Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

centralize role resolution across all MCP tools

Đang mở
#3,757 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức phù hợp với người mới
55/100
Loại issue
Tái cấu trúc
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Ít trao đổi
Công nghệ
csharp

Hướng nghiên cứu

Đọc McpAuthorizationHelper và tám điểm vào của công cụ MCP đã được nêu tên, sau đó so sánh các thay đổi hiện có về alignment và security trong PR #3737. Xác minh rằng role header chỉ được đọc trong McpAuthorizationHelper, không có mã MCP nào tách nó, mọi công cụ đều sử dụng TryResolveValidatedRole và các bài kiểm thử hiện có đều đạt.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

mcp-server

Related PR: #3737 — MSRC 31000000666371: MCP describe_entities info-disclosure fix + single-role alignment

Proposed fix

Add a single choke point on McpAuthorizationHelper that every MCP tool calls to obtain the caller's role:

public static bool TryResolveValidatedRole(
    HttpContext httpContext,
    IAuthorizationResolver authResolver,
    out string? role);

Behavior:

  • Delegates validation to IAuthorizationResolver.IsValidRoleContext (exactly-one non-empty header value + HttpContext.User.IsInRole(header)).
  • Returns the validated X-MS-API-ROLE header value verbatim as the single role for the request.
  • Is the only place any MCP code reads AuthorizationResolver.CLIENT_ROLE_HEADER.

Then refactor every MCP tool to call it: DescribeEntitiesTool, AggregateRecordsTool, CreateRecordTool, DeleteRecordTool, ExecuteEntityTool, ReadRecordsTool, UpdateRecordTool, DynamicCustomTool.

Design

  • Single-role model. X-MS-API-ROLE is one atomic role. No splitting, no unioning. Matches REST, GraphQL, and DAB's existing ClientRoleHeaderAuthorizationMiddleware.
  • Resolver-owned inheritance. Per-entity authorization goes through IAuthorizationResolver.AreRoleAndOperationDefinedForEntity / GetAllowedExposedColumns, so anonymous → authenticated → named inheritance and wildcard All expansion are consistent with REST/GraphQL.
  • One header read. AuthorizationResolver.CLIENT_ROLE_HEADER appears in exactly one MCP file after this change.

Acceptance

  • grep AuthorizationResolver.CLIENT_ROLE_HEADER src/Azure.DataApiBuilder.Mcp/** returns one match, in McpAuthorizationHelper.
  • No .Split(',') on the role header anywhere in the MCP project.
  • All MCP tools use TryResolveValidatedRole; existing tests still pass.

Non-goals

  • No resolver behavior changes.
  • No config schema changes.
  • No new live-database tests.

Reference

See PR #3737 for the single-role model, the MSRC fix in DescribeEntitiesTool, and the McpAuthorizationHelper.TryResolveAuthorizedRole alignment this issue builds on.

Ngôn ngữ chính
C#
Star
1.5k
Fork
371
Merge trung bình
9 ngày 2 giờ
Pull request đã merge (30 ngày)
10

Chuẩn bị môi trường

Mở trong Codespaces

Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của Azure/data-api-builder

Tất cả issue của Azure/data-api-builder

Issue tương tự

Thêm issue về C#

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.