mirror of
https://github.com/PrefectHQ/fastmcp.git
synced 2026-10-10 23:13:20 +02:00
`host_origin_protection`, `allowed_hosts`, and `allowed_origins` (and their `FASTMCP_HTTP_*` settings) now configure the legacy SSE transport the same way they configure Streamable HTTP. `create_sse_app()` accepts the three options, `http_app(transport="sse")` and `run(transport="sse")` forward them, and the request guard covers both the SSE connection endpoint and the message endpoint. `True`, `False`, and `"auto"` mean the same thing on both transports, so a server's Host/Origin policy is the same on either one.
Both app factories now build the guard through one shared helper, and the SSE transport passes explicit SDK security settings that leave Host/Origin validation to FastMCP, matching Streamable HTTP. The default stays `False`, so servers that don't opt in see no change. The deployment and settings docs now say the options apply to both transports.
```python
from fastmcp import FastMCP
mcp = FastMCP("My Server")
app = mcp.http_app(
transport="sse",
host_origin_protection=True,
allowed_hosts=["mcp.example.com"],
)
```
Co-authored-by: Claude <noreply@anthropic.com>
|
||
|---|---|---|
| .. | ||
| http.mdx | ||
| prefect-horizon.mdx | ||
| running-server.mdx | ||
| sandboxed-agents.mdx | ||
| server-configuration.mdx | ||