Claude
4ff2ab8e54
fix(auth): include RFC 6750 scope attribute in WWW-Authenticate challenges
...
RequireAuthMiddleware built its 401/403 WWW-Authenticate challenges with
error/error_description (and optional resource_metadata) but never the
scope attribute, even though required_scopes is configured on the
middleware instance. Clients therefore could not discover the required
scopes from the challenge: the SDK client reads scope from
WWW-Authenticate as the highest-priority source both for initial
authorization (401) and for SEP-2350 step-up on 403 insufficient_scope,
so that path was always empty and fell back to protected resource
metadata scopes_supported.
Emit scope="<space-delimited required_scopes>" whenever required_scopes
is non-empty, per RFC 6750 section 3 (section 3.1 for the
insufficient_scope case).
Fixes #3103
2026-08-11 05:29:09 +00:00
Marcelo Trylesinski
2713b53b12
Replace httpx and httpx-sse with httpx2 ( #2972 )
...
CI / checks (push) Failing after 1s
CI / all-green (push) Has been cancelled
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2026-07-14 17:05:08 +01:00
Max
7322ca56f4
Require integrity protection for MRTR requestState ( #3032 )
2026-06-30 21:30:32 +01:00
Marcelo Trylesinski
c0ecb70e24
Support RFC 8693 token exchange for enterprise IdP flows (SEP-990) ( #2988 )
...
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2026-06-26 17:57:10 +02:00
Marcelo Trylesinski
f41a5193f3
Preserve empty issuer/resource paths on AuthSettings ( #2987 )
2026-06-26 11:41:41 +02:00
Max Isbey
0e96aecd1d
fix: use exact match for loopback hosts in issuer URL validation ( #2089 )
2026-02-18 19:40:52 +00:00
Marcelo Trylesinski
65c614e48e
Rename FastMCP to MCPServer ( #1951 )
2026-01-25 14:45:52 +01:00
Marcelo Trylesinski
d77292fb06
refactor: drop test classes ( #1924 )
2026-01-22 12:37:52 +01:00
Felix Weinberger
d41d0c0128
chore: add D212 lint rule to enforce Google-style docstrings ( #1892 )
2026-01-16 16:10:52 +00:00
Max Isbey
5d80f4efc8
refactor: move inline imports to module level ( #1893 )
2026-01-16 14:54:08 +00:00
Marcelo Trylesinski
6149b63a44
tests: add missing init files ( #1831 )
2026-01-06 19:52:09 +01:00
Max Isbey
89e9c43acf
Get baseline 100% clean coverage ( #1553 )
2025-11-11 14:09:32 +01:00
Marcus Shu
df3e428ee8
Improve OAuth protected resource metadata URL construction per RFC 9728 ( #1407 )
2025-10-06 13:52:44 +01:00
Yann Jouanin
20596e5f41
Add test for ProtectedResourceMetadataParsing ( #1236 )
...
Co-authored-by: Paul Carleton <paulcarletonjr@gmail.com >
Co-authored-by: Marcelo Trylesinski <marcelotryle@gmail.com >
Co-authored-by: Felix Weinberger <3823880+felixweinberger@users.noreply.github.com >
2025-09-23 12:48:21 +01:00
San Nguyen
eaf7cf41d5
fix: error too many values to unpack (expected 2) ( #1279 )
...
Signed-off-by: San Nguyen <vinhsannguyen91@gmail.com >
Co-authored-by: Felix Weinberger <fweinberger@anthropic.com >
Co-authored-by: Felix Weinberger <3823880+felixweinberger@users.noreply.github.com >
2025-08-23 21:36:39 +01:00
Marcelo Trylesinski
c7671e470c
Add pyright strict mode on the whole project ( #1254 )
2025-08-11 18:56:37 +01:00
Inna Harper
17f9c00c53
MCP server separation into Authorization Server (AS) and Resource Server (RS) roles per spec PR #338 ( #982 )
...
Co-authored-by: Paul Carleton <paulc@anthropic.com >
2025-06-23 14:19:03 +01:00
Marcelo Trylesinski
543961968c
Use 120 characters instead of 88 ( #856 )
2025-06-11 11:45:50 +02:00
yabea
a1307abded
Fix the issue of get Authorization header fails during bearer auth ( #637 )
...
Co-authored-by: yangben <yangben@zhihu.com >
2025-05-07 17:42:02 +01:00
Peter Raboud
2210c1be18
Add support for serverside oauth ( #255 )
...
Main branch checks / checks (push) Failing after 0s
Check uv.lock / check-lock (push) Has been cancelled
Co-authored-by: David Soria Parra <davidsp@anthropic.com >
Co-authored-by: Basil Hosmer <basil@anthropic.com >
Co-authored-by: ihrpr <inna@anthropic.com >
2025-05-01 19:42:59 +01:00