Fix: enforce MCP token length too

This commit is contained in:
shamoon
2026-08-07 15:09:57 -07:00
parent 2fae37b004
commit 7904d4adc9
5 changed files with 95 additions and 19 deletions
+2 -2
View File
@@ -28,7 +28,7 @@ http://your-homepage-instance/api/mcp
The MCP endpoint requires authentication. Requests from an authenticated Homepage session are allowed when Homepage auth is enabled with `HOMEPAGE_AUTH_ENABLED`.
For MCP clients that cannot use the browser session, set `HOMEPAGE_MCP_TOKEN`. An MCP token is required when Homepage auth is not enabled. Requests can include either of the following headers:
For MCP clients that cannot use the browser session, set `HOMEPAGE_MCP_TOKEN`. An MCP token is required when Homepage auth is not enabled. The token grants read access to every configured service credential and, with writes enabled, control of `custom.js` (which runs in every browser), so it must be at least 32 characters — generate one with `openssl rand -base64 32`. Homepage refuses MCP requests while a shorter token is configured. Requests can include either of the following headers:
```txt
Authorization: Bearer your-token
@@ -46,7 +46,7 @@ Example Docker Compose environment block:
environment:
HOMEPAGE_MCP_ENABLED: "true"
HOMEPAGE_AUTH_ENABLED: "true"
HOMEPAGE_MCP_TOKEN: "change-me"
HOMEPAGE_MCP_TOKEN: "generate-with-openssl-rand-base64-32"
```
## Read-only by default