fix(mcp_server): preserve authorization header in HTTP mode#11366
Merged
Conversation
FastMCP 3.2.4 added `authorization` to the default exclusion set of
`get_http_headers()`, so every authenticated call to the HTTP transport
was failing with "No authorization header provided". Pass
`include={"authorization"}` so the header reaches the auth flow.
Contributor
|
✅ All necessary |
jfagoagas
approved these changes
May 26, 2026
Contributor
|
✅ Conflict Markers Resolved All conflict markers have been successfully resolved in this pull request. |
Contributor
🔒 Container Security ScanImage: 📊 Vulnerability Summary
2 package(s) affected
|
Collaborator
💚 All backports created successfully
Questions ?Please refer to the Backport tool documentation and see the Github Action logs for details |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Context
After bumping
fastmcpfrom 2.14.0 to 3.2.4 in #4317, every authenticated call to the MCP server in HTTP mode started failing withValueError: No authorization header provided. FastMCP 3.2.4 addedauthorizationto the default exclusion set ofget_http_headers()(seefastmcp/server/dependencies.py:442), so the bearer token sent by the lighthouse agent (and any other HTTP client) was being filtered out before reaching the auth flow.Description
Pass
include={"authorization"}toget_http_headers()so the authorization header survives the default exclusion and reachesProwlerAppAuth.authenticate().Steps to review
mcp_server/prowler_mcp_server/prowler_app/utils/auth.py.prowler_app_get_mutelist) with a validAuthorization: Bearer <token>header — it should now succeed instead of raisingNo authorization header provided.mode == "http"branch is the only change).Checklist
Community Checklist
SDK/CLI
UI
API
License
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.