modelcontextprotocol / modelcontextprotocol/python-sdk
Server ClientAuthenticator requires client_id in token body, rejecting valid client_secret_basic requests (RFC 6749 §2.3.1)
Chưa có ai nhận issue này.
- Ngôn ngữ chính
- Python
- Star
- 24.3k
- Fork
- 4k
- Merge trung bình
- 1 ngày 1 giờ
- Pull request đã merge (30 ngày)
- 31
Mô tả
Summary
The server-side ClientAuthenticator reads client_id only from the token request form body and raises invalid_client: "Missing client_id" when it is absent — even when the client authenticated correctly via HTTP Basic (Authorization: Basic base64(client_id:client_secret)). Per RFC 6749 §2.3.1, a client using client_secret_basic sends its client_id and client_secret in the Authorization header and MAY omit them from the body. Servers advertising client_secret_basic in token_endpoint_auth_methods_supported therefore reject spec-compliant clients (e.g. clients that use Basic and do not duplicate client_id into the body).
Location
src/mcp/server/auth/middleware/client_auth.py, authenticate_request:
form_data = await request.form()
client_id = form_data.get("client_id")
if not client_id:
raise AuthenticationError("Missing client_id")
...
if client.token_endpoint_auth_method == "client_secret_basic":
...
basic_client_id, request_client_secret = decoded.split(":", 1)
basic_client_id = unquote(basic_client_id)
if basic_client_id != client_id: # only cross-checks; never used as fallback
raise AuthenticationError("Client ID mismatch in Basic auth")
client_id from the Basic header is only used to cross-check a body-supplied value; it is never used as a fallback source. So a request with credentials solely in the Basic header fails before the client is even looked up.
Steps to reproduce
- Register a client with
token_endpoint_auth_method=client_secret_basic. POST /tokenwithgrant_type=authorization_code,Authorization: Basic base64(client_id:client_secret), and noclient_id/client_secretin the form body.- Response:
401 {"error":"invalid_client","error_description":"Missing client_id"}.
Sending the same credentials via client_secret_post (in the body) works.
Expected
When Authorization: Basic is present, the authenticator should derive client_id from the header if it is absent from the body (RFC 6749 §2.3.1), then verify the secret as it does today.
Notes
This is the mirror image of client-side PR #3536 (which stops MCP clients from putting client_id in the body under client_secret_basic). With that client-side change, compliant clients will send client_id only in the Basic header — which this server-side code rejects. The two need to agree.
Observed on mcp 1.27.0.
Hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Hướng nghiên cứu
Bắt đầu trong src/mcp/server/auth/middleware/client_auth.py tại authenticate_request và theo dõi cách các trường biểu mẫu và thông tin xác thực HTTP Basic được phân tích. Tái hiện yêu cầu token với thông tin xác thực chỉ nằm trong tiêu đề Authorization, sau đó xác minh rằng việc xác thực client_secret_basic thành công, trong khi thông tin xác thực không khớp vẫn tạo ra lỗi xác thực được ghi lại trong tài liệu.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Đánh giá
- Công nghệ
- python
- Lĩnh vực
- api, authentication
- Loại issue
- Lỗi
- Độ khó
- 2/5
- Thời gian dự kiến
- 1-3 giờ
- Mức độ hoạt động
- Sôi nổi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức phù hợp với người mới
- 76/100