modelcontextprotocol / modelcontextprotocol/python-sdk
RequireAuthMiddleware omits RFC 6750 scope in WWW-Authenticate on 401/403
還沒有人認領這個 Issue。
- 主要語言
- Python
- 星號
- 24.3k
- 分支
- 4k
- 平均合併
- 1 天 1 小時
- 30 天內合併 PR
- 31
描述
Initial Checks
- I confirm that I'm using the latest version of MCP Python SDK
- I confirm that I searched for my issue in https://github.com/modelcontextprotocol/python-sdk/issues before opening this issue
Description
Summary
RequireAuthMiddleware._send_auth_error builds WWW-Authenticate with error and error_description (and optional resource_metadata), but never includes the scope parameter, even when required_scopes is configured.
This breaks RFC 6750 Section 3.1 and the MCP Authorization scope-selection / step-up flow. The SDK client already expects scope via extract_scope_from_www_auth() and uses it in get_client_metadata_scopes() as the highest-priority source when handling 403 insufficient_scope.
Actual behavior
For a server configured with required_scopes=["api.read"]:
401 (no/invalid token):
WWW-Authenticate: Bearer error="invalid_token", error_description="Authentication required"
403 (token missing required scope):
WWW-Authenticate: Bearer error="insufficient_scope", error_description="Required scope: api.read"
Neither response includes scope="api.read".
Expected behavior
When required_scopes is non-empty, the challenge should include the RFC 6750 scope parameter, e.g.:
WWW-Authenticate: Bearer error="insufficient_scope", error_description="Required scope: api.read", scope="api.read"
(and similarly for 401 when scopes are configured, so the client can request the correct scopes on initial authorization).
Impact
- MCP clients cannot reliably discover required scopes from the challenge header.
- Step-up authorization falls back to PRM
scopes_supported(or omits scope), which is lower priority per the MCP scope selection strategy and can fail when PRM does not advertise scopes. - The SDK client already implements the correct consumer side; only server emission is missing.
Root cause
In src/mcp/server/auth/middleware/bearer_auth.py, _send_auth_error builds:
www_auth_parts = [f'error="{error}"', f'error_description="{description}"']
if self.resource_metadata_url:
www_auth_parts.append(f'resource_metadata="{self.resource_metadata_url}"')
It never appends scope= from self.required_scopes, which is already available on the middleware instance.
Present on both v1.x and main (verified in current source).
Suggested fix
When self.required_scopes is non-empty, append:
www_auth_parts.append(f'scope="{" ".join(self.required_scopes)}"')
Happy to open a PR against v1.x once a maintainer assigns this issue to me. Please also advise whether a follow-up for main (v2) is desired.
Example Code
Python & MCP Python SDK
Python: 3.14.6
MCP Python SDK: 1.28.1 (also reproduced against current v1.x / main source of RequireAuthMiddleware._send_auth_error)
貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
研究方向
從 src/mcp/server/auth/middleware/bearer_auth.py 開始,重點關注 RequireAuthMiddleware._send_auth_error 及其現有的 WWW-Authenticate 建構方式。檢查周圍的驗證回應涵蓋範圍,然後驗證已設定 required_scopes 時的 401 和 403 兩種情況;完成的標準是 challenge 暴露所需的 scope,同時保留現有參數。
由索引模型根據 Issue 內容生成。
評估
- 技術堆疊
- python
- 領域
- authentication, backend, security
- Issue 類型
- 缺陷
- 難度
- 2/5
- 預估耗時
- 1-3 小時
- 活躍度
- 冷清
- 描述清晰度
- 描述清楚
- 新手友好度
- 78/100