diff --git a/internal/probe/mcp/session.go b/internal/probe/mcp/session.go index 6a328a5..5f35f74 100644 --- a/internal/probe/mcp/session.go +++ b/internal/probe/mcp/session.go @@ -442,6 +442,12 @@ func negotiateInitialize(ctx context.Context, sess probe.Session) (*InitializeRe // error body happens to be valid JSON. if raw.StatusCode != http.StatusOK { lastErr = fmt.Errorf("server returned HTTP %d for initialize (expected 200)", raw.StatusCode) + // 405 Method Not Allowed and 501 Not Implemented mean the server + // didn't recognise this HTTP method or protocol variant; try the + // next version regardless of whether the body contains "version". + if raw.StatusCode == http.StatusMethodNotAllowed || raw.StatusCode == http.StatusNotImplemented { + continue + } if isVersionRejection(raw.StatusCode, string(raw.Body)) { continue } diff --git a/internal/probe/transport/checks.go b/internal/probe/transport/checks.go index 1a1ac61..7efdc7f 100644 --- a/internal/probe/transport/checks.go +++ b/internal/probe/transport/checks.go @@ -127,11 +127,9 @@ func (p *tlsCertHealthProbe) Run(ctx context.Context, s probe.Session, r *report issues = append(issues, "certificate is not yet valid") raise(report.SeverityHigh) } - if cert.IsCA { - if err := cert.CheckSignatureFrom(cert); err == nil { - issues = append(issues, "certificate is self-signed") - raise(report.SeverityHigh) - } + if cert.Issuer.String() == cert.Subject.String() { + issues = append(issues, "certificate is self-signed") + raise(report.SeverityHigh) } if err := cert.VerifyHostname(u.Hostname()); err != nil { issues = append(issues, fmt.Sprintf("hostname mismatch: %v", err)) @@ -258,6 +256,12 @@ func (p *corsWildcardProbe) Run(ctx context.Context, s probe.Session, r *report. // browsers permit credentials with a reflected origin. desc = fmt.Sprintf("Server reflects an arbitrary request Origin (%s) back in Access-Control-Allow-Origin, which permits credentialed cross-origin access from any site.", probeOrigin) sev = report.SeverityHigh + // IsCORSWildcard only sets credentialed when acao=="*"; check the + // header independently so the credentials detail appears when the + // origin is reflected rather than wildcarded. + if strings.EqualFold(headers.Get("Access-Control-Allow-Credentials"), "true") { + desc += " The server also sends Access-Control-Allow-Credentials: true, allowing cookies and auth headers to be included in cross-origin requests from any site." + } } if credentialed { sev = report.SeverityHigh