The streamable HTTP server checks the Host header against its allowed hosts (host_is_allowed, validate_dns_rebinding_headers), but those functions are private in 3.3.0. A server that authenticates in an axum layer in front of the rmcp service has to run its own, often costlier, checks before rmcp's Host check refuses a request. A public function that takes the request headers and the configured allowed hosts and returns whether the request passes would let such a layer run the same check first, with no copy of the parsing rules.
The streamable HTTP server checks the
Hostheader against its allowed hosts (host_is_allowed,validate_dns_rebinding_headers), but those functions are private in 3.3.0. A server that authenticates in an axum layer in front of the rmcp service has to run its own, often costlier, checks before rmcp's Host check refuses a request. A public function that takes the request headers and the configured allowed hosts and returns whether the request passes would let such a layer run the same check first, with no copy of the parsing rules.