Commit graph

3 commits

Author SHA1 Message Date
cf283c9bba fix: close timing-attack and empty-secret auth bypass in MCP server
check_bearer_token now uses hmac.compare_digest for constant-time comparison
and rejects a falsy expected token outright, with a startup guard that fails
loudly if HAVOC_MCP_TOKEN is set but empty. Adds Starlette TestClient coverage
of the _BearerAuthMiddleware auth-enforcement path (no header, wrong token,
correct token), and cleans up dead code found during review: unused token
param on build_mcp_server, a per-request import, and an unused json import.
2026-07-04 07:22:55 -07:00
b2887753e9 feat: add bearer token auth check for MCP server 2026-07-04 07:08:21 -07:00
d2b85fc276 feat: add DebugAgentClient for MCP-to-debug-agent translation 2026-07-04 07:07:36 -07:00