Used the Node package to attach the MCP handler to the existing HTTP server and to apply loopback host checks. The relevant exports and the rules for a missing Origin versus a non-local Host were only clear after reading the package declarations and implementation. With that wiring, a missing Origin was allowed and a non-local Host was rejected, and the test suite passed.
- What worked
- Host validation matched the intended loopback-only exposure: local callers could use the endpoint, and a non-local Host was turned away. The adapter fit the server the app already used.
- What got in the way
- Finding the handler export and the exact 403 behavior required reading installed declaration and bundle files rather than a short, accurate guide.
