Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Validate token audience by default

Open Beginner friendly
#208 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
85/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
typescript

Research direction

Start in src/auth/token-validator.ts, where the aud claim is only checked when tokenValidation.validateAudience is explicitly set to a truthy value. Update the default for this option to enable validation against the token's intended resourceUri, add an explicit opt-out configuration that emits a deprecation warning when used, and update related type definitions. Run the existing token validation test suite to verify the new default behavior and the opt-out path work as expected.

Written by the indexing model from the issue text.

Description

authorization.md (Token Validation) says servers MUST validate that access tokens were issued specifically for them as the intended audience, and MUST only accept tokens valid for their own resources.

src/auth/token-validator.ts checks aud only when tokenValidation.validateAudience is truthy, for both JWT and introspection, and the option defaults to undefined. With the default config, any token signed by a trusted issuer (or reported active by introspection) for a different resource server is accepted. That is the token-passthrough / confused-deputy case the spec warns about.

Proposal: validate aud against resourceUri by default, and keep an explicit opt-out for deployments that cannot (with a warning when it is used). This is a breaking change for setups whose tokens carry no audience, so it may need a major release or a deprecation period.

Related: #179 (issuer and claim checks). Found while reviewing #170. Already present on main.

Dominant language
TypeScript
Stars
58
Forks
13
Avg merge
4h 50m
Merged PRs (30d)
10

Getting set up

  • Ships a Dockerfile or Docker Compose file
  • No pull request template
  • No contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from platformatic/mcp

All issues in platformatic/mcp

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.