py`) runs FastMCP with `host=0.0.0.0` (line 19) and no authentication of any kind. Caddy routes the public path `/mcp/*` to it (port 8874), so anyone on the internet can:
```python
app = FastMCP("wh40-rogue-trader-mcp", host="0.0.0.0", port=MCP_PORT)
...
app.run(transport="streamable-http") # no auth hook anywhere
```
Suggested fix
🔧 Work started — Plan:
MCP_AUTH_TOKENenv)docker-compose.prod.yml(like JWT_SECRET)Note: this will break any existing unauthenticated MCP clients — they'll need to send
Authorization: Bearer <token>going forward.🔧 Progress: ASGI bearer-token middleware added around FastMCP's streamable-http app;
MCP_AUTH_TOKENis now required by docker-compose (token generated into .env). uvicorn runs the wrapped app. Pending: build + live curl verification (401 without token / success with token).✅ Fixed & verified live (commit
05b5453):Authorization: Bearer <MCP_AUTH_TOKEN>MCP_AUTH_TOKEN:${MCP_AUTH_TOKEN:?}), generated into.env/, middleware strips/mcp(Caddy forwards the prefix intact — this was also silently breaking the route)Live verification:
POST /mcp/without token → 401Client config going forward: URL
https://roguetrader.tabletopamsterdam.nl/mcp/(trailing slash matters), headerAuthorization: Bearer <token from .env>.Note for external MCP clients (Claude etc.): add the Authorization header to your MCP connector config.