AltimateAI / AltimateAI/altimate-code

security: reconsider auth/CORS posture for state-changing /altimate/mcp/reload-datamate

Open
#956 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
811
Forks
134
Avg merge
3d 2h
Merged PRs (30d)
50

Description

Found during the v0.8.8 release review (CTO, P2 deferred).

`POST /altimate/mcp/reload-datamate` (added in #893) is a state-changing endpoint that re-reads IDE `mcp.json` from disk and calls `MCP.add()` to (re)connect MCP clients with whatever command/url those files contain. With no `OPENCODE_SERVER_PASSWORD` set (the default, loopback bind + startup warning only), any local process — including a browser page the CORS policy reflects `http://localhost:*` / `http://127.0.0.1:*` for — can POST to it and trigger a reconnect.

This is the **same auth posture as all existing routes** (not a new exposure class), but `reload-datamate` is more side-effectful (spawns/reconnects transports) than the read routes, so it warrants a closer look.

Possible directions: require auth for state-changing `/altimate/*` routes even when the global password is unset, or tighten the CORS reflection for those routes. Deferred — design decision, not an in-diff edit, and default bind is loopback.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.