Hacktoberfest 2026:維護者為十月標記出來的 issue,仍然開放、適合新手。 瀏覽 Hacktoberfest issue

RevocationRequest requires client_secret, so public clients get 400 from /revoke

未關閉 適合新手
#3,648 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視

維護者通常 1 天內回覆

還沒有人認領這個 Issue。

評估

難度
2/5
預估耗時
1-3 小時
新手友好度
88/100
Issue 類型
缺陷
描述清晰度
描述清楚
活躍度
活躍
技術堆疊
python

研究方向

表單模型位於 mcp/server/auth/handlers/revoke.py。為client_secret設定預設值None(或移除欄位),讓 pydantic 不再將其視為必填,然後確認ClientAuthenticator仍只對機密用戶端強制要求 secret。使用一個 public client(token_endpoint_auth_method: none)重現問題:只向/revoke傳送token和client_id;當其回傳 200 而不是 400 invalid_request 時即完成。

由索引模型根據 Issue 內容生成。

描述

Summary

POST /revoke answers 400 invalid_request to a public client (token_endpoint_auth_method: none) that sends only token and client_id, which is what RFC 7009 allows for a client without credentials.

Cause

In mcp/server/auth/handlers/revoke.py the form model is

class RevocationRequest(BaseModel):
    token: str
    token_type_hint: Literal["access_token", "refresh_token"] | None = None
    client_id: str
    client_secret: str | None

client_secret: str | None has no default, so pydantic treats the field as required (nullable, but it must be present). A public client omits it, RevocationRequest.model_validate(dict(form_data)) fails and the handler returns 400 before the provider's revoke_token is called. ClientAuthenticator already handles the secret on its own (it reads it from the form or the Basic header and demands it only for a client registered with one), so the model does not need the field at all, or it needs = None.

Reproduction

Register a client with token_endpoint_auth_method: "none", obtain tokens, then POST /revoke with token=<refresh token>&client_id=<id>. Expected 200, actual 400 {"error": "invalid_request", ...}. Claude Code registers this way and hit it (mcp 2.2.0).

Suggested fix

client_secret: str | None = None (or drop the field).

主要語言
Python
星號
24.5k
分支
4k
平均合併
1 天 11 小時
30 天內合併 PR
37

環境準備

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

modelcontextprotocol/python-sdk 的其他 Issue

查看 modelcontextprotocol/python-sdk 的全部 Issue

相似的 Issue

更多 Python Issue

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。