Azure-Samples / Azure-Samples/remote-mcp-apim-functions-python

Is this Sample Project Security Wise Production ready ?

オープン
#28 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
Bicep
スター
129
フォーク
79
PR マージ指標
30日以内にマージされた PR はありません

説明

Hello,

from a security standpoint, is the sample project using API Management as an authorization server (with dynamic client registration and secure remote MCP tools access) production-ready? Specifically, has been properly assessed and evaluated the approach where a dynamically registered MCP client gets a client_id, but the authorization code flow toward Entra uses a different client_id stored in APIM? Does this design introduce security or compliance risks ?

Many thanks for your answer.

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

まず、サンプルが API Management を認可サーバーとしてどのように使用しているかを確認します。これには、動的なクライアント登録と Entra 認可コードフローが含まれます。異なるクライアント ID がセキュリティまたはコンプライアンス上のリスクを生じさせるかを評価します。完了の条件は、本番対応可否について明確な評価を文書化することであり、issue 内でファイル名やテスト名を指定することはありません。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
azure
領域
authentication, authorization, cloud, security
issue の種類
ドキュメント
難易度
5/5
見積もり時間
1週間以上
活発さ
停滞
明瞭さ
説明が足りない
初心者へのやさしさ
20/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。