{"record":{"id":"8cfa264a5d740aca","repo":"koala73/worldmonitor","slug":"serverurl-host-is-not-allowed","errorCode":null,"errorMessage":"serverUrl host is not allowed","messagePattern":"serverUrl host is not allowed","errorType":"exception","errorClass":"McpProxySsrfError","httpStatus":422,"severity":"error","filePath":"api/mcp-proxy.ts","lineNumber":119,"sourceCode":"export function proxyUsageIdentityFor(req, identity) {\n  if (!identity?.isPremium) {\n    return buildUsageIdentity({\n      sessionUserId: null,\n      isUserApiKey: false,\n      enterpriseApiKey: null,\n      widgetKey: null,\n      clerkOrgId: null,\n      userApiKeyCustomerRef: null,\n      tier: null,\n      planKey: null,\n    });\n  }\n\n  if (identity.kind === 'internal-mcp') {\n    return {\n      auth_kind: 'mcp_oauth',\n      principal_id: identity.userId,\n      customer_id: identity.userId,\n      tier: 0,\n      plan_key: null,\n    };\n  }\n\n  const enterpriseApiKey = identity.kind === 'enterprise'\n    ? req.headers.get('X-WorldMonitor-Key') ?? req.headers.get('X-Api-Key')\n    : null;\n  return buildUsageIdentity({\n    sessionUserId: identity.userId,\n    isUserApiKey: identity.kind === 'user-api-key',\n    enterpriseApiKey,\n    widgetKey: null,\n    clerkOrgId: null,\n    userApiKeyCustomerRef: null,\n    tier: null,\n    planKey: null,\n  });","sourceCodeStart":101,"sourceCodeEnd":137,"githubUrl":"https://github.com/koala73/worldmonitor/blob/e586b8b4b80f595aa7ece295eec10d76f2921240/api/mcp-proxy.ts#L101-L137","documentation":"SSRF guard error in the MCP proxy: the requested serverUrl resolved to a private or otherwise blocked address. The concrete IP is intentionally omitted from the public message (returning it would let callers probe internal IPs); it is only logged server-side as part of an audit record.","triggerScenarios":"Thrown at api/mcp-proxy.ts:117 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Point serverUrl at a public, routable hostname","Do not use loopback, link-local, or RFC1918 addresses — they are blocked by design","Check the server logs for the blocked_address audit entry if you believe this is a false positive"],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"e586b8b4b80f595aa7ece295eec10d76f2921240","analyzedAt":"2026-08-21T16:51:25.751Z","contentChangedAt":"2026-08-21T16:51:25.751Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}