Files
jhonny-editor/code/docs/recommendations/2026-08-18-round-2/23-routing-header-integrity.md
T
João Henrique b541f502ba feat: initial commit - Jhonny Editor
- Adicionado estrutura completa do projeto
- Configurado MCP server para Premiere Pro
- Adicionado documentação e skills
- Configurado Gitignore para o projeto
2026-09-08 09:59:31 -04:00

1.1 KiB
Executable File

Recommendation 23: MCP routing-header integrity

Evidence

MCP 2026-07-28 adds Mcp-Method and Mcp-Name headers for routing without parsing request bodies and defines HeaderMismatchError when they disagree with the JSON-RPC payload.

Proposed improvement

Validate routing headers against the parsed body before authentication scope selection or dispatch. Treat headers as bounded routing hints, never as independent authorization facts, and redact sensitive resource names from access logs.

Acceptance criteria

  • Missing, duplicate, oversized, and mismatched headers have deterministic outcomes.
  • Proxies cannot authorize one tool while dispatching another.
  • Header values use strict byte and character limits.
  • Compatibility tests cover clients from both protocol generations.

This complements exact HTTP route admission; it addresses semantic routing after admission.