M7. MCP authorization (OAuth code flow)
- Langage dominant
- C#
- Étoiles
- 3
- Forks
- 7
- Merge moyen
- 1 j 12 h
- PR mergées (30 j)
- 14
Description
## Why
Today the MCP server relies solely on **origin-header validation** and localhost binding — safe for a single-user local machine, but there is **no authorization layer**. Any **remote, hosted, or shared** agent deployment (team agent, CI runner, cloud-hosted assistant) currently has no supported way to authenticate a caller. The MCP spec defines an **OAuth 2.1 authorization-code flow** for exactly this; adopting it unlocks hosted/agentic scenarios without falling back to master keys.
This is the natural companion to confirmation/elicitation (item M3): authorization answers *"who is allowed to call,"* M3 answers *"what may they do."*
## Proposed behavior
- Implement the MCP **authorization-code flow** for the HTTP transport: advertise the authorization server, validate bearer tokens on each request, and map the authenticated identity onto the shell's existing Entra/RBAC connection so tool calls run with **least-privilege, per-caller** credentials rather than a shared session.
- Keep localhost/no-auth as an explicit opt-in for the current single-user experience.
## Acceptance criteria
- Unauthenticated remote requests are rejected.
- A client can complete the authorization-code flow and call tools with a bearer token.
- Identity flows to the Cosmos/ARM credential.
- Localhost no-auth mode preserved behind a flag.
- Threat model + `docs/mcp.md` updated.
---
_Filed from the Agentic & Automation Roadmap (`docs/agentic-roadmap.md`), item **M7**, Wave 2. Priority P1._
Guide de contribution
Ouvrir le guide de contribution
Piste de recherche
Commencez par docs/mcp.md et docs/agentic-roadmap.md, en particulier l’élément M7 de la feuille de route, puis suivez le transport HTTP et le chemin existant des informations d’identification Entra/RBAC. Le travail est terminé lorsque les requêtes distantes non authentifiées sont rejetées, que l’autorisation par bearer token fonctionne, que l’identité parvient aux informations d’identification Cosmos/ARM, que l’absence d’authentification sur localhost reste contrôlée par un flag, et que le modèle de menace et la documentation sont mis à jour.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Évaluation
- Stack technique
- azure, csharp
- Domaine
- authentication, authorization, cli, security
- Type d'issue
- Fonctionnalité
- Difficulté
- 5/5
- Temps estimé
- Plus d'une semaine
- Activité
- Active
- Clarté
- Plutôt claire
- Accessibilité débutants
- 35/100