Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Nextcloud MCP-Server an OAuth

Aperta
#74 7 commenti 9 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
5/5
Tempo stimato
Più di una settimana
Idoneità per principianti
25/100
Tipo di issue
Funzionalità
Chiarezza
Abbastanza chiara
Stato di attività
Ferma
Stack tecnologico
python

Direzione di ricerca

Inizia con il MCP server integrato e il flusso attuale di bearer-token descritto nella documentazione Nextcloud collegata. Metti in relazione gli endpoint OAuth richiesti, l’applicazione delle ACL per utente, gli soft scopes, le restrizioni per gli amministratori, la compatibilità del trasporto e la revoca con i criteri di accettazione; il lavoro è completo quando una connessione OAuth di ChatGPT espone solo dati autorizzati e supporta la revoca del consenso.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

enhancement not planned

Add OAuth 2.1 (Auth Code + PKCE) to the built-in MCP server and support per-user access control

Is your feature request related to a problem? Please describe.

Nextcloud’s Context Agent already exposes an MCP server, but it currently authenticates via app password using Authorization: Bearer <token> only. This prevents using it as a ChatGPT connector, because the ChatGPT admin UI for remote MCP servers supports OAuth or no authentication, not custom bearer headers. As a result, organizations cannot easily add the Nextcloud MCP server as a workspace-wide connector in ChatGPT.

Describe the solution you’d like

Please add first-class OAuth 2.1 Authorization Code with PKCE to the built-in MCP server, along with per-user access enforcement:

  1. OAuth 2.1 / OIDC-compatible endpoints (/authorize, /token) so ChatGPT can complete user consent and store user-bound tokens.
  2. Per-user binding: the MCP server should execute requests as the consenting Nextcloud user, honoring existing shares/ACLs (files, Talk, calendar, etc.).
  3. Server-enforced “soft scopes” for MCP (even if core OAuth lacks scopes): e.g., files.read, files.write, talk.read, calendar.read. The MCP server would internally restrict exposed tools/routes accordingly.
  4. Admin controls to constrain exposure, e.g., allowlist of folders/namespaces or group-based eligibility.
  5. Transport compatibility with ChatGPT MCP (SSE/streaming HTTP) and token revocation/rotation.

Describe alternatives you’ve considered

  • Context Chat (built-in): indexes data into a vector DB; tight content scoping can be difficult depending on setup.
  • AI as a Service / integration_openai: works, but typically requires an external API provider/account (API key) and is not an MCP server for ChatGPT connectors.
  • Community MCP servers for Nextcloud: often authenticate with app passwords and don’t solve the ChatGPT OAuth requirement for workspace rollout.

Why this matters

  • ChatGPT workspace admins can publish connectors for all users; with OAuth, each user authorizes their own access and only sees what they can already access in Nextcloud. This aligns with least privilege and simplifies enterprise rollout.

Acceptance criteria (suggestion)

  • In ChatGPT, an admin adds “Nextcloud MCP” as a remote server and chooses OAuth.
  • A user starts a chat, picks the connector, completes the OAuth consent, and can list/search only files they already have rights to.
  • Revoking consent in Nextcloud (or the connector) immediately invalidates access.
  • Optional admin policy: restrict tools (read-only vs read/write) and/or allowlist top-level paths.

Security & privacy

  • Use Auth Code + PKCE, short-lived access tokens, refresh tokens, and proper token revocation.
  • Because core OAuth may lack granular scopes, implement server-side scoping within the MCP server (tool exposure + path allowlists) until upstream scopes are available.

References

Lingua principale
Python
Stelle
26
Fork
18
Merge medio
2g 1h
PR unite (30g)
5

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di nextcloud/context_agent

Tutte le issue di nextcloud/context_agent

Issue simili

Altre issue su Python

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.