Skip to content

bug(source/looker): Public host URL resolution leaks internal service address in isolated network environments #3602

Description

@pushkar0108

Prerequisites

  • I've searched the current open issues
  • I've updated to the latest version of Toolbox

Toolbox version

latest

Environment

  1. OS type and version: [(output of uname -a)](root:xnu-11417.140.69.710.16~1/RELEASE_ARM64_T6000 arm64)
  2. How are you running Toolbox:
  • Compiled from source: go run . --prebuilt looker

Client

Tested this using curl and gemini-cli

Expected Behavior

Looker tools should expose the host_url settings exposed by admin settings for all the returned urls from the MCP tools.

Current Behavior

In deployments where the MCP server connects to the Looker instance using an internal/private service address (e.g., across a private network or local DNS), several Looker tools that return absolute URLs (or pass instance domains to external APIs) reference the raw connection BaseUrl or call sdk.GetSetting("host_url"). This leads to two critical problems:

  1. Internal Domain Leakage: Tools like looker-generate-embed-url and looker-conversational-analytics reference the connection's BaseUrl directly, resulting in signed embed URLs containing the private internal hostname which is unresolvable by the external client's browser, or causing external APIs to fail metadata domain validation.

  2. Permission Denied for Standard Users: Tools like looker-make-look and looker-make-dashboard try to call sdk.GetSetting("host_url", ...). However, standard Looker users do not have administrative privileges to query system settings. This call fails (yielding 403 Forbidden / 404 Not Found API errors) and falls back to returning relative URL paths (e.g. /dashboards/123 or /looks/123) lacking a public hostname prefix.

Steps to reproduce?

Prerequisites & Setup

  1. Looker Custom Domain Setup: Ensure your Looker instance has a custom domain configured in the Admin console (e.g., host_url is set to https://public.looker.example.com).
  2. MCP Connection Setup: Configure the MCP toolbox base_url to point to the instance using a local/internal address (e.g., base_url: http://localhost:19999 or your local tunnel address).

Example 1: looker-generate-embed-url tool

  1. Trigger looker-generate-embed-url: Invoke the tool with valid parameters
  2. Check the returned embed URL. It will contain the internal connection address: http://localhost:19999/embed/... instead of the public custom domain: https://public.looker.example.com/embed/...

Additional Details

No response

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

priority: p2Moderately-important priority. Fix may not be included in next release.product: lookerLookertype: bugError or flaw in code with unintended results or allowing sub-optimal usage patterns.

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions