Trailing slash in OAuthMetadata's `issuer` causes issues with clients
Personne n'a encore pris cette issue.
Évaluation
- Difficulté
- 3/5
- Temps estimé
- 1-2 jours
- Accessibilité débutants
- 58/100
- Type d'issue
- Bug
- Clarté
- Plutôt claire
- Activité
- Active
- Stack technique
- python
- Domaine
- api, authentication
Piste de recherche
Commencez par le modèle OAuthMetadata et le endpoint .well-known/oauth-authorization-server, puis examinez comment AnyHttpUrl de Pydantic normalise la valeur de issuer. Vérifiez les exigences de la RFC 8414 et la discussion existante dans l’issue avant de décider du comportement attendu pour un unique slash final ; le travail est terminé lorsque l’issuer renvoyé et l’URL de découverte restent compatibles avec les clients concernés.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Description
Initial Checks
- I confirm that I'm using the latest version of MCP Python SDK
- I confirm that I searched for my issue in https://github.com/modelcontextprotocol/python-sdk/issues before opening this issue
Description
In the .well-known/oauth-authorization-server endpoint and , the issuer is forced to always contain a trailing slash e.g.,
https://your-mcp.com/instead ofhttps://your-mcp.com
as a byproduct of using pydantic'sAnyHttpUrltype.
This causes issues in both Google's ADK and IBM's MCP Context Forge because:
- when building the .well-known URL, they expect a discovery issuer URL that does not contain a trailing slash; and
- then they MUST verify that the returned metadata issuer URL is identical to the discovery issuer URL ("authorization server's issuer identifier value" in the spec) according to RFC 8414 Section 3.2; so
- when
OAuthMetadata.issuercontains the trailing slash, the discovery process is aborted.
OAuth 2.0 Authorization Server Metadata spec says that the client MUST remove trailing paths from when the issuer contains a path component:
If the issuer identifier value contains a path component, any
terminating "/" MUST be removed before inserting "/.well-known/" and
the well-known URI suffix between the host component and the path
component.
-- https://datatracker.ietf.org/doc/html/rfc8414#section-3.1
if the trailing / in https://example.com/ is a "path component", and should thus be stripped by the client, so I think the spec is ambiguous about the responsibilities of the client in the case where there the issuer identifier value contains a lone trailing slash.
I did note that the examples of issuer identifiers in the spec do not contain a lone trailing slash, i.e. they are https://example.com rather than https://example.com/.
For these reasons, and
- while it's listed as the client's responsibility to remove trailing slashes from the issuer identifier,
- I don't believe it's the server implementation's responsibility to intentionally make it harder for clients by returning a URL that do not follow the assumptions in the spec.
I think it's worth it to consider interpreting the spec as "the issuer field should not contain a trailing slash".
I also believe this issue could be similar in mechanism, but different in scope, to what is described in https://github.com/modelcontextprotocol/python-sdk/issues/1265
Example Code
# A demonstration on how AnyHttpUrl adds a trailing slash.
>>> from pydantic.networks import AnyHttpUrl
>>> x = AnyHttpUrl("http://localhost:8000")
>>> x
AnyHttpUrl('http://localhost:8000/')
>>> str(x)
'http://localhost:8000/'
>>>
Python & MCP Python SDK
Python 3.14
mcp==1.25.0
- Langage dominant
- Python
- Étoiles
- 24.3k
- Forks
- 4k
- Merge moyen
- 1 j 11 h
- PR mergées (30 j)
- 30
Guide de contribution
Ouvrir le guide de contribution
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Autres issues de modelcontextprotocol/python-sdk
-
Difficulté 2/5 1-3 heures Accessibilité débutants 75/100
modelcontextprotocol/python-sdk#3566 ·
-
Streamable HTTP client logs a WARNING for valid 202 Accepted on session termination (DELETE) Ouvertev1 v2
Difficulté 2/5 1-3 heures Accessibilité débutants 85/100
modelcontextprotocol/python-sdk#3546 · 5 commentaires ·
-
v1 v2
Difficulté 2/5 1-3 heures Accessibilité débutants 76/100
modelcontextprotocol/python-sdk#3545 · 1 commentaire ·
-
v1 v2
Difficulté 1/5 Moins d'une heure Accessibilité débutants 91/100
modelcontextprotocol/python-sdk#3508 · 2 commentaires ·
-
Difficulté 2/5 1-3 heures Accessibilité débutants 64/100
modelcontextprotocol/python-sdk#3504 ·
Toutes les issues de modelcontextprotocol/python-sdk
Issues similaires
-
bug
Difficulté 2/5 1-3 heures Accessibilité débutants 75/100
xinnan-tech/xiaozhi-fde-talk#263 ·
-
rules
Difficulté 1/5 Moins d'une heure Accessibilité débutants 90/100
-
Difficulté 2/5 1-3 heures Accessibilité débutants 70/100
huggingface/Repo2RLEnv#163 · 1 commentaire ·
-
Difficulté 1/5 Moins d'une heure Accessibilité débutants 95/100
huggingface/sentence-transformers#4074 ·
-
comp/dashboard invalid P3
Difficulté 2/5 1-3 heures Accessibilité débutants 70/100
NousResearch/hermes-agent#121143 ·