Repository navigation
auth: check token expiry before required scopes - #1350
Merged
guglielmo-san merged 1 commit intoOct 7, 2026
Merged
guglielmo-san merged 1 commit into
guglielmo-san merged 1 commit into
Conversation
verify checked the required scopes before the token's expiration, so a token that was both expired and missing a required scope was rejected with 403 "insufficient scope" instead of 401 "token expired". Per RFC 6750 section 3.1, an expired token is invalid_token (401). It grants nothing, so it cannot have insufficient scope (403). The 403 tells the client to request more scopes when it needs a new token. Check expiration, including a missing expiration, before scopes. Fixes modelcontextprotocol#1349 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
guglielmo-san
approved these changes
Oct 7, 2026
Contributor
|
@ilaigold thank you for the contribution! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
While reading
RequireBearerTokenI noticed thatverifychecks required scopes before expiry. A token that's expired and also missing a scope gets403 insufficient scopeinstead of401 token expired, and a token with no expiration gets the same 403 whenAllowMissingExpirationis false. Repro is in #1349.An expired token is
invalid_token(RFC 6750 §3.1), so the client should be told to get a new token, not to ask for more scopes. I moved the expiry check, including the missing-expiration case, above the scope loop. No API change.This touches the same lines in
verifyandTestVerifyas #1135. If that one lands first I'll rebase on it.Tested with go1.27.1 on darwin/arm64:
TestVerifycases ("expired and missing scope", "no expiration and missing scope") fail on main withgot ("insufficient scope", 403)and pass with the fix.gofmt -l authandgo vet ./...are clean, andgo test -count=1 ./...passes.401 token expired.Fixes #1349
AI assistance: I used Claude Code to help write this fix and the tests.
🤖 Generated with Claude Code