modelcontextprotocol / modelcontextprotocol/python-sdk

Implement server-side support for Client ID Metadata Documents (CIMD)

未關閉
#1,801 3 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視

還沒有人認領這個 Issue。

auth enhancement needs decision P2
主要語言
Python
星號
24.3k
分支
4k
平均合併
1 天 1 小時
30 天內合併 PR
31

描述

Summary

PR #1652 implemented client-side support for Client ID Metadata Documents (CIMD) per SEP-991, but the server-side implementation is missing. Authorization servers built with the Python SDK cannot currently support CIMD.

Background

CIMD (draft-ietf-oauth-client-id-metadata-document-00) allows OAuth clients to use HTTPS URLs as client identifiers, where the URL points to a JSON document containing client metadata. This is the recommended registration approach per the MCP spec (ahead of DCR).

From the MCP Authorization spec:

Authorization servers and MCP clients SHOULD support OAuth Client ID Metadata Documents

Current State

Client-side (implemented in #1652)
  • is_valid_client_metadata_url() - validates HTTPS URLs with path component
  • should_use_client_metadata_url() - checks if server advertises CIMD support
  • create_client_info_from_metadata_url() - uses URL as client_id
  • ✅ OAuth flow integration with DCR fallback
Server-side (missing)
  • ❌ Never advertises client_id_metadata_document_supported=true in OAuth metadata
  • ❌ No detection of URL-formatted client_ids
  • ❌ No metadata document fetching
  • ❌ No validation (client_id matching, redirect_uri verification, document structure)
  • ❌ No caching infrastructure
  • ❌ No SSRF protection for fetching

Spec Requirements for Authorization Servers

From the MCP spec and CIMD RFC:

Requirement Level
Fetch metadata documents when encountering URL-formatted client_ids SHOULD
Validate that fetched document's client_id matches the URL exactly MUST
Validate redirect URIs against those in the metadata document MUST
Validate document structure is valid JSON with required fields MUST
Cache metadata respecting HTTP cache headers SHOULD
Protect against SSRF attacks SHOULD
Limit document size (~5KB recommended) SHOULD
Display client_id hostname during consent SHOULD
Never cache error responses MUST NOT

References

AI Disclaimer

貢獻指南

開啟貢獻指南

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

研究方向

先檢視 PR #1652 中的用戶端 CIMD 支援,以及 SDK 的 OAuth 中繼資料和伺服器端授權處理。將缺少的 URL client_id 偵測、文件擷取、驗證、快取和 SSRF 防護對應到現有進入點。完成標準是授權伺服器宣告支援 CIMD,並在不快取錯誤的情況下滿足列出的 CIMD 和 MCP 要求。

由索引模型根據 Issue 內容生成。

評估

技術堆疊
python
領域
api, authentication, backend, security
Issue 類型
功能
難度
5/5
預估耗時
一週以上
活躍度
停滯
描述清晰度
基本清楚
新手友好度
35/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。