Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

OAuth discovery rejects cross-origin resource_metadata from WWW-Authenticate, breaking centralized PRM (SEP-985) deployments

Aperta
#1,298 1 commento 1 reazione 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 3 giorni

@DaleSeo ci sta già lavorando.

Dal 26/9/2026.

  • #1302 di @DaleSeo — aperta

Valutazione

Difficoltà
3/5
Tempo stimato
1-2 giorni
Idoneità per principianti
74/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
rust

Direzione di ricerca

Start in crates/rmcp/src/transport/auth.rs at AuthorizationManager::resolve_resource_metadata_url, then trace discover_metadata and the OAuthState discovery flow. Reproduce the three-server cross-origin topology described in the issue and inspect the existing is_disallowed_metadata_host handling. Done means a permitted cross-origin resource_metadata URL is fetched, its authorization_servers value is used, and disallowed metadata hosts remain blocked.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

bug P1 ready for work T-security T-transport

Describe the bug
AuthorizationManager::resolve_resource_metadata_url (crates/rmcp/src/transport/auth.rs) unconditionally discards a resource_metadata URL from a WWW-Authenticate challenge when it is not same-origin (scheme+host+port) with the MCP resource:

https://github.com/modelcontextprotocol/rust-sdk/blob/main/crates/rmcp/src/transport/auth.rs

fn resolve_resource_metadata_url(value: &str, base_url: &Url) -> Option<Url> {
    ...
    if Self::is_same_origin_resource_metadata_url(base_url, &url) {
        Some(url)
    } else {
        warn!("rejecting resource metadata URL `{url}` because it is not same-origin with `{base_url}`");
        None
    }
}

This check was introduced in #935 (SSRF hardening) and is still present, unchanged and with no opt-out, on main today.

SEP-985 (tracked in #517, closed as implemented) explicitly asks the SDK to support protected-resource-metadata discovery via the resource_metadata parameter in the WWW-Authenticate challenge. That parameter is designed to point at a centralized protected-resource-metadata (PRM) endpoint, which is commonly on a different origin than the MCP resource itself — one PRM host serving metadata for many resource servers, each of which then names its own (also possibly different-origin) authorization server. The same-origin check added in #935 rejects exactly this shape unconditionally, before the authorization_servers value is ever read. There is currently no way to opt into accepting a cross-origin resource_metadata pointer — no builder method, no flag, nothing in AuthorizationManager or OAuthState addresses this specific check.

To Reproduce
Steps to reproduce the behavior:

  1. Stand up a resource server that returns 401 with WWW-Authenticate: Bearer resource_metadata="<url on a different origin than the resource>".
  2. Have that URL serve valid protected-resource metadata naming an authorization_servers entry (on any origin).
  3. Call AuthorizationManager::discover_metadata() (or the equivalent OAuthState discovery flow) against the resource.
  4. Observe that resolve_resource_metadata_url logs rejecting resource metadata URL ... because it is not same-origin and discovery falls through without ever fetching the PRM document or the authorization server metadata.

A self-contained, dependency-free Python reproducer using three loopback-only mock servers (resource / centralized PRM / authorization server) that mirrors this exact topology is available here: https://github.com/openai/codex/issues/42427#issuecomment-5519770828

A real-world case with no mocks: https://api.anthropic.com/v1/design/mcp advertises resource_metadata at https://api.anthropic.com/v1/design/.well-known/oauth-protected-resource, which in turn names https://claude.ai/v1/design/mcp as the authorization server — a different origin from the MCP resource.

Expected behavior
The resource_metadata URL should be followed regardless of origin (subject to the same SSRF allowlist/denylist already applied to authorization-server metadata URLs, e.g. is_disallowed_metadata_host), so that a legitimate centralized PRM host — the deployment shape SEP-985 was written to support — resolves its authorization_servers and completes discovery, instead of being discarded unconditionally.

Logs

[rmcp] warn: rejecting resource metadata URL `https://<prm-host>/.well-known/oauth-protected-resource` because it is not same-origin with `https://<resource-host>/mcp`

Downstream effect in a consuming client (openai/codex), also blocked by this: https://github.com/openai/codex/issues/42427

Additional context

  • This is blocking OAuth login in openai/codex, which uses this SDK for its MCP OAuth client. Claude Code and Qwen Code both complete OAuth against the api.anthropic.com/claude.ai example above; Codex cannot, purely because this SDK never reaches the point of reading authorization_servers.
  • Suggested fix: rather than a binary same-origin requirement on the resource_metadata URL itself, apply the same SSRF allowlist/denylist already used for authorization-server metadata URLs (is_disallowed_metadata_host) to the resolved resource_metadata URL as well. That preserves the SSRF protection #935 was added for while allowing the legitimate cross-origin PRM case.
Lingua principale
Rust
Stelle
4k
Fork
654
Merge medio
4g 3h
PR unite (30g)
40

Preparare l'ambiente

Apri in Codespaces

Avvia il container di sviluppo del progetto nel browser, con il tuo account GitHub.

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di modelcontextprotocol/rust-sdk

Tutte le issue di modelcontextprotocol/rust-sdk

Issue simili

Altre issue su Rust

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.