From 671d0c746c339243164baba149b2dd9b89183a02 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Rub=C3=A9n=20De=20la=20Torre=20Vico?= Date: Tue, 26 May 2026 15:25:46 +0200 Subject: [PATCH] fix(mcp_server): preserve authorization header in HTTP mode (#11366) Co-authored-by: Pepe Fagoaga --- mcp_server/CHANGELOG.md | 10 ++++++++++ .../prowler_mcp_server/prowler_app/utils/auth.py | 3 ++- 2 files changed, 12 insertions(+), 1 deletion(-) diff --git a/mcp_server/CHANGELOG.md b/mcp_server/CHANGELOG.md index aac630c494..8f1438a3bb 100644 --- a/mcp_server/CHANGELOG.md +++ b/mcp_server/CHANGELOG.md @@ -2,6 +2,14 @@ All notable changes to the **Prowler MCP Server** are documented in this file. +## [0.7.2] (Prowler v5.28.1) + +### 🐞 Fixed + +- Preserve authorization header in HTTP mode [(#11366)](https://github.com/prowler-cloud/prowler/pull/11366) + +--- + ## [0.7.1] (Prowler v5.28.0) ### 🔐 Security @@ -44,6 +52,8 @@ All notable changes to the **Prowler MCP Server** are documented in this file. - Attack Path tool to get Neo4j DB schema [(#10321)](https://github.com/prowler-cloud/prowler/pull/10321) +--- + ## [0.4.0] (Prowler v5.19.0) ### 🚀 Added diff --git a/mcp_server/prowler_mcp_server/prowler_app/utils/auth.py b/mcp_server/prowler_mcp_server/prowler_app/utils/auth.py index 32ab72e574..48535fb10a 100644 --- a/mcp_server/prowler_mcp_server/prowler_app/utils/auth.py +++ b/mcp_server/prowler_mcp_server/prowler_app/utils/auth.py @@ -5,6 +5,7 @@ from datetime import datetime from typing import Dict, Optional from fastmcp.server.dependencies import get_http_headers + from prowler_mcp_server import __version__ from prowler_mcp_server.lib.logger import logger @@ -68,7 +69,7 @@ class ProwlerAppAuth: async def authenticate(self) -> str: """Authenticate and return token (API key for STDIO, API key or JWT for HTTP).""" if self.mode == "http": - headers = get_http_headers() + headers = get_http_headers(include={"authorization"}) authorization_header = headers.get("authorization", None) if not authorization_header: