cgreene / cgreene/farewright

Deploy a throwaway remote MCP host/auth feasibility slice

Open
#4 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

infrastructure security workstream:agent workstream:auth-payments workstream:deployment
Dominant language
No language data
Stars
0
Forks
0
Avg merge
8h 21m
Merged PRs (30d)
2

Description

Outcome

A minimal public slice proves the real user-facing host path before product architecture depends on it.

Scope

  • Serve protected-resource and authorization-server discovery over public HTTPS.
  • Prove one scoped read and one scoped mutation with normalized principal context.
  • Exercise login, consent, revocation, and a short-lived mobile browser link.
  • Keep the slice throwaway: no product state machine or demo choreography.

Acceptance

  • The target host connects to the deployed MCP URL from a cold account.
  • Google login reaches Farewright through a candidate authorization-server profile.
  • Read and mutation scopes are enforced and revocation blocks a later call.
  • The mobile browser link completes on the intended device/session.
  • Observed product, plan, version, URLs, and limitations are recorded without secrets.

Dependencies

  • External setup issue complete enough to supply candidate credentials.
  • GitHub foundation issue complete enough for a reviewed spike PR.

Review

Security-sensitive spike evidence must be reviewed by a model session that did not implement it.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No files or tests are named; start with the deployed MCP URL and candidate authorization-server profile after the external setup and GitHub foundation dependencies are ready. Exercise the listed login, scoped read and mutation, revocation, and mobile-link acceptance cases, then record the observed product, plan, version, URLs, and limitations without secrets.

Written by the indexing model from the issue text.

Assessment

Domain
api, authentication, cloud, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.