RevocationRequest requires client_secret, so public clients get 400 from /revoke
維護者通常 1 天內回覆
還沒有人認領這個 Issue。
評估
- 難度
- 2/5
- 預估耗時
- 1-3 小時
- 新手友好度
- 88/100
- Issue 類型
- 缺陷
- 描述清晰度
- 描述清楚
- 活躍度
- 活躍
- 技術堆疊
- python
- 領域
- api, authentication, backend
研究方向
表單模型位於 mcp/server/auth/handlers/revoke.py。為client_secret設定預設值None(或移除欄位),讓 pydantic 不再將其視為必填,然後確認ClientAuthenticator仍只對機密用戶端強制要求 secret。使用一個 public client(token_endpoint_auth_method: none)重現問題:只向/revoke傳送token和client_id;當其回傳 200 而不是 400 invalid_request 時即完成。
由索引模型根據 Issue 內容生成。
描述
Summary
POST /revoke answers 400 invalid_request to a public client (token_endpoint_auth_method: none) that sends only token and client_id, which is what RFC 7009 allows for a client without credentials.
Cause
In mcp/server/auth/handlers/revoke.py the form model is
class RevocationRequest(BaseModel):
token: str
token_type_hint: Literal["access_token", "refresh_token"] | None = None
client_id: str
client_secret: str | None
client_secret: str | None has no default, so pydantic treats the field as required (nullable, but it must be present). A public client omits it, RevocationRequest.model_validate(dict(form_data)) fails and the handler returns 400 before the provider's revoke_token is called. ClientAuthenticator already handles the secret on its own (it reads it from the form or the Basic header and demands it only for a client registered with one), so the model does not need the field at all, or it needs = None.
Reproduction
Register a client with token_endpoint_auth_method: "none", obtain tokens, then POST /revoke with token=<refresh token>&client_id=<id>. Expected 200, actual 400 {"error": "invalid_request", ...}. Claude Code registers this way and hit it (mcp 2.2.0).
Suggested fix
client_secret: str | None = None (or drop the field).
- 主要語言
- Python
- 星號
- 24.5k
- 分支
- 4k
- 平均合併
- 1 天 11 小時
- 30 天內合併 PR
- 37
環境準備
- 沒有 Dockerfile 或 Docker Compose 檔案
- 有 Pull Request 範本
- 閱讀貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
modelcontextprotocol/python-sdk 的其他 Issue
-
v1 v2
難度 2/5 1-3 小時 新手友好度 75/100
modelcontextprotocol/python-sdk#3639 · 1 則留言 ·
維護者通常 1 天內回覆
-
P3
難度 2/5 1-3 小時 新手友好度 78/100
modelcontextprotocol/python-sdk#3597 · 1 則留言 ·
維護者通常 1 天內回覆
-
v1 v2
難度 2/5 1-3 小時 新手友好度 68/100
modelcontextprotocol/python-sdk#3592 · 1 則留言 · 1 個 reaction ·
維護者通常 1 天內回覆
-
Deploy docs: reused-process runtimes (Lambda) hit the single-use session manager error, but aren't covered可能重新可做 關聯的 PR 已關閉且未合併。 未關閉
難度 1/5 1-3 小時 新手友好度 88/100
modelcontextprotocol/python-sdk#3590 ·
維護者通常 1 天內回覆
-
v1 v2
難度 2/5 1-3 小時 新手友好度 86/100
modelcontextprotocol/python-sdk#3589 · 1 則留言 ·
維護者通常 1 天內回覆
查看 modelcontextprotocol/python-sdk 的全部 Issue
相似的 Issue
-
難度 2/5 1-3 小時 新手友好度 68/100
維護者通常 3 天內回覆
-
docs good first issue
難度 2/5 1-3 小時 新手友好度 78/100
VenetoStato/giorgio#6 ·
-
難度 1/5 1 小時以內 新手友好度 70/100
EclipseFdn/open-vsx.org#13831 ·
維護者通常 1 天內回覆
-
feature request
難度 2/5 1-3 小時 新手友好度 68/100
維護者通常 2 天內回覆
-
Ramp limits of a fixed modular committable unit scale with p_nom times the number of running modules未關閉operational realism optimization
難度 2/5 1-3 小時 新手友好度 75/100
維護者通常 1 天內回覆