M7. MCP authorization (OAuth code flow)
维护者通常 2 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 5/5
- 预计耗时
- 一周以上
- 新手友好度
- 35/100
- Issue 类型
- 功能
- 描述清晰度
- 基本清楚
- 活跃度
- 活跃
- 技术栈
- azure, csharp
调研方向
从 docs/mcp.md 和 docs/agentic-roadmap.md 开始,重点查看路线图项目 M7,然后跟踪 HTTP 传输和现有的 Entra/RBAC 凭据路径。完成的标准是:拒绝未经身份验证的远程请求,bearer-token 授权正常工作,身份信息能够传递到 Cosmos/ARM 凭据,localhost 的 no-auth 仍由 flag 控制,并更新威胁模型和文档。
由索引模型根据 Issue 内容生成。
描述
Why
Today the MCP server relies solely on origin-header validation and localhost binding — safe for a single-user local machine, but there is no authorization layer. Any remote, hosted, or shared agent deployment (team agent, CI runner, cloud-hosted assistant) currently has no supported way to authenticate a caller. The MCP spec defines an OAuth 2.1 authorization-code flow for exactly this; adopting it unlocks hosted/agentic scenarios without falling back to master keys.
This is the natural companion to confirmation/elicitation (item M3): authorization answers "who is allowed to call," M3 answers "what may they do."
Proposed behavior
- Implement the MCP authorization-code flow for the HTTP transport: advertise the authorization server, validate bearer tokens on each request, and map the authenticated identity onto the shell's existing Entra/RBAC connection so tool calls run with least-privilege, per-caller credentials rather than a shared session.
- Keep localhost/no-auth as an explicit opt-in for the current single-user experience.
Acceptance criteria
- Unauthenticated remote requests are rejected.
- A client can complete the authorization-code flow and call tools with a bearer token.
- Identity flows to the Cosmos/ARM credential.
- Localhost no-auth mode preserved behind a flag.
- Threat model +
docs/mcp.mdupdated.
Filed from the Agentic & Automation Roadmap (docs/agentic-roadmap.md), item M7, Wave 2. Priority P1.
- 主要语言
- C#
- 星标
- 4
- 派生
- 7
- 平均合并
- 3 天 12 小时
- 30 天内合并 PR
- 23
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
Azure/CosmosDBShell 的其他 Issue
-
enhancement
难度 5/5 一周以上 新手友好度 25/100
Azure/CosmosDBShell#240 ·
维护者通常 2 天内回复
-
automation P1
难度 5/5 一周以上 新手友好度 45/100
Azure/CosmosDBShell#178 · 1 条评论 ·
维护者通常 2 天内回复
-
Lightweight headless CI distribution (no MCP, LSP, interactive UI)可能重新可做 关联的 PR 已关闭且未合并。 未关闭automation P1
难度 5/5 一周以上 新手友好度 35/100
Azure/CosmosDBShell#175 · 1 条评论 ·
维护者通常 2 天内回复
-
agentic enhancement P0
难度 4/5 3-5 天 新手友好度 55/100
Azure/CosmosDBShell#153 · 1 条评论 ·
维护者通常 2 天内回复
-
难度 5/5 一周以上 新手友好度 30/100
Azure/CosmosDBShell#118 · 1 条评论 ·
维护者通常 2 天内回复
查看 Azure/CosmosDBShell 的全部 Issue
相似的 Issue
-
S: Untriaged
难度 2/5 1-3 小时 新手友好度 78/100
space-wizards/space-station-14#46357 ·
维护者通常 1 天内回复
-
Versioning_oM: Remove unneeded depeendecy on Test_oM可能已有人在做 @IsakNaslundBh 今天认领。 未关闭type:bug type:compliance
难度 2/5 1 小时以内 新手友好度 85/100
-
难度 2/5 1-3 小时 新手友好度 78/100
-
难度 2/5 1-3 小时 新手友好度 66/100
MicrosoftLearning/PL-400_Microsoft-Power-Platform-Developer#231 ·
-
难度 2/5 1-3 小时 新手友好度 66/100
joinrpg/joinrpg-net#5313 ·
维护者通常 1 天内回复