Skip to content

Expose the streamable HTTP server's Host validation #1334

Description

@gluax

The streamable HTTP server checks the Host header against its allowed hosts (host_is_allowed, validate_dns_rebinding_headers), but those functions are private in 3.3.0. A server that authenticates in an axum layer in front of the rmcp service has to run its own, often costlier, checks before rmcp's Host check refuses a request. A public function that takes the request headers and the configured allowed hosts and returns whether the request passes would let such a layer run the same check first, with no copy of the parsing rules.

Activity

  1. added
    enhancementNew feature or request
    P2Medium: important but non-blocking improvement
    T-transportTransport layer changes
    T-securitySecurity-related changes
    ready for workIssue is well-defined and ready to be picked up
    on Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    P2Medium: important but non-blocking improvementT-securitySecurity-related changesT-transportTransport layer changesenhancementNew feature or requestready for workIssue is well-defined and ready to be picked up

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions