Azure / Azure/CosmosDBShell

M7. MCP authorization (OAuth code flow)

Offen
#159 2 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
agentic enhancement P1
Vorherrschende Sprache
C#
Sterne
3
Forks
7
Ø Merge
1 T. 12 Std.
Gemergte PRs (30 T.)
14

Beschreibung

## Why

Today the MCP server relies solely on **origin-header validation** and localhost binding — safe for a single-user local machine, but there is **no authorization layer**. Any **remote, hosted, or shared** agent deployment (team agent, CI runner, cloud-hosted assistant) currently has no supported way to authenticate a caller. The MCP spec defines an **OAuth 2.1 authorization-code flow** for exactly this; adopting it unlocks hosted/agentic scenarios without falling back to master keys.

This is the natural companion to confirmation/elicitation (item M3): authorization answers *"who is allowed to call,"* M3 answers *"what may they do."*

## Proposed behavior

- Implement the MCP **authorization-code flow** for the HTTP transport: advertise the authorization server, validate bearer tokens on each request, and map the authenticated identity onto the shell's existing Entra/RBAC connection so tool calls run with **least-privilege, per-caller** credentials rather than a shared session.
- Keep localhost/no-auth as an explicit opt-in for the current single-user experience.

## Acceptance criteria

- Unauthenticated remote requests are rejected.
- A client can complete the authorization-code flow and call tools with a bearer token.
- Identity flows to the Cosmos/ARM credential.
- Localhost no-auth mode preserved behind a flag.
- Threat model + `docs/mcp.md` updated.

---
_Filed from the Agentic & Automation Roadmap (`docs/agentic-roadmap.md`), item **M7**, Wave 2. Priority P1._

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Beginne mit docs/mcp.md und docs/agentic-roadmap.md, insbesondere mit dem Roadmap-Eintrag M7, und verfolge dann den HTTP-Transport sowie den bestehenden Entra/RBAC-Anmeldeinformationspfad. Erledigt ist die Aufgabe, wenn nicht authentifizierte Remote-Anfragen abgewiesen werden, die Autorisierung per Bearer-Token funktioniert, die Identität die Cosmos/ARM-Anmeldeinformationen erreicht, die No-Auth-Funktion für localhost weiterhin durch ein Flag gesteuert wird und das Threat Model sowie die Dokumentation aktualisiert sind.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
azure, csharp
Bereich
authentication, authorization, cli, security
Issue-Typ
Feature
Schwierigkeit
5/5
Geschätzter Aufwand
Über eine Woche
Aktivitätsstatus
Aktiv
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
35/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.