Agent-Hellboy / Agent-Hellboy/mcp-runtime

Internal/Origin IP Address Exposure in API Response

オープン
#107 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
day2-infra-hardening platform
主要言語
Go
スター
6
フォーク
1
平均マージ
11時間 33分
マージ済み PR(30日)
13

説明

Steps to Reproduce :
1. Open the MCP Sentinel dashboard
2. Navigate to API Keys
3. Click Create Key
4. Open browser DevTools → Network tab
5. Inspect the request api-keys
6. Observe the Remote Address field

Expected Behavior:
1. The internal or origin IP address should not be exposed
2. Requests should ideally be routed via:
3. Reverse proxy / CDN (e.g., Cloudflare, Nginx)
4.Masked infrastructure endpoints

Actual Behavior :
1. Backend server IP is directly exposed in network response metadata

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。