Add server conformance for SEP-2350 scope challenges
I maintainer di solito rispondono entro 7 giorni
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 68/100
- Tipo di issue
- Funzionalità
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Attiva
- Stack tecnologico
- typescript
- Ambito
- api, testing-qa
Direzione di ricerca
Inizia con src/seps/sep-2350.yaml, i fixture Cross-SDK esistenti e lo scenario runner ufficiale. Esegui tools/call, static e template resources/read e prompts/get con i token con permessi ridotti e completi. Il lavoro è completato quando le richieste con token con permessi ridotti restituiscono HTTP 403 con un'unica challenge insufficient_scope contenente entrambi gli scope richiesti, mentre i tentativi successivi con token completi hanno esito positivo per tutte le operazioni elencate.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Goal
Add one language-neutral server conformance scenario for request-time OAuth insufficient_scope behavior from SEP-2350. The scenario should exercise every invocable MCP server primitive: tools/call, resources/read for both a static URI and a template-expanded URI, and prompts/get.
Portable fixture contract
Reuse the existing cross-SDK fixtures so implementations fail on observable wire behavior rather than on a missing test-only primitive:
| Operation | Fixture | Required scopes in one challenge |
|---|---|---|
| Tool | tools/call / test_simple_text |
mcp:conformance:tools:call, mcp:conformance:tools:test_simple_text |
| Static resource | resources/read / test://static-text |
mcp:conformance:resources:read, mcp:conformance:resources:static |
| Template resource | resources/read / test://template/123/data |
mcp:conformance:resources:read, mcp:conformance:resources:template:123 |
| Prompt | prompts/get / test_simple_prompt |
mcp:conformance:prompts:get, mcp:conformance:prompts:test_simple_prompt |
Servers should treat mcp-conformance-scope-low as a valid opaque token with only mcp:conformance:baseline, and mcp-conformance-scope-full as a valid opaque token with all required scopes. Unauthenticated behavior remains unchanged for existing scenarios.
For each operation, the low token should produce HTTP 403 and a Bearer WWW-Authenticate challenge containing error="insufficient_scope", the fixture protected-resource metadata URL, and both required scopes in one challenge. Retrying the same operation with the full token should produce the normal successful MCP result.
Rationale
src/seps/sep-2350.yaml currently excludes the server single-challenge requirement because the challenge was the only source of truth for required scopes. The fixed fixture contract supplies independent ground truth, so sep-2350-server-single-challenge can become an observable check.
This deliberately does not test general token validation or require a mock authorization server; it isolates the SDK/server request-time challenge seam. It also avoids the TypeScript-specific client/auth imports and guessed admin-action fixture in the older, unmerged #106 approach.
Proof
Run the official scenario through the existing SDK runner against:
- Unmodified
modelcontextprotocol/typescript-sdk@main: build succeeds, but low-token operations return HTTP 200 and the scenario exits non-zero. SamMorrowDrums/typescript-sdk@scope-challenge-server-sdk(modelcontextprotocol/typescript-sdk#1624): all challenge and upgraded-retry checks pass.
Related
- SEP-2350: modelcontextprotocol/modelcontextprotocol#2350
- Existing client coverage: #281 / #282
- Existing server-row exclusion: #302
- Older overlapping proposal: #106
- TypeScript SDK implementation: modelcontextprotocol/typescript-sdk#1624
- Lingua principale
- TypeScript
- Stelle
- 130
- Fork
- 107
- Merge medio
- 8g 19h
- PR unite (30g)
- 2
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di modelcontextprotocol/conformance
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
modelcontextprotocol/conformance#531 · 1 commento ·
I maintainer di solito rispondono entro 7 giorni
-
server-stateless: 500 ms whole-request deadline in no-log-without-loglevel reports slow servers as failuresForse già presa @birbprophet l’ha presa 8 giorni fa. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
modelcontextprotocol/conformance#530 ·
I maintainer di solito rispondono entro 7 giorni
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
modelcontextprotocol/conformance#519 ·
I maintainer di solito rispondono entro 7 giorni
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
modelcontextprotocol/conformance#315 · 1 commento ·
I maintainer di solito rispondono entro 7 giorni
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
modelcontextprotocol/conformance#312 · 1 commento ·
I maintainer di solito rispondono entro 7 giorni
Tutte le issue di modelcontextprotocol/conformance
Issue simili
-
level/task reporter/qa type/bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
wazuh/wazuh-dashboard-plugins#9310 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
cybersemics/treecrdt#267 ·
-
Difficoltà 1/5 1-3 ore Idoneità per principianti 85/100
wiz-sec-public/backstage-plugin-wiz#16 · 1 commento ·
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
solana-foundation/solana-com#2245 ·
I maintainer di solito rispondono entro 1 giorno