DCR initialAccessToken fails open: an unresolved ${VAR} placeholder becomes the bearer secret, an empty value opens registration
I maintainer di solito rispondono entro 5 giorni
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Idoneità per principianti
- 68/100
- Tipo di issue
- Bug
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Attiva
- Stack tecnologico
- typescript
- Ambito
- api, authentication, security
Direzione di ricerca
Start with src/lib/mcp/dcr.ts, especially checkInitialAccessToken and the warning, then read src/lib/config.ts around expandEnvVar and the placeholder regex. Verify the behavior for unresolved and empty declared values, while preserving open registration only when the key is omitted; run the relevant test suite if available.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
What happens
mcp.dynamicClientRegistration.initialAccessToken is the gate on POST /oauth/mcp/register (RFC 7591 Dynamic Client Registration). Two misconfigurations turn it into no gate:
- Unset env var.
initialAccessToken: ${DCR_TOKEN}withDCR_TOKENunset reachescheckInitialAccessTokenas the literal string${DCR_TOKEN}—expandEnvVarkeeps an unresolved placeholder as-is (src/lib/config.ts~L25-34) — and that literal is then the accepted bearer value. Anyone who can read the app's config (placeholders are routinely committed) can register clients. Nothing is logged. - Set but empty.
initialAccessToken: ""(or an env var set to empty) hitsif (!configured) return null(src/lib/mcp/dcr.ts~L39-41): open registration, with a once-per-process warning (dcr.ts~L229-234) whose wording describes the legitimate RFC 7591 open mode, so it reads as intentional.
Verified by reading main @ 92ab477; not executed.
Why it matters
#182 closed "absent dynamicClientRegistration block ⇒ open registration". These two shapes reopen it on an operator mistake that the docs' own ${VAR} convention makes likely (an env var missing on one host). Registration alone does not grant tokens — a user still has to authorize the registered client — so this is a consent-phishing surface, not a direct token bypass. It is still a security gate failing open, silently in the placeholder case.
Expected
The fail-closed rule from #236 (mcp.signingKeyPem) and #238 (redirectUri): a declared value that is an unresolved ${…} placeholder or empty throws at boot naming the key. Open registration remains available only by omitting the key. src/lib/config.ts already carries the placeholder regex (~L94) and #236/#238 each add a copy — one shared isUnresolvedEnvPlaceholder() helper is the natural home once the second of those lands.
Scope
Only deployments that enable DCR (a deprecated compat path since 2026-07-28; CIMD is primary) and misconfigure the token. clientId/clientSecret placeholders expand the same way but fail at the IdP, so they are out of scope here.
Found during the cross-model review round on #236.
- Lingua principale
- JavaScript
- Stelle
- 1
- Fork
- 3
- Merge medio
- 3g 8h
- PR unite (30g)
- 11
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di HarperFast/oauth
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 86/100
HarperFast/oauth#243 ·
I maintainer di solito rispondono entro 5 giorni
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 82/100
HarperFast/oauth#207 ·
I maintainer di solito rispondono entro 5 giorni
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 70/100
HarperFast/oauth#244 · 2 commenti ·
I maintainer di solito rispondono entro 5 giorni
-
Provider-type check in the 2.7.0 evidence path is case-sensitive while preset resolution is notAperta
Difficoltà 3/5 1-2 giorni Idoneità per principianti 76/100
HarperFast/oauth#242 ·
I maintainer di solito rispondono entro 5 giorni
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 25/100
HarperFast/oauth#231 · 1 commento ·
I maintainer di solito rispondono entro 5 giorni
Tutte le issue di HarperFast/oauth
Issue simili
-
check:failed feeds:add
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
iptv-org/database#36278 · 1 commento ·
I maintainer di solito rispondono entro 3 giorni
-
fix
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
idean3885/claude-ops-agent#577 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
I maintainer di solito rispondono entro 7 giorni
-
agent/quality hive/hosted-available-lke648397-260827-5n31 quality testing
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
I maintainer di solito rispondono entro 1 giorno
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
notionnext-org/NotionNext#4544 ·
I maintainer di solito rispondono entro 1 giorno