HIGH SEVERITYCONFIRMED
OAuthProxyProvider(allowed_client_redirect_uris=None) allows ALL redirect URIs
Package
fastmcp
Version
2.14.5
Verified
2026-03-28
Description
In `fastmcp/server/auth/redirect_validation.py:50`, when `allowed_patterns is None` the function returns `True` unconditionally. The documentation states 'If None (default), only localhost redirect URIs are allowed.' The code directly contradicts the documented behavior.
Reproduction
# Source: redirect_validation.py:50
if allowed_patterns is None:
return True # 'for DCR compatibility' — but docs say localhost-only