fix(security): validate Bearer token value in MCP endpoints, not just presence

Previously any Bearer token (even invalid) passed the HTTP middleware and
got a session with access to tools/list and resources/list. Now the
OAuthRequiredMiddleware validates tokens against master key, API keys,
and OAuth JWT before allowing initialize.

Also fixes:
- WordPress Advanced env prefix: WORDPRESS_ → WORDPRESS_ADVANCED_ in docs
- Bump version to 3.0.1

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
airano
2026-02-18 16:24:04 +03:30
parent 4a45178d2d
commit 85379ec36c
6 changed files with 51 additions and 5 deletions

View File

@@ -1995,7 +1995,7 @@ def _get_project_version() -> str:
return line.split("=")[1].strip().strip('"').strip("'")
except Exception:
pass
return "3.0.0"
return "3.0.1"
def get_about_info() -> dict:

View File

@@ -138,7 +138,7 @@
<!-- Footer -->
<p class="text-center text-gray-500 text-sm mt-6">
MCP Hub v{{ version|default('3.0.0') }}
MCP Hub v{{ version|default('3.0.1') }}
</p>
</div>
</body>