Azure / Azure/data-api-builder

centralize role resolution across all MCP tools

Open
#3,757 0 comments 0 reactions 0 assignees View on GitHub
mcp-server
Dominant language
C#
Stars
1.5k
Forks
370
Avg merge
3d 17h
Merged PRs (30d)
8

Description

**Related PR:** [#3737 — MSRC 31000000666371: MCP `describe_entities` info-disclosure fix + single-role alignment](https://github.com/Azure/data-api-builder/pull/3737)

## Proposed fix

Add a single choke point on `McpAuthorizationHelper` that every MCP tool calls to obtain the caller's role:

```csharp
public static bool TryResolveValidatedRole(
HttpContext httpContext,
IAuthorizationResolver authResolver,
out string? role);
```

Behavior:
- Delegates validation to `IAuthorizationResolver.IsValidRoleContext` (exactly-one non-empty header value + `HttpContext.User.IsInRole(header)`).
- Returns the validated `X-MS-API-ROLE` header value verbatim as the single role for the request.
- Is the only place any MCP code reads `AuthorizationResolver.CLIENT_ROLE_HEADER`.

Then refactor every MCP tool to call it: `DescribeEntitiesTool`, `AggregateRecordsTool`, `CreateRecordTool`, `DeleteRecordTool`, `ExecuteEntityTool`, `ReadRecordsTool`, `UpdateRecordTool`, `DynamicCustomTool`.

## Design

- **Single-role model.** `X-MS-API-ROLE` is one atomic role. No splitting, no unioning. Matches REST, GraphQL, and DAB's existing `ClientRoleHeaderAuthorizationMiddleware`.
- **Resolver-owned inheritance.** Per-entity authorization goes through `IAuthorizationResolver.AreRoleAndOperationDefinedForEntity` / `GetAllowedExposedColumns`, so `anonymous → authenticated → named` inheritance and wildcard `All` expansion are consistent with REST/GraphQL.
- **One header read.** `AuthorizationResolver.CLIENT_ROLE_HEADER` appears in exactly one MCP file after this change.

## Acceptance

- `grep AuthorizationResolver.CLIENT_ROLE_HEADER src/Azure.DataApiBuilder.Mcp/**` returns one match, in `McpAuthorizationHelper`.
- No `.Split(',')` on the role header anywhere in the MCP project.
- All MCP tools use `TryResolveValidatedRole`; existing tests still pass.

## Non-goals

- No resolver behavior changes.
- No config schema changes.
- No new live-database tests.

## Reference

See [PR #3737](https://github.com/Azure/data-api-builder/pull/3737) for the single-role model, the MSRC fix in `DescribeEntitiesTool`, and the `McpAuthorizationHelper.TryResolveAuthorizedRole` alignment this issue builds on.

Contributor guide

Open the contributing guide

Research direction

Read McpAuthorizationHelper and the eight named MCP tool entry points, then compare the existing alignment and security changes in PR #3737. Verify the role header is read only in McpAuthorizationHelper, no MCP code splits it, every tool uses TryResolveValidatedRole, and the existing tests pass.

Written by the indexing model from the issue text.

Assessment

Tech stack
csharp
Domain
backend-api-design, security
Issue type
Refactor
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Clearly specified
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.