Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

[Auth] OAuth proxy / DCR facade for non-DCR providers (e.g. Entra ID + Claude Code)

Đang mở
#1,446 4 bình luận 11 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức phù hợp với người mới
25/100
Loại issue
Tính năng
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
csharp

Hướng nghiên cứu

Bắt đầu bằng cách rà soát bề mặt xác thực trong ModelContextProtocol.AspNetCore và thiết kế FastMCP OAuthProxy/OIDCProxy được liên kết. Xác định facade DCR, việc chuyển tiếp callback, token factory, các cơ chế bảo vệ State và PKCE, OIDC discovery, cùng các ranh giới lưu trữ của IDataProtector/IDistributedCache; hoàn thành có nghĩa là Claude Code có thể xác thực thông qua proxy mà không để lộ upstream token.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

area-auth enhancement P2 ready for work

Is your feature request related to a problem? Please describe.

Securing an MCP server with Entra ID is not workable when the connecting client is Claude Code. Entra ID doesn't support Dynamic Client Registration, and Claude Code has no app registration and no client_metadata_document_uri to offer, so there's no client_id to present and no supported registration path. Claude Code simply can't authenticate against an Entra-backed MCP server today.

This is distinct from #648 / PR #1402, which fix the resource= parameter bug for clients that already have a pre-registered client_id. That fix is necessary but not sufficient: our problem is upstream of it.

Describe the solution you'd like

A server-side OAuth proxy / DCR facade in ModelContextProtocol.AspNetCore, similar to what FastMCP (Python) ships as OAuthProxy / OIDCProxy. At a high level it would:

  1. Present a DCR-compliant surface to MCP clients: handle POST /register and return pre-registered credentials rather than attempting real DCR against the upstream provider
  2. Handle callback forwarding: store the MCP client's dynamic redirect URI, use the server's fixed redirect URI with the upstream provider, and forward back to the client after token exchange
  3. Issue its own short-lived JWTs to MCP clients rather than forwarding the upstream token (token factory pattern), preventing token passthrough
  4. Encrypt and store upstream tokens server-side using IDataProtector and IDistributedCache
  5. Support OIDC discovery: Entra exposes /.well-known/openid-configuration, so endpoints should be auto-discoverable rather than manually configured

Describe alternatives you've considered

  • External sidecar proxy (e.g. mcp-auth-proxy): works, but adds ops complexity with no idiomatic .NET integration
  • Use a DCR-capable AS (Auth0, WorkOS): viable, but forces a third-party IdP dependency on teams already standardised on Entra
  • Pre-registration + surfacing client_id in PRM: only works for clients that support pre-registration or CIMD; Claude Code supports neither

Additional context

FastMCP's implementation is a useful reference for the security design: it includes confused deputy mitigation via state cookie binding, PKCE validation at both the client-to-proxy and proxy-to-upstream legs, and a token factory that ensures upstream tokens are never exposed to MCP clients.

Ngôn ngữ chính
C#
Star
4.6k
Fork
817
Merge trung bình
8 ngày 7 giờ
Pull request đã merge (30 ngày)
3

Chuẩn bị môi trường

Mở trong Codespaces

Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của modelcontextprotocol/csharp-sdk

Tất cả issue của modelcontextprotocol/csharp-sdk

Issue tương tự

Thêm issue về C#

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.