Azure / Azure/data-api-builder
centralize role resolution across all MCP tools
- Vorherrschende Sprache
- C#
- Sterne
- 1.5k
- Forks
- 370
- Ø Merge
- 3 T. 17 Std.
- Gemergte PRs (30 T.)
- 8
Beschreibung
**Related PR:** [#3737 — MSRC 31000000666371: MCP `describe_entities` info-disclosure fix + single-role alignment](https://github.com/Azure/data-api-builder/pull/3737)
## Proposed fix
Add a single choke point on `McpAuthorizationHelper` that every MCP tool calls to obtain the caller's role:
```csharp
public static bool TryResolveValidatedRole(
HttpContext httpContext,
IAuthorizationResolver authResolver,
out string? role);
```
Behavior:
- Delegates validation to `IAuthorizationResolver.IsValidRoleContext` (exactly-one non-empty header value + `HttpContext.User.IsInRole(header)`).
- Returns the validated `X-MS-API-ROLE` header value verbatim as the single role for the request.
- Is the only place any MCP code reads `AuthorizationResolver.CLIENT_ROLE_HEADER`.
Then refactor every MCP tool to call it: `DescribeEntitiesTool`, `AggregateRecordsTool`, `CreateRecordTool`, `DeleteRecordTool`, `ExecuteEntityTool`, `ReadRecordsTool`, `UpdateRecordTool`, `DynamicCustomTool`.
## Design
- **Single-role model.** `X-MS-API-ROLE` is one atomic role. No splitting, no unioning. Matches REST, GraphQL, and DAB's existing `ClientRoleHeaderAuthorizationMiddleware`.
- **Resolver-owned inheritance.** Per-entity authorization goes through `IAuthorizationResolver.AreRoleAndOperationDefinedForEntity` / `GetAllowedExposedColumns`, so `anonymous → authenticated → named` inheritance and wildcard `All` expansion are consistent with REST/GraphQL.
- **One header read.** `AuthorizationResolver.CLIENT_ROLE_HEADER` appears in exactly one MCP file after this change.
## Acceptance
- `grep AuthorizationResolver.CLIENT_ROLE_HEADER src/Azure.DataApiBuilder.Mcp/**` returns one match, in `McpAuthorizationHelper`.
- No `.Split(',')` on the role header anywhere in the MCP project.
- All MCP tools use `TryResolveValidatedRole`; existing tests still pass.
## Non-goals
- No resolver behavior changes.
- No config schema changes.
- No new live-database tests.
## Reference
See [PR #3737](https://github.com/Azure/data-api-builder/pull/3737) for the single-role model, the MSRC fix in `DescribeEntitiesTool`, and the `McpAuthorizationHelper.TryResolveAuthorizedRole` alignment this issue builds on.
Beitragsleitfaden
Rechercherichtung
Lesen Sie McpAuthorizationHelper und die acht benannten MCP-Tool-Einstiegspunkte und vergleichen Sie anschließend die vorhandenen Alignment- und Sicherheitsänderungen in PR #3737. Verifizieren Sie, dass der Role-Header nur in McpAuthorizationHelper gelesen wird, kein MCP-Code ihn aufteilt, jedes Tool TryResolveValidatedRole verwendet und die vorhandenen Tests bestehen.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Tech-Stack
- csharp
- Bereich
- backend-api-design, security
- Issue-Typ
- Refactoring
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Aktivitätsstatus
- Ruhig
- Klarheit
- Klar beschrieben
- Anfängerfreundlichkeit
- 55/100