Expand description
The Streamable HTTP transport, and everything that stands in front of it.
Stdio has one client, reached over a pipe the operating system already decided who may open. HTTP has none of that: anything that can reach the socket can try, and a browser on the same machine can be made to try by a page the operator never visited. So the transport is the small part of this module and the checks are the rest.
What has to be true before a request reaches the handler, in the order it is asked:
- The
Hostheader names something on the allow-list. Loopback, plus this node’s own tailnet names read from status at startup, plus whatever the operator added. This is what stops DNS rebinding: a page that resolvesevil.exampleto127.0.0.1reaches the socket and arrives with the wrongHost. - There is no
Origin, or theOriginis on its own allow-list. A request carrying one came from a page, and a page is not a client this server has any reason to serve unless the operator said so. - The caller’s address is under its rate limit.
- The bearer token matches, compared in constant time.
The body limit is the one check that is not here: rmcp’s transport reads
the body, so rmcp’s transport is what caps it. See MAX_BODY_BYTES.
GET /health skips all four: it exists to be reachable by something that
holds no credential, which is the whole point of a health check.
A token is optional on loopback and required everywhere else. Binding
to an address other than loopback without one refuses to start, and
--http-no-auth is the only way past that — a flag rather than an
omission, so that serving an unauthenticated tailnet address is something
an operator did rather than something that happened.
Structs§
- Caller
- Who is calling, as far as this server can tell.
- Guard
- Everything the checks need, built once at startup.
Enums§
- Refusal
- Why a request was refused.
Constants§
- DEFAULT_
BIND - Where
--httplistens when it is given no address. - HEALTH_
PATH - The path that answers without a token.
- MAX_
BODY_ BYTES - The largest request body accepted.
- MCP_
PATH - The path the MCP transport is served at.
- RATE_
BURST - How many requests one address may make in
RATE_WINDOW. - RATE_
WINDOW - The window the burst is counted over.