modelcontextprotocol / modelcontextprotocol/php-sdk

[2026-07-28] Authorization hardening (OAuth/OIDC)

Offen
#338 0 Kommentare 1 Reaktion 0 zugewiesene Personen Auf GitHub ansehen

Dieses Issue hat noch niemand übernommen.

2026-07-28 auth Client enhancement improves spec compliance Server
Vorherrschende Sprache
PHP
Sterne
1.6k
Forks
173
Ø Merge
2 T. 49 Min.
Gemergte PRs (30 T.)
23

Beschreibung

Tracking issue for the MCP Spec 2026-07-28 releaseAuthorization hardening milestone.

Most of this milestone overlaps with the existing client-OAuth backlog (#315–#326). New SEP-specific work concentrates on issuer validation, AS-binding semantics, server-side scope emission, and OIDC offline_access handling.

SEPs covered

SEP Title Spec PR Coverage
SEP-2468 Recommend iss Parameter (RFC 9207) #2468 New issue
SEP-2352 Authorization Server binding and migration #2352 New issue
SEP-2351 RFC 8414 well-known URI suffix #2351 Covered by #318
SEP-2350 Client-side scope accumulation in step-up #2350 Client covered by #322; new server-side issue
SEP-2207 OIDC-flavored refresh token guidance #2207 New issues (client + server)
SEP-837 OIDC application_type during DCR #837 Covered by #320 + #321

Sub-issues

  • #360 — SEP-2468: Validate iss parameter in authorization response (client)
  • #361 — SEP-2352: Key DCR/tokens by AS issuer; reject cross-AS reuse (client)
  • #362 — SEP-2350: Emit per-operation scopes in insufficient_scope 403 responses (server)
  • #363 — SEP-2207: Request offline_access against OIDC-flavored AS (client)
  • #364 — SEP-2207: Audit PRM to ensure offline_access is not advertised as required (server)

Existing issues to annotate with SEP refs

  • #315 (TokenStorage) → SEP-2352
  • #318 (RFC 8414 AS metadata) → SEP-2351
  • #319 (Auth Code + PKCE) → SEP-2468, SEP-2207
  • #320 (DCR) → SEP-2352, SEP-837
  • #321 (token_endpoint_auth_method) → SEP-837
  • #322 (scope handling/step-up) → SEP-2350
  • #323 (refresh_token grant) → SEP-2207

Notes

  • All six SEPs are merged.
  • PHP SDK client-side OAuth is largely unimplemented; the bulk of work is therefore on the client side via the existing #315–#326 backlog plus the new SEP-specific issues above. Server-side OAuth middleware needs targeted PRM/WWW-Authenticate audits only.

Beitragsleitfaden

Beitragsleitfaden öffnen

Erste Schritte

  1. Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
  3. Forke das Repository und arbeite in einem Branch.
  4. Öffne einen Pull Request, der die Issue-Nummer nennt.

Rechercherichtung

Beginne mit der Durchsicht der Unteraufgaben #360–#364 und des zugehörigen OAuth-Backlogs #315–#326. Lies anschließend die verknüpften SEP-Referenzen und die vorhandene Autorisierungsimplementierung. Dieses Tracking-Issue ist abgeschlossen, sobald seine fünf Unteraufgaben gelöst und die aufgeführten PRM- und WWW-Authenticate-Audits abgeschlossen sind.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
php
Bereich
authentication, security
Issue-Typ
Feature
Schwierigkeit
5/5
Geschätzter Aufwand
Über eine Woche
Aktivitätsstatus
Ruhig
Klarheit
Muss geklärt werden
Anfängerfreundlichkeit
25/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.