centralize role resolution across all MCP tools
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 55/100
- Loại issue
- Tái cấu trúc
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Ít trao đổi
- Công nghệ
- csharp
- Lĩnh vực
- backend-api-design, security
Hướng nghiên cứu
Đọc McpAuthorizationHelper và tám điểm vào của công cụ MCP đã được nêu tên, sau đó so sánh các thay đổi hiện có về alignment và security trong PR #3737. Xác minh rằng role header chỉ được đọc trong McpAuthorizationHelper, không có mã MCP nào tách nó, mọi công cụ đều sử dụng TryResolveValidatedRole và các bài kiểm thử hiện có đều đạt.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Related PR: #3737 — MSRC 31000000666371: MCP describe_entities info-disclosure fix + single-role alignment
Proposed fix
Add a single choke point on McpAuthorizationHelper that every MCP tool calls to obtain the caller's role:
public static bool TryResolveValidatedRole(
HttpContext httpContext,
IAuthorizationResolver authResolver,
out string? role);
Behavior:
- Delegates validation to
IAuthorizationResolver.IsValidRoleContext(exactly-one non-empty header value +HttpContext.User.IsInRole(header)). - Returns the validated
X-MS-API-ROLEheader value verbatim as the single role for the request. - Is the only place any MCP code reads
AuthorizationResolver.CLIENT_ROLE_HEADER.
Then refactor every MCP tool to call it: DescribeEntitiesTool, AggregateRecordsTool, CreateRecordTool, DeleteRecordTool, ExecuteEntityTool, ReadRecordsTool, UpdateRecordTool, DynamicCustomTool.
Design
- Single-role model.
X-MS-API-ROLEis one atomic role. No splitting, no unioning. Matches REST, GraphQL, and DAB's existingClientRoleHeaderAuthorizationMiddleware. - Resolver-owned inheritance. Per-entity authorization goes through
IAuthorizationResolver.AreRoleAndOperationDefinedForEntity/GetAllowedExposedColumns, soanonymous → authenticated → namedinheritance and wildcardAllexpansion are consistent with REST/GraphQL. - One header read.
AuthorizationResolver.CLIENT_ROLE_HEADERappears in exactly one MCP file after this change.
Acceptance
grep AuthorizationResolver.CLIENT_ROLE_HEADER src/Azure.DataApiBuilder.Mcp/**returns one match, inMcpAuthorizationHelper.- No
.Split(',')on the role header anywhere in the MCP project. - All MCP tools use
TryResolveValidatedRole; existing tests still pass.
Non-goals
- No resolver behavior changes.
- No config schema changes.
- No new live-database tests.
Reference
See PR #3737 for the single-role model, the MSRC fix in DescribeEntitiesTool, and the McpAuthorizationHelper.TryResolveAuthorizedRole alignment this issue builds on.
- Ngôn ngữ chính
- C#
- Star
- 1.5k
- Fork
- 371
- Merge trung bình
- 9 ngày 2 giờ
- Pull request đã merge (30 ngày)
- 10
Chuẩn bị môi trường
Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.
- Có Dockerfile hoặc tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của Azure/data-api-builder
-
pgsql
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
Azure/data-api-builder#3598 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
2.x cli mcp-server
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
Azure/data-api-builder#3576 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
2.x health-endpoint
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
Azure/data-api-builder#3570 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
2.x telemetry
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
Azure/data-api-builder#3564 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
2.x telemetry
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
Azure/data-api-builder#3562 ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của Azure/data-api-builder
Issue tương tự
-
area-ai untriaged
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
dotnet/extensions#7790 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
P2 testing
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 90/100
Maintainer thường phản hồi trong vòng 1 ngày
-
area-Infrastructure-coreclr os-ios os-maccatalyst os-tvos untriaged
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
dotnet/runtime#134766 · 3 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
0 - Backlog Bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
BrighterCommand/Brighter#4444 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
Maintainer thường phản hồi trong vòng 1 ngày