modelcontextprotocol / modelcontextprotocol/python-sdk

Enable FastMCP to filter tools, prompts, resources using a fine grained policy

Offen
#1,031 3 Kommentare 2 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Dieses Issue hat noch niemand übernommen.

auth enhancement v2
Vorherrschende Sprache
Python
Sterne
24.3k
Forks
4k
Ø Merge
1 T. 1 Std.
Gemergte PRs (30 T.)
31

Beschreibung

Description

The authorization protocol allows MCP to implement course grained authorization checks e.g. a principal can/cannot access the server.

For advanced use cases though it is useful to be able to limit access on a per tool/resource/prompt basis.

There are a range of authorization tools that can be used however rather than being specific I suggest it is better to provide a plugin API that allows providers to pick their underlying authorization approach.

I have a patch that shows this idea, I'll open a draft pull request to illustrate the idea and allow for further testing & refinement.

References

No response

Beitragsleitfaden

Beitragsleitfaden öffnen

Erste Schritte

  1. Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
  3. Forke das Repository und arbeite in einem Branch.
  4. Öffne einen Pull Request, der die Issue-Nummer nennt.

Rechercherichtung

Beginne damit, den Vorschlag zur feingranularen Autorisierung und den im Issue erwähnten Patch zu prüfen, und vergleiche sie anschließend mit dem MCP-Autorisierungsprotokoll. Die Arbeit ist abgeschlossen, wenn FastMCP eine Provider-Plugin-API bereitstellt, die den Zugriff auf Tools, Prompts und Ressourcen unabhängig voneinander erlauben oder verweigern kann und der Ansatz durch Tests verfeinert wurde.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
python
Bereich
api, security
Issue-Typ
Feature
Schwierigkeit
5/5
Geschätzter Aufwand
Über eine Woche
Aktivitätsstatus
Ruhig
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
35/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.