MCP: move to Streamable HTTP (spec 2026-07-28) with OAuth, so clients refresh their own tokens
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Idoneità per principianti
- 35/100
- Tipo di issue
- Funzionalità
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Attiva
- Stack tecnologico
- typescript
- Ambito
- api, authentication, backend-api-design, documentation
Direzione di ricerca
Start with backend-ts/src/routes/mcp.ts and docs/MCP.md, then read the linked MCP 2026-07-28 transport and authorization specifications. Map the existing /sse flow, role gates, and per-call audit before planning the new Streamable HTTP and OAuth paths. Done means the new transport and token refresh flow work while /sse remains available, and the MCP documentation and mcp-surface skill are updated.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Why
WorkWell's MCP server (backend-ts/src/routes/mcp.ts) speaks the legacy HTTP+SSE transport: GET /sse, with initialize, notifications/initialized and ping. Clients connect through npx mcp-remote <api>/sse --transport sse-only --header Authorization:${AUTH_HEADER} (docs/MCP.md). Two problems follow.
- The transport is on the removal track. MCP revision 2026-07-28 (current; the previous was 2025-11-25) formally lists HTTP+SSE as Deprecated in the new deprecation registry. That revision also removes the
initializehandshake, sessions andpingfrom the core, and requiresserver/discoverplus theMcp-Method/Mcp-Nameheaders.- When can HTTP+SSE be removed? The deprecation SEP says as early as the next revision; the release blog says a 12-month offramp.
- Sources: https://modelcontextprotocol.io/specification/2026-07-28/changelog and https://modelcontextprotocol.io/specification/2026-07-28/deprecated
- The token cannot refresh. Access tokens last 15 minutes, on purpose (#703): a JWT cannot be revoked, and logout revokes only the refresh family.
mcp-remotesends a fixed--headerand never renews it. So an MCP session dies after 15 minutes, and a new JWT has to be minted by hand.mcp-remote's own OAuth client does refresh tokens, which needs the server to support the MCP authorization flow.
What to do
- Serve Streamable HTTP per 2026-07-28:
server/discover;- per-request
_metaversion and capabilities; - the required headers;
ttlMs/cacheScopeon list results.- Keep
/ssealongside until clients have moved.
- Support the MCP authorization flow (OAuth 2.1, optional in the spec but the only way a client refreshes on its own):
- Protected Resource Metadata (RFC 9728);
- an authorization server issuing short access tokens plus refresh tokens;
- Client ID Metadata Documents rather than the now-deprecated Dynamic Client Registration.
- Keep the existing role gates (
ROLE_ADMIN/ROLE_CASE_MANAGER) and per-call audit.
- Update
docs/MCP.mdand themcp-surfaceskill.
Not urgent
Nothing on the "Ready for January" list uses MCP, and the pilot does not. One caveat: Claude Desktop's own custom connectors have an open report of not refreshing expired OAuth tokens (anthropics/claude-ai-mcp#247). Check the client side before relying on refresh.
Also noted: a Claude Desktop config still pointing at https://twh-api.os.mieweb.org/sse gets a 404. That was the retired Java host; the live one is twh-api-ts.
- Lingua principale
- TypeScript
- Stelle
- 0
- Fork
- 0
- Merge medio
- 4h 20m
- PR unite (30g)
- 104
Preparare l'ambiente
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di Taleef7/workwell
-
frontend maui-pilot pilot-ask question
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
I maintainer di solito rispondono entro 1 giorno
-
documentation owner-ops waiting
Difficoltà 1/5 1-3 ore Idoneità per principianti 86/100
I maintainer di solito rispondono entro 1 giorno
-
owner-ops waiting
Difficoltà 1/5 1-3 ore Idoneità per principianti 85/100
I maintainer di solito rispondono entro 1 giorno
-
backend maui-pilot webchart-convergence
Difficoltà 4/5 3-5 giorni Idoneità per principianti 68/100
I maintainer di solito rispondono entro 1 giorno
-
backend
Difficoltà 5/5 Più di una settimana Idoneità per principianti 35/100
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di Taleef7/workwell
Issue simili
-
bug
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 88/100
StabilityNexus/Fate-EVM-Frontend#153 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
code-yeongyu/oh-my-openagent#9039 ·
I maintainer di solito rispondono entro 1 giorno
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
Tencent/teamai-cli#862 ·
I maintainer di solito rispondono entro 1 giorno
-
bug good first issue hacktoberfest redis
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
libredb/libredb-studio#1164 ·
I maintainer di solito rispondono entro 1 giorno
-
flake
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
I maintainer di solito rispondono entro 1 giorno