Daily review fixes: MCP Host refusals explained, security events kept, setup links measurable - #845
Open
keysersoft wants to merge 1 commit into
Open
keysersoft wants to merge 1 commit into
keysersoft wants to merge 1 commit into
Conversation
…, setup links measurable
- A remote MCP server whose DNS-rebinding protection refuses our Host
("host not allowed" / "Invalid Host header") now gets an error that
says to add the hostname to its allowed hosts. Seen on a customer's
MCP connector behind a trycloudflare tunnel, stuck at 0 tools.
- A security event that references a deleted user or organization
(TOKEN_REJECTED for a deleted user) was lost on the foreign key; it is
now stored without the links, with the ids in its metadata.
- Expired one-time setup links stay in the table for a week instead of
being deleted at the next link, so the share of links that get opened
can be measured. They stop working at expiry as before.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
From the daily production review (4 Oct 2026).
host not allowed/Invalid Host header. That is the remote server's DNS-rebinding protection refusing the tunnel hostname. The error now says which setting to change (allowedHosts). Applied where the MCP client connects, so every discovery path gets it.Failed to persist security event 'TOKEN_REJECTED': Foreign key constraint violated(2× in 24h): the referenced user/org no longer exists. The event is now stored without the links, with the ids undermetadata.unresolved.resolveLink).Tests: backend 6648 passed (+4 new).