fix(security): validate Bearer token value in MCP endpoints, not just presence
Previously any Bearer token (even invalid) passed the HTTP middleware and got a session with access to tools/list and resources/list. Now the OAuthRequiredMiddleware validates tokens against master key, API keys, and OAuth JWT before allowing initialize. Also fixes: - WordPress Advanced env prefix: WORDPRESS_ → WORDPRESS_ADVANCED_ in docs - Bump version to 3.0.1 Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -319,7 +319,7 @@ MCP Hub supports **Open Dynamic Client Registration** (RFC 7591). ChatGPT can au
|
||||
|--------|-------|------------|
|
||||
| WordPress | 67 | `WORDPRESS_` |
|
||||
| WooCommerce | 28 | `WOOCOMMERCE_` |
|
||||
| WordPress Advanced | 22 | `WORDPRESS_` (same sites, advanced ops) |
|
||||
| WordPress Advanced | 22 | `WORDPRESS_ADVANCED_` |
|
||||
| Gitea | 56 | `GITEA_` |
|
||||
| n8n | 56 | `N8N_` |
|
||||
| Supabase | 70 | `SUPABASE_` |
|
||||
|
||||
Reference in New Issue
Block a user