Skip to content

auth: drop the query from the 2025-03-26 fallback authorization base URL - #1348

Open
akshita317 wants to merge 1 commit into
modelcontextprotocol:mainfrom
akshita317:auth/backcompat-base-url-query
Open

akshita317 wants to merge 1 commit into
modelcontextprotocol:mainfrom
akshita317:auth/backcompat-base-url-query

Conversation

@akshita317

Copy link
Copy Markdown
Contributor

When an MCP server publishes no protected resource metadata, AuthorizationCodeHandler falls back to the 2025-03-26 rule: the authorization base URL is the MCP server URL with its path discarded. getProtectedResourceMetadata cleared only the path, so a query or fragment on the server URL stayed in the base URL.

For a server at https://api.example.com/mcp?tenant=acme, the issuer became https://api.example.com?tenant=acme. Metadata served at the root names the issuer https://api.example.com, so GetAuthServerMeta rejected it ("metadata issuer … does not match issuer URL") and Authorize failed. Without metadata, the default endpoints were built by concatenation into https://api.example.com?tenant=acme/authorize.

This builds the base URL from the scheme and authority only. Protected resource metadata discovery is unchanged: RFC 9728 §3.1 keeps the query when inserting the well-known suffix.

Tests (both fail without the change):

  • TestGetProtectedResourceMetadata_BackcompatDropsQuery: a query, a fragment, an empty ?, and a query with no path all give http://localhost:1234.
  • TestAuthorize_BackcompatServerURLWithQuery: the full flow against the fake authorization server, reached at /mcp?tenant=acme, now gets a token.

Fixes #1347

AI assistance: prepared with Claude Code.

🤖 Generated with Claude Code

When an MCP server publishes no protected resource metadata, the
authorization code handler falls back to the 2025-03-26 rule: the
authorization base URL is the MCP server URL with its path discarded.
getProtectedResourceMetadata cleared only the path, so a query or
fragment on the server URL stayed in the base URL.

For a server at https://api.example.com/mcp?tenant=acme the issuer
became https://api.example.com?tenant=acme. Metadata served at the root
names the issuer https://api.example.com, so GetAuthServerMeta rejected
it with "metadata issuer ... does not match issuer URL" and Authorize
failed. Without metadata, the default endpoints were built by string
concatenation into https://api.example.com?tenant=acme/authorize.

Build the base URL from the scheme and authority only.

Fixes modelcontextprotocol#1347

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Akshita kumari <110122283+akshita317@users.noreply.github.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

auth: Authorize fails against a 2025-03-26 server whose URL has a query string

1 participant