Skip to content

Internal/Origin IP Address Exposure in API Response #107

@ankitkatewa

Description

@ankitkatewa

Steps to Reproduce :

  1. Open the MCP Sentinel dashboard
  2. Navigate to API Keys
  3. Click Create Key
  4. Open browser DevTools → Network tab
  5. Inspect the request api-keys
  6. Observe the Remote Address field

Expected Behavior:

  1. The internal or origin IP address should not be exposed
  2. Requests should ideally be routed via:
  3. Reverse proxy / CDN (e.g., Cloudflare, Nginx)
    4.Masked infrastructure endpoints

Actual Behavior :

  1. Backend server IP is directly exposed in network response metadata

Metadata

Metadata

Assignees

No one assigned

    Labels

    day2-infra-hardeningOperational hardening after install: NetworkPolicy, RBAC tightening, mTLS, etc.platformCross-cutting platform concerns spanning multiple components

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions