Practical OAuth implementation for production
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 初心者へのやさしさ
- 35/100
- issue の種類
- ドキュメント
- 明瞭さ
- 説明が足りない
- 活発さ
- 静か
- 技術スタック
- csharp
調査の方向性
まず samples/ProtectedMcpServer と tests/ModelContextProtocol.TestOAuthServer を確認し、次に issue #648 と AuthorizationServers メタデータの使用方法を読みます。remote MCP servers 向けに、本番環境で利用できる実践的な認証経路を文書化してください。既存のプロバイダーがサポートされているかどうか、また samples が教育目的にとどまる箇所も含めてください。読者がプロトコルの詳細を推測しなくても実装上の疑問に答えられるガイダンスになれば完了です。
索引モデルが issue の本文から書いたものです。
説明
For building a production-ready remote MCP server with OAuth authentication, what is a practical way to implement the authentication part?
So far all the examples I've checked have comments like "not for production use" and often contain code implementing low-level details of some security protocols. For example, the ProtectedMcpServer sample seem to depend on the TestOAuthServer, which basically implements an OAuth server from scratch, including things like token encryption, encoding etc. This is very useful for educational purposes, but probably not very practical for building a real application.
It's also possible to point the AuthorizationServers metadata to an existing auth provider (Microsoft/Google/etc.), but seems like even that doesn't work well with some providers due to issues like https://github.com/modelcontextprotocol/csharp-sdk/issues/648, and it's not clear whether those issues might actually be by design due to incorrect usage.
So, as of today, how should someone building a real world MCP server go about authentication? Is their best bet to build an OAuth server from scratch just like the samples show? Or is there a better re-usable solution, ideally an existing authentication service that is well supported and works smoothly with MCP scenarios?
- 主要言語
- C#
- スター
- 4.6k
- フォーク
- 817
- 平均マージ
- 8日 7時間
- マージ済み PR(30日)
- 3
環境構築
このプロジェクトの開発コンテナを、あなたの GitHub アカウントでブラウザ上に起動します。
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートなし
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
modelcontextprotocol/csharp-sdk のほかの issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
modelcontextprotocol/csharp-sdk#1867 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 88/100
modelcontextprotocol/csharp-sdk#1840 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
modelcontextprotocol/csharp-sdk#1836 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
enhancement needs confirmation
難易度 2/5 1〜3時間 初心者へのやさしさ 64/100
modelcontextprotocol/csharp-sdk#678 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
enhancement needs confirmation P3 ready for work
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
modelcontextprotocol/csharp-sdk#515 · コメント 6 件 · リアクション 3 件 ·
メンテナーはふだん 1 日以内に返信
modelcontextprotocol/csharp-sdk の issue をすべて見る
似ている issue
-
bug P3
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
nightscout/nocturne#1908 ·
メンテナーはふだん 1 日以内に返信
-
bug documentation Needs: Triage :mag:
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
-
WPF: each page's `Title` overwrites the window title, and returning to a page does not restore itオープン
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
メンテナーはふだん 1 日以内に返信
-
agentic-workflows area/Docs partner/agentic-workflows
難易度 1/5 1時間未満 初心者へのやさしさ 82/100
メンテナーはふだん 1 日以内に返信
-
bug
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
jamesmontemagno/tiny-clips#378 · コメント 2 件 ·
メンテナーはふだん 1 日以内に返信