modelcontextprotocol / modelcontextprotocol/csharp-sdk

Not able to customize the url '.well-known/oauth-protected-resource' behind AKS/nginx ingress

オープン
#643 コメント 7 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

area-auth bug help wanted needs confirmation P3
主要言語
C#
スター
4.5k
フォーク
814
平均マージ
9日 19時間
マージ済み PR(30日)
4

説明

Describe the bug
When we enable OAuth (using Entra) for the MCP server it produces the well known resource url through '/.well-known/oauth-protected-resource'.

.AddMcp(options =>
{
    var metadata = new ModelContextProtocol.Authentication.ProtectedResourceMetadata()
    {
        Resource = new Uri(serverAddress + "api/mcp"),
        AuthorizationServers = { new Uri($"{instance}/{tenantId}/v2.0") },
        ScopesSupported = [$"{apiAppName}/Mcp.Access"],
    };

    options.ResourceMetadata = metadata;
});
...
...
app.MapMcp("/api/mcp").RequireAuthorization();

Now when we deploy this behind an ingress controller with path redirects, the MCP client doesn't have a way to know the modified resource url that it needs to connect.

E.g. if I deploy the server from this base route 'https://abc.azure.com/sanjayd' with ingress redirects, we can ideally reach the mcp server at 'https://abc.azure.com/sanjayd/api/mcp', and that will throw 401. But all clients including VS Code etc. now tries to connect to 'https://abc.azure.com/.well-known/oauth-protected-resource' to download the metadata. Ideally there should be a way to mention the base route for metadata while using ingress.

1st call from client: POST https://abc.azure.com/sanjayd/api/mcp -> returns 401 with 'www-authenticate' header like 'Bearer realm="McpAuth", resource_metadata="http://10.10.1.40/.well-known/oauth-protected-resource"'

2nd call from client: GET https://abc.azure.com/.well-known/oauth-protected-resource -> missing the 'sanjayd' part.

This works locally though as there is no ingress/re-route.

Any help is appreciated on how this will work with ingress.

Below are from a web client
Image

Image

コントリビューションガイド

コントリビューションガイドを開く

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

調査の方向性

AddMcp ResourceMetadata 構成と app.MapMcp("/api/mcp") エントリポイントから始め、AKS/nginx の ingress パスの背後にデプロイされたときに WWW-Authenticate の resource_metadata URL がどのように生成されるかを追跡します。/sanjayd/api/mcp フローを再現し、クライアントがベースルートを維持したままメタデータを取得できることを確認します。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
azure, csharp, kubernetes, nginx
領域
api, authentication, cloud
issue の種類
バグ
難易度
4/5
見積もり時間
3〜5日
活発さ
静か
明瞭さ
おおむね明確
初心者へのやさしさ
45/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。