spring-projects / spring-projects/spring-security

Courtesy notice: unofficial MCP server for Spring Security documentation

Open
#19,248 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

status: waiting-for-triage type: enhancement
Dominant language
Java
Stars
9.6k
Forks
6.3k
Avg merge
2d 11h
Merged PRs (30d)
52

Description

Hello Spring Security team,

I am working on an unofficial MCP (Model Context Protocol) server for searching and referencing Spring Security documentation from MCP-compatible clients.

Repository:
https://github.com/shutx-net/spring-security-documentation-mcp-server

Hosted experimental endpoint:
https://ss-doc-mcp.shutx.net/mcp

The intent of this project is documentation-oriented search and retrieval only. It is not intended to replace the official Spring Security documentation or any official support channel.

The repository and README state that this is an unofficial community project and that it is not affiliated with, endorsed by, sponsored by, or maintained by the Spring Security team, VMware, Broadcom, or the Spring project.

The project may fetch, build, parse, or index content from the official Spring Security repository and documentation in order to provide MCP tools for documentation search and retrieval. The Spring Security repository is treated as an upstream source for documentation indexing, not as code owned or maintained by this project.

The project does not intend to:

  • claim ownership of Spring Security source code or documentation
  • present itself as an official Spring Security distribution
  • imply endorsement by the Spring Security team or the Spring project
  • publish patched Spring Security source code
  • modify the upstream Spring Security project
  • remove or obscure upstream attribution
  • replace the official Spring Security documentation
  • provide official Spring Security support

Where possible, indexed or returned content should preserve attribution metadata such as upstream repository URL, documentation version or branch, commit SHA, official documentation URL, build timestamp, and heading path or page title. Search results should link back to the official Spring Security documentation whenever possible.

I wanted to open this issue as a courtesy notice before making the project more widely available and to ask whether the Spring Security team has any concerns or preferences regarding:

  1. Naming or wording that should be avoided to prevent implying official endorsement
  2. Attribution or disclaimer wording
  3. Use of the Spring Security reference documentation for indexing and MCP-based retrieval
  4. Preferred metadata to preserve when referencing documentation, such as version, branch, commit SHA, or official documentation URL
  5. Any other concerns with this kind of unofficial documentation-focused MCP server

If any naming, wording, attribution, or disclaimer in the repository is inappropriate, I am happy to revise it.

Thank you for your time and for maintaining Spring Security.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the external MCP server repository and its README, then compare its naming, disclaimers, attribution, and metadata references with the concerns listed here. Done means receiving or recording the Spring Security team’s guidance; this issue does not specify a change to the Spring Security repository.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, spring
Domain
documentation, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.