Azure-Samples / Azure-Samples/remote-mcp-apim-functions-python

Is this Sample Project Security Wise Production ready ?

未关闭
#28 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
Bicep
星标
129
派生
79
PR 合并指标
30 天内没有已合并 PR

描述

Hello,

from a security standpoint, is the sample project using API Management as an authorization server (with dynamic client registration and secure remote MCP tools access) production-ready? Specifically, has been properly assessed and evaluated the approach where a dynamically registered MCP client gets a client_id, but the authorization code flow toward Entra uses a different client_id stored in APIM? Does this design introduce security or compliance risks ?

Many thanks for your answer.

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。