modelcontextprotocol / modelcontextprotocol/python-sdk
Enable FastMCP to filter tools, prompts, resources using a fine grained policy
Dieses Issue hat noch niemand übernommen.
- Vorherrschende Sprache
- Python
- Sterne
- 24.3k
- Forks
- 4k
- Ø Merge
- 1 T. 1 Std.
- Gemergte PRs (30 T.)
- 31
Beschreibung
Description
The authorization protocol allows MCP to implement course grained authorization checks e.g. a principal can/cannot access the server.
For advanced use cases though it is useful to be able to limit access on a per tool/resource/prompt basis.
There are a range of authorization tools that can be used however rather than being specific I suggest it is better to provide a plugin API that allows providers to pick their underlying authorization approach.
I have a patch that shows this idea, I'll open a draft pull request to illustrate the idea and allow for further testing & refinement.
References
No response
Beitragsleitfaden
Erste Schritte
- Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
- Forke das Repository und arbeite in einem Branch.
- Öffne einen Pull Request, der die Issue-Nummer nennt.
Rechercherichtung
Beginne damit, den Vorschlag zur feingranularen Autorisierung und den im Issue erwähnten Patch zu prüfen, und vergleiche sie anschließend mit dem MCP-Autorisierungsprotokoll. Die Arbeit ist abgeschlossen, wenn FastMCP eine Provider-Plugin-API bereitstellt, die den Zugriff auf Tools, Prompts und Ressourcen unabhängig voneinander erlauben oder verweigern kann und der Ansatz durch Tests verfeinert wurde.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Tech-Stack
- python
- Bereich
- api, security
- Issue-Typ
- Feature
- Schwierigkeit
- 5/5
- Geschätzter Aufwand
- Über eine Woche
- Aktivitätsstatus
- Ruhig
- Klarheit
- Größtenteils klar
- Anfängerfreundlichkeit
- 35/100