Files
Max Isbey bad42e2841 Emit RFC 6750 scope= in WWW-Authenticate and validate token audience
BearerAuthBackend / RequireAuthMiddleware now produce spec-conformant
challenges and reject tokens issued for a different resource server.

- A request with no credentials gets a bare `Bearer` challenge (with
  scope/resource_metadata only), not error="invalid_token" -- RFC 6750
  Section 3.1 says the error attribute SHOULD NOT appear when no
  authentication information was presented.
- A malformed/unknown token, an expired token, or a token whose audience
  does not match the configured resource_server_url is answered 401
  invalid_token with a specific error_description, carried via a new
  InvalidTokenUser marker so the middleware can distinguish it from
  no-credentials.
- All challenges (401 and the 403 insufficient_scope path) now advertise
  the required scopes in a `scope=` parameter, which the SDK client
  already reads to drive step-up.
- New check_token_audience() helper canonicalises default ports before
  comparing, and is wired through both the lowlevel and MCPServer
  Starlette stacks via the auth settings' resource_server_url.

Docs and migration guide updated; the corresponding interaction-suite
divergence entries are now closed.
2026-06-27 18:53:13 +00:00
..