Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

MCP: move to Streamable HTTP (spec 2026-07-28) with OAuth, so clients refresh their own tokens

Aperta
#714 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
5/5
Tempo stimato
Più di una settimana
Idoneità per principianti
35/100
Tipo di issue
Funzionalità
Chiarezza
Abbastanza chiara
Stato di attività
Attiva
Stack tecnologico
typescript

Direzione di ricerca

Start with backend-ts/src/routes/mcp.ts and docs/MCP.md, then read the linked MCP 2026-07-28 transport and authorization specifications. Map the existing /sse flow, role gates, and per-call audit before planning the new Streamable HTTP and OAuth paths. Done means the new transport and token refresh flow work while /sse remains available, and the MCP documentation and mcp-surface skill are updated.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

backend enhancement

Why

WorkWell's MCP server (backend-ts/src/routes/mcp.ts) speaks the legacy HTTP+SSE transport: GET /sse, with initialize, notifications/initialized and ping. Clients connect through npx mcp-remote <api>/sse --transport sse-only --header Authorization:${AUTH_HEADER} (docs/MCP.md). Two problems follow.

  1. The transport is on the removal track. MCP revision 2026-07-28 (current; the previous was 2025-11-25) formally lists HTTP+SSE as Deprecated in the new deprecation registry. That revision also removes the initialize handshake, sessions and ping from the core, and requires server/discover plus the Mcp-Method/Mcp-Name headers.
  2. The token cannot refresh. Access tokens last 15 minutes, on purpose (#703): a JWT cannot be revoked, and logout revokes only the refresh family. mcp-remote sends a fixed --header and never renews it. So an MCP session dies after 15 minutes, and a new JWT has to be minted by hand. mcp-remote's own OAuth client does refresh tokens, which needs the server to support the MCP authorization flow.

What to do

  • Serve Streamable HTTP per 2026-07-28:
    • server/discover;
    • per-request _meta version and capabilities;
    • the required headers;
    • ttlMs/cacheScope on list results.
    • Keep /sse alongside until clients have moved.
  • Support the MCP authorization flow (OAuth 2.1, optional in the spec but the only way a client refreshes on its own):
    • Protected Resource Metadata (RFC 9728);
    • an authorization server issuing short access tokens plus refresh tokens;
    • Client ID Metadata Documents rather than the now-deprecated Dynamic Client Registration.
    • Keep the existing role gates (ROLE_ADMIN/ROLE_CASE_MANAGER) and per-call audit.
  • Update docs/MCP.md and the mcp-surface skill.

Not urgent

Nothing on the "Ready for January" list uses MCP, and the pilot does not. One caveat: Claude Desktop's own custom connectors have an open report of not refreshing expired OAuth tokens (anthropics/claude-ai-mcp#247). Check the client side before relying on refresh.

Also noted: a Claude Desktop config still pointing at https://twh-api.os.mieweb.org/sse gets a 404. That was the retired Java host; the live one is twh-api-ts.

Lingua principale
TypeScript
Stelle
0
Fork
0
Merge medio
4h 20m
PR unite (30g)
104

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di Taleef7/workwell

Tutte le issue di Taleef7/workwell

Issue simili

Altre issue su TypeScript

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.