Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

OAuth discovery rejects cross-origin resource_metadata from WWW-Authenticate, breaking centralized PRM (SEP-985) deployments

Abierto
#1,298 1 comentario 1 reacción 0 asignados Ver en GitHub

Los mantenedores suelen responder en 3 días

@DaleSeo ya está trabajando en esto.

Desde el 26/9/2026.

  • #1302 de @DaleSeo — abierto

Evaluación

Dificultad
3/5
Tiempo estimado
1-2 días
Aptitud para principiantes
74/100
Tipo de issue
Error
Claridad
Bien especificado
Estado de actividad
Activo
Stack tecnológico
rust

Línea de trabajo

Start in crates/rmcp/src/transport/auth.rs at AuthorizationManager::resolve_resource_metadata_url, then trace discover_metadata and the OAuthState discovery flow. Reproduce the three-server cross-origin topology described in the issue and inspect the existing is_disallowed_metadata_host handling. Done means a permitted cross-origin resource_metadata URL is fetched, its authorization_servers value is used, and disallowed metadata hosts remain blocked.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

bug P1 ready for work T-security T-transport

Describe the bug
AuthorizationManager::resolve_resource_metadata_url (crates/rmcp/src/transport/auth.rs) unconditionally discards a resource_metadata URL from a WWW-Authenticate challenge when it is not same-origin (scheme+host+port) with the MCP resource:

https://github.com/modelcontextprotocol/rust-sdk/blob/main/crates/rmcp/src/transport/auth.rs

fn resolve_resource_metadata_url(value: &str, base_url: &Url) -> Option<Url> {
    ...
    if Self::is_same_origin_resource_metadata_url(base_url, &url) {
        Some(url)
    } else {
        warn!("rejecting resource metadata URL `{url}` because it is not same-origin with `{base_url}`");
        None
    }
}

This check was introduced in #935 (SSRF hardening) and is still present, unchanged and with no opt-out, on main today.

SEP-985 (tracked in #517, closed as implemented) explicitly asks the SDK to support protected-resource-metadata discovery via the resource_metadata parameter in the WWW-Authenticate challenge. That parameter is designed to point at a centralized protected-resource-metadata (PRM) endpoint, which is commonly on a different origin than the MCP resource itself — one PRM host serving metadata for many resource servers, each of which then names its own (also possibly different-origin) authorization server. The same-origin check added in #935 rejects exactly this shape unconditionally, before the authorization_servers value is ever read. There is currently no way to opt into accepting a cross-origin resource_metadata pointer — no builder method, no flag, nothing in AuthorizationManager or OAuthState addresses this specific check.

To Reproduce
Steps to reproduce the behavior:

  1. Stand up a resource server that returns 401 with WWW-Authenticate: Bearer resource_metadata="<url on a different origin than the resource>".
  2. Have that URL serve valid protected-resource metadata naming an authorization_servers entry (on any origin).
  3. Call AuthorizationManager::discover_metadata() (or the equivalent OAuthState discovery flow) against the resource.
  4. Observe that resolve_resource_metadata_url logs rejecting resource metadata URL ... because it is not same-origin and discovery falls through without ever fetching the PRM document or the authorization server metadata.

A self-contained, dependency-free Python reproducer using three loopback-only mock servers (resource / centralized PRM / authorization server) that mirrors this exact topology is available here: https://github.com/openai/codex/issues/42427#issuecomment-5519770828

A real-world case with no mocks: https://api.anthropic.com/v1/design/mcp advertises resource_metadata at https://api.anthropic.com/v1/design/.well-known/oauth-protected-resource, which in turn names https://claude.ai/v1/design/mcp as the authorization server — a different origin from the MCP resource.

Expected behavior
The resource_metadata URL should be followed regardless of origin (subject to the same SSRF allowlist/denylist already applied to authorization-server metadata URLs, e.g. is_disallowed_metadata_host), so that a legitimate centralized PRM host — the deployment shape SEP-985 was written to support — resolves its authorization_servers and completes discovery, instead of being discarded unconditionally.

Logs

[rmcp] warn: rejecting resource metadata URL `https://<prm-host>/.well-known/oauth-protected-resource` because it is not same-origin with `https://<resource-host>/mcp`

Downstream effect in a consuming client (openai/codex), also blocked by this: https://github.com/openai/codex/issues/42427

Additional context

  • This is blocking OAuth login in openai/codex, which uses this SDK for its MCP OAuth client. Claude Code and Qwen Code both complete OAuth against the api.anthropic.com/claude.ai example above; Codex cannot, purely because this SDK never reaches the point of reading authorization_servers.
  • Suggested fix: rather than a binary same-origin requirement on the resource_metadata URL itself, apply the same SSRF allowlist/denylist already used for authorization-server metadata URLs (is_disallowed_metadata_host) to the resolved resource_metadata URL as well. That preserves the SSRF protection #935 was added for while allowing the legitimate cross-origin PRM case.
Lenguaje dominante
Rust
Estrellas
4k
Forks
654
Merge medio
4 d 3 h
PR fusionados (30 d)
40

Preparar el entorno

Abrir en Codespaces

Inicia el contenedor de desarrollo del proyecto en tu navegador, con tu propia cuenta de GitHub.

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de modelcontextprotocol/rust-sdk

Todos los issues de modelcontextprotocol/rust-sdk

Issues similares

Más issues de Rust

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.